1. Home
  2. Glossary
  3. Shadow AI
AI glossary · Safety, ethics & policy

Shadow AI

Shadow AI: Shadow AI is the use of AI tools inside an organization without the knowledge or approval of IT, security, or leadership: personal ChatGPT accounts, browser extensions, and AI features quietly switched on inside existing software.

The name borrows from shadow IT, the long-standing problem of employees adopting unapproved software because the sanctioned tools are slow to arrive or hard to use. Shadow AI is the same pattern at higher speed. Someone pastes a customer contract into a free chat assistant to summarize it, installs a meeting-notes bot that joins every call, or turns on an AI feature inside a tool the company already pays for, and nobody responsible for data protection knows.

The exposure is mostly about data. Consumer AI tools may retain conversations and use them to improve models unless settings or paid plans say otherwise, so confidential material can leave the company with no record. For regulated work that can mean protected health information, privileged client documents, financial data covered by GLBA or SOX, or employee records going somewhere they are not allowed to go. There is also no audit trail, no consistency in quality, and no way to answer a customer who asks how their data is handled.

Bans rarely work; they push usage further underground. What does work is to provide approved tools with business-grade data terms, publish a short plain-language policy that says what can and cannot be pasted where, keep an allow-list people can request additions to, and ask teams what they already use without punishing honest answers. The rule to repeat: never put confidential data into a consumer AI tool unless your organization has approved it.

Example at work

A finance manager discovers that three analysts have been using personal AI accounts to clean up spreadsheets containing customer payment data. Instead of writing them up, she gets the company's enterprise AI plan extended to her team within two weeks, runs a 30-minute session on what is allowed, and adds the tool to the onboarding checklist.

Why it matters

Shadow AI is probably already happening on your team. The question is whether it happens with protected data and no visibility, or with approved tools and clear rules. Getting ahead of it is a governance problem with a practical, low-drama solution.

Related terms