Personal accounts on approved tools
You have an enterprise tenant with a DPA and no-training terms. An employee is logged into their personal account in another browser profile. Your contract governs the tenant; their session is outside it entirely.
Glossary
Shadow AI is employee use of AI tools outside sanctioned, governed channels: personal accounts on approved products, entirely unapproved tools, and AI features embedded in software that was approved before those features existed.
Three forms
You have an enterprise tenant with a DPA and no-training terms. An employee is logged into their personal account in another browser profile. Your contract governs the tenant; their session is outside it entirely.
A new AI product launches, does one job exceptionally well, and someone starts using it. It is on no list because nobody has heard of it yet.
The subtle one. Your note-taking app, CRM, design tool and helpdesk all shipped AI features after you approved them. The vendor is approved; the data flow to a model provider is new.
Nobody signed off on the third form. It appeared in a release note.
Not the same as shadow IT
Shadow IT was mostly about where data was stored — an unsanctioned sync tool holding documents somewhere unknown. That is bounded and discoverable: find the tool, migrate the data, revoke access.
Shadow AI is about what data was disclosed, once, in a message. There is no repository to discover afterwards. The disclosure has already happened, and deleting the conversation does not undo it.
The discovery techniques differ too. Finding an unsanctioned SaaS app means looking at OAuth grants and DNS. Finding shadow AI means looking at what was typed — which most of the stack cannot see.
Why it resists measurement
Any list of AI tools is incomplete by the time it ships.
A textarea and a send button look identical across every tool, sanctioned or not.
Nothing appears in a file system, a sync log or an OAuth grant.
Block the domains and usage moves to personal phones where you have no telemetry. Visibility drops; exposure does not.
What actually helps
Distinguish destinations rather than treating all AI traffic identically — the same card number is a different event depending on where it went. Detect at the composer rather than the network, so you see content and not just connections. Flag submissions to unrecognised hosts that look like AI interfaces, which turns an unbounded unknown into a triage queue.
Above all, give people a sanctioned tool that is genuinely good enough for the work. Most shadow AI is not defiance; it is someone trying to finish a task with the best tool they could find.
Related terms
The AI features inside software you already approved are the ones nobody has assessed.