Compyl
GRC Your Way

What Is Shadow AI? How to Find and Govern Ungoverned AI

Last updated: September 24, 2026

Shadow AI is any AI tool, model, feature, or agent used inside an organization without the review, approval, or visibility of the teams responsible for security, privacy, and compliance. It includes employees pasting data into personal chatbot accounts, AI features switched on inside approved SaaS apps, and agents or API integrations built outside any governance process. You govern it the way you govern any unmanaged risk: find it, triage it, give people an approved path, and put controls and monitoring around what remains.

This guide is part of our complete guide to AI governance. It covers where shadow AI comes from, why it matters, and how to control it without banning useful tools.

Key takeaways

  • Shadow AI is broader than unapproved chatbots: it includes embedded SaaS AI features, browser extensions, personal API keys, and self-built agents.
  • IBM’s 2026 Cost of a Data Breach Report found shadow AI involved in 43% of the breaches studied, more than double the prior year.
  • Blanket bans tend to push usage further underground. An approved alternative plus clear rules works better.
  • Discovery is continuous, not a one-time audit: combine network and SaaS telemetry, expense data, vendor reviews, and employee self-reporting.
  • ISO 42001, the NIST AI RMF, and the EU AI Act all assume you know what AI you use. An inventory that captures shadow AI is the foundation for all three.

What counts as shadow AI?

Shadow AI is the AI-era successor to shadow IT, but it spreads faster because most AI tools need nothing more than a browser and an email address. In practice it falls into five categories:

  • Personal accounts on public AI assistants. Staff using free or personal chatbot, writing, or coding assistant accounts for work, often with company data.
  • Embedded AI in approved software. Vendors ship AI features into CRM, ticketing, document, and meeting tools, sometimes enabled by default. The app was approved; the AI capability and its data flows were not.
  • Browser extensions and plugins. Summarizers, transcription tools, and writing aids that can read every page and form an employee opens.
  • Developer-built integrations. Personal API keys wired into scripts, internal tools, or production code, and open-source models downloaded and run without review.
  • Autonomous agents. Agents connected to email, calendars, code repositories, or business systems with delegated credentials, acting without anyone in governance knowing they exist.

The common thread is not the technology but the absence of a decision: nobody accountable assessed the data it touches, the outputs it produces, or the obligations it triggers.

Why is shadow AI a governance problem, not just a security problem?

The security risk is real. IBM’s 2026 Cost of a Data Breach Report, based on 602 breached organizations, found shadow AI involved in 43% of incidents, up from 20% a year earlier, and more than two-thirds of organizations said they had no governance processes to limit it. The 2025 edition put the added cost of high shadow AI usage at roughly $670,000 per breach.

The exposure goes well beyond breaches:

  • Data protection. Personal data sent to an unvetted provider may have no lawful basis, no data processing agreement, and no control over retention or model training.
  • Confidentiality and IP. Source code, contracts, and strategy documents pasted into consumer tools can leave your control permanently.
  • Regulatory obligations. Under the EU AI Act, obligations attach to the use of an AI system in a professional context, not to whether IT approved it. If a team uses an unvetted tool to screen CVs or evaluate staff, that can be a high-risk use case carrying deployer duties such as human oversight and log retention. The Digital Omnibus (Regulation (EU) 2026/1744) moved the Annex III high-risk obligations to December 2, 2027, but did not remove them.
  • Decision quality. Outputs from unmonitored tools end up in customer communications, code, and reports without anyone validating accuracy or bias.
  • Audit and certification. If an auditor finds AI in use that is missing from your inventory or scope, it undermines the credibility of your whole AI management system.

Why do employees use shadow AI?

Almost always to get work done faster. Most shadow AI is not malicious; it fills a gap between what people need and what the organization has provided. Common drivers are no approved tool, an approved tool that is noticeably worse than a consumer alternative, a slow or opaque approval process, and unclear rules about what is allowed. A ban does nothing about an unmet need, and surveys suggest many workers find workarounds when applications are blocked.

How do you find shadow AI in your organization?

No single signal catches everything, so combine several sources and repeat on a schedule:

  1. Network and secure web gateway logs. Look for traffic to known AI domains and APIs. Many CASB and SSE tools now include AI app categories.
  2. SaaS management and SSO data. Identify AI apps connected via OAuth, sign-ups with corporate email addresses, and third-party apps granted access to mail, files, or calendars.
  3. Endpoint and browser inventory. Review installed desktop AI clients and browser extensions with broad page permissions.
  4. Expense and procurement records. Small card purchases and subscriptions are a reliable indicator of team-level adoption.
  5. Code and cloud scanning. Search repositories and secret stores for AI provider API keys and SDK imports, and check cloud accounts for model hosting and AI service usage.
  6. Vendor reviews. Ask existing vendors whether AI features are enabled, what data they use, and whether customer data trains models. A vendor AI questionnaire standardizes this.
  7. Amnesty surveys. Ask teams directly what they use, with a clear promise that disclosure will not be punished.

Everything you find goes into a single register. Our guide to building an AI system inventory covers the fields to capture, including owner, purpose, data categories, vendor, and risk tier.

How do you govern shadow AI once you find it?

Triage every discovery

Sort each tool into one of four outcomes: approve as is, approve with conditions (for example, enterprise tier only, no personal data, SSO required), replace with an approved alternative, or block. Base the decision on data sensitivity, vendor terms, and the use case, not on the tool’s popularity.

Provide a sanctioned path

The most effective control is an approved AI tool that people actually want to use, backed by enterprise terms that exclude training on your data. Pair it with a lightweight intake form so new requests get a decision in days, not months.

Set clear rules

Employees need to know what data they can put into which tools, which uses need review, and how to disclose AI-generated output. An AI acceptable use policy does this in plain language, and it sits under a broader AI governance policy that assigns ownership.

Assess the risky uses

Any tool that touches personal data, makes or supports decisions about people, or feeds customer-facing output needs a documented risk assessment. The AI risk assessment guide walks through the method.

Apply technical guardrails

Use SSO and conditional access for approved tools, data loss prevention rules for sensitive data sent to AI endpoints, extension allowlists, and secret scanning for AI API keys. Block only what you have decided to block, and tell people what to use instead.

Train and monitor

Training explains why the rules exist and how to use approved tools well. Article 4 of the EU AI Act, as amended by the Digital Omnibus, requires providers and deployers to take measures to support the development of AI literacy among their staff, and a shadow AI program is practical evidence of that. Rerun discovery at least quarterly and track the trend: the goal is a shrinking gap between AI in use and AI in the inventory.

Shadow AI response options compared

ApproachWhat it looks likeStrengthWeakness
Blanket banBlock all public AI tools at the network edgeFast to implement, simple messagePushes use to personal devices, loses productivity, no visibility
IgnoreNo policy, no monitoringNo frictionUnmanaged data exposure, regulatory and audit risk
Detect and block case by caseSecurity tooling flags and blocks risky appsTargets real riskReactive, no approved alternative, users route around it
Govern and enableApproved tools, clear policy, fast intake, inventory, monitoringReduces risk while keeping productivity; audit-readyNeeds ownership and ongoing effort

How do AI governance frameworks address shadow AI?

None of the major frameworks use the term, but all of them require the capabilities a shadow AI program builds. ISO 42001 requires you to define the scope of your AI management system (clause 4.3) and includes Annex A controls on resources for AI systems (A.4), use of AI systems (A.9), and third-party and customer relationships (A.10), none of which can be met for AI you do not know about. The NIST AI RMF calls for mechanisms to inventory AI systems (GOVERN 1.6). The EU AI Act attaches obligations to the use of AI regardless of how it was procured. For how these fit together, see our AI governance framework comparison.

Frequently asked questions

Is shadow AI the same as shadow IT?

It is a subset with sharper edges. Shadow IT covers any unapproved technology. Shadow AI adds risks specific to AI: data used for model training, unpredictable outputs, automated decisions about people, and AI-specific regulation.

Should we ban ChatGPT and similar tools?

A ban without an alternative rarely works. Most organizations get better results by approving an enterprise-grade tool with data protections, restricting consumer accounts, and publishing clear rules about sensitive data.

Are AI features inside approved SaaS apps shadow AI?

They can be. If a vendor enabled an AI feature that processes your data and nobody reviewed it, it is ungoverned. Include AI features in vendor reviews and contract renewals.

Who should own shadow AI governance?

Typically the AI governance lead or committee, with security running discovery and technical controls, privacy and legal assessing data and regulatory exposure, and business owners accountable for each approved tool.

Does the EU AI Act apply to shadow AI?

Yes. Its obligations follow how AI is used in a professional context, not whether it was formally approved, so an unapproved tool used for a high-risk purpose still creates obligations for the organization.

Bring shadow AI into the light

Shadow AI is a sign of demand, not just a risk. The organizations that handle it well turn discovery into an inventory, the inventory into risk-based decisions, and those decisions into evidence for ISO 42001, the NIST AI RMF, and the EU AI Act. Compyl helps teams do that on one platform, with a live AI inventory, vendor AI assessments, policy attestation, and controls cross-mapped across frameworks. If you are building toward certification, see how Compyl supports ISO 42001 compliance.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies