Glossary
Shadow AI
Shadow AI is the use of AI tools inside an organisation that were never approved by it, typically adopted by capable people trying to do their existing work faster.
In plain terms
Somebody pastes a contract into a chat window to get a summary. Somebody else runs meeting notes through a service they found and liked. Neither told anybody, neither thought they were doing anything unusual, and both were trying to get their work done. That is the whole phenomenon. It is rarely rebellion and almost never malice; it is the ordinary behaviour of people who have found something that helps and have not been given an approved way to use it.
Why it matters
Because the exposure is real while the visibility is not. Material leaves the organisation through accounts nobody administers, under terms nobody read, into products that may or may not retain what they are given. If somebody leaves, the work goes with their personal login. If a customer asks where their data has been, the honest answer is that nobody can fully say. None of that requires anyone to have behaved badly, which is what makes it awkward to address as a discipline matter and productive to address as a supply problem.
How it works
It appears where the approved route is slower than the unapproved one. The pattern is consistent across organisations: the larger the gap between what people need and what they have been given, the more of this there is. It is a demand signal wearing the costume of a compliance failure.
Consumer terms differ from business terms, and that is usually the substance of the risk. A personal account and a business account for the same product can carry materially different commitments about retention and about training on what you submit. The tool is often fine; the account it was used through is the problem.
It concentrates in the work people find tedious rather than the work they find hard. Summarising, reformatting, drafting routine replies and rewriting for tone come up repeatedly, which is useful intelligence: those are the tasks an approved offering should cover first.
The organisation loses the record, not just the control. There is no log of what was sent, no ability to answer a question about a specific document later, and no way to reconstruct what happened when somebody asks. That absence of record is often more consequential than any single thing that was sent.
Prohibition tends to relocate it. A ban with no approved alternative moves the same activity onto personal devices, where the organisation has less visibility rather than more. The activity is not price-sensitive or policy-sensitive; it is friction-sensitive.
Discovering it is mostly a conversation. Expense claims, browser telemetry and network logs each show a fraction. Asking people directly, without a threat attached, tends to surface more than any of them, because most of it is not hidden in the first place.
A sanctioned route has to beat the unsanctioned one on friction, not on features. The tool people reached for was almost always the one they could start using in a minute, so an approved alternative that requires a ticket, a training session and a two-week wait loses to it however much better it is. The effective move is usually narrow: take the two or three tasks that came up most, provide an administered account of a capable tool for exactly those, and make getting access the fastest part of the process rather than the slowest.
It never fully goes away, and a programme that assumes otherwise will misread its own success. New tools appear continuously and some will be genuinely better than whatever was approved last year. The realistic goal is a short, visible gap between what people need and what they have, plus a route for telling somebody about a new tool that does not feel like a confession. Organisations that keep that route open hear about the next one early; the rest hear about it during an incident.
How it usually arrives
Seen in the wild
A contract or customer email pasted into a general assistant for a quick summary, through whichever account the person already had.
ChatGPTA team standardising on a tool nobody procured because it answers questions from their own documents better than the approved search does.
GleanAn individual running a model locally on their own machine to avoid sending anything outside, which solves one exposure and creates a different unmanaged one.
OllamaA department wiring an assistant into an automation so it processes records unattended, which turns occasional personal use into a standing unreviewed flow of company data.
Make
Common misconceptions
People assume
This is a discipline problem.
In fact
It is overwhelmingly a supply problem. The people doing it are usually the ones most engaged with their work, using a tool that helps, because nothing sanctioned was offered. Treating it as misconduct loses that information and teaches people to stop mentioning it, which removes the last cheap way of finding out.
People assume
A ban solves it.
In fact
A ban without an approved alternative generally moves the activity onto personal devices and out of sight. The organisation ends up with the same exposure and less visibility, which is a worse position than the one it started from and harder to detect.
People assume
Our staff would not put anything sensitive into one of these.
In fact
Sensitivity is judged against the task, not against the tool. A contract being summarised does not feel like a data transfer to the person doing it; it feels like reading a contract faster. That is why the material involved skews towards exactly the documents an organisation would most want to know about, and why asking people what they paste tends to be more revealing than asking whether they use AI.
People assume
We would know if it were happening here.
In fact
Most of it leaves no trace in the systems an organisation normally watches. It happens in a browser, through a free account, on material that was already on the person's screen. Absence of evidence in the logs is weak evidence of absence in the work.
Telling them apart
Shadow AI vs AI policy
Shadow AI
The behaviour: unapproved tools in real use, usually invisible to the organisation.
The written response: what staff may and may not do, and through which accounts.
One is what is already happening; the other is the document written after somebody notices.
Questions
- How do we find out how much of it we have?
- Ask, without a penalty attached, and pair that with what expenses and browser telemetry show. Amnesty questions surface far more than monitoring does, because most of this was never concealed. People will tell you what they use if the answer does not get them into trouble, and they will stop telling you the moment it does.
- What is the first thing to do about it?
- Offer a sanctioned route for the two or three tasks that come up most, on business terms with an administered account. Supply removes most of the behaviour faster than policy does, because the behaviour was never about permission in the first place. The written policy then has something to point at.
- Is it worse than shadow IT was?
- It spreads faster and the material involved is usually more sensitive. Adopting an unapproved spreadsheet tool took a download and some setup; adopting an assistant takes a browser tab and a paste. The old category also rarely involved handing whole documents to a third party as a matter of routine.
- Which accounts actually matter here?
- The distinction is business terms against consumer terms for the same product. Business tiers commonly commit not to train on submitted content and give an administrator visibility; consumer tiers often do neither. Paying does not by itself settle it either, because a paid seat bought on somebody's own card is still invisible to the organisation. What matters is who administers the account rather than who pays for it.
- Should we name individuals when we find it?
- It is usually counterproductive. The information is worth more than the enforcement, and naming people converts a rich source of intelligence about unmet needs into silence. Address the pattern, supply the alternative, and keep the route open for the next person who finds something useful before somebody else does.
- What if the tool they chose is genuinely good?
- Then you have been handed a shortlist by the people who do the work, which is better market research than most procurement produces. The question becomes whether it can be bought properly, on business terms with an administered account, rather than whether it should be removed.
Key takeaways
- Shadow AI is unapproved use by people trying to do their existing work faster, not misconduct.
- The exposure is the account and its terms more often than the tool itself.
- The lost record is often more consequential than any single document sent.
- It concentrates in tedious tasks, which tells you what to sanction first.
- Prohibition without an alternative moves it out of sight rather than stopping it.
Last checked July 2026