Glossary

Shadow AI

Shadow AI is employee use of AI tools outside sanctioned, governed channels: personal accounts on approved products, entirely unapproved tools, and AI features embedded in software that was approved before those features existed.

SANCTIONED OUTSIDE IT
The governed set is small. What appears outside it is not.
Three forms Personal accounts Unapproved tools Features in approved software

Three forms

The third is the one most organisations miss.

Personal accounts on approved tools

You have an enterprise tenant with a DPA and no-training terms. An employee is logged into their personal account in another browser profile. Your contract governs the tenant; their session is outside it entirely.

Unapproved tools

A new AI product launches, does one job exceptionally well, and someone starts using it. It is on no list because nobody has heard of it yet.

AI features inside approved software

The subtle one. Your note-taking app, CRM, design tool and helpdesk all shipped AI features after you approved them. The vendor is approved; the data flow to a model provider is new.

And it arrives without a decision

Nobody signed off on the third form. It appeared in a release note.

Not the same as shadow IT

One is about storage. The other is about disclosure.

Shadow IT was mostly about where data was stored — an unsanctioned sync tool holding documents somewhere unknown. That is bounded and discoverable: find the tool, migrate the data, revoke access.

Shadow AI is about what data was disclosed, once, in a message. There is no repository to discover afterwards. The disclosure has already happened, and deleting the conversation does not undo it.

The discovery techniques differ too. Finding an unsanctioned SaaS app means looking at OAuth grants and DNS. Finding shadow AI means looking at what was typed — which most of the stack cannot see.

Why it resists measurement

Four properties, all working against you.

  1. 01

    Domain lists go stale

    Any list of AI tools is incomplete by the time it ships.

  2. 02

    The interface is generic

    A textarea and a send button look identical across every tool, sanctioned or not.

  3. 03

    No artefact is left behind

    Nothing appears in a file system, a sync log or an OAuth grant.

  4. 04

    Blocking hides it

    Block the domains and usage moves to personal phones where you have no telemetry. Visibility drops; exposure does not.

What actually helps

Mostly, a good sanctioned tool.

Distinguish destinations rather than treating all AI traffic identically — the same card number is a different event depending on where it went. Detect at the composer rather than the network, so you see content and not just connections. Flag submissions to unrecognised hosts that look like AI interfaces, which turns an unbounded unknown into a triage queue.

Above all, give people a sanctioned tool that is genuinely good enough for the work. Most shadow AI is not defiance; it is someone trying to finish a task with the best tool they could find.

Find the third form first.

The AI features inside software you already approved are the ones nobody has assessed.