what-is-shadow-ai-and-how-does-it-work
  • 25th Aug 2026
  • 1 min read

What Is Shadow AI and How Does It Work?

Gabriel Few-Wiegratz
  • Written by
Gabriel Few-Wiegratz
View my profile on
In Short..
  • Shadow AI is broader than ChatGPT: it also covers AI features quietly added to tools you've already approved, and AI used by suppliers who never disclosed it.
  • Most AI use at work already happens this way: 78% of AI users bring their own tools rather than anything IT has sanctioned (Microsoft/LinkedIn, 2024).
  • The exposure is legal as well as technical: UK GDPR treats an unapproved AI tool exactly like any other unauthorised data processor, whether or not anyone signed off on it.
  • Banning the tools shifts the risk rather than removing it: it moves usage onto personal devices, where the organisation has even less visibility than before.

Shadow AI is any AI tool, model, or capability used inside an organisation without the knowledge, approval, or oversight of IT, security, or compliance functions. It is the AI equivalent of shadow IT, spreading faster, touching more sensitive data, and staying far less visible. Most employees who use AI at work are already doing this: 78% bring their own AI tools to work rather than using anything IT has sanctioned, according to Microsoft and LinkedIn's 2024 Work Trend Index. In regulated sectors, where data classification, audit trails, and third-party processing agreements are legal requirements, that gap between AI use and AI oversight is a real and growing liability.

Expert View

undefined-May-25-2026-06-11-05-9774-PM

 

Matt Davies

Chief Product Officer, SureCloud

LinkedIn

 

 

What our experts say about shadow AI's governance gap

 

"The organisations that handle shadow AI well already had a risk register broad enough to absorb a new category without a special project. They extended what they had instead of starting over. The ones that struggle are usually building AI governance and general governance at the same time, from scratch, under real pressure."

 

Defining Shadow AI

Shadow AI refers to any AI tool, model, or capability used inside an organisation that sits outside sanctioned procurement, security review, or governance controls. Consumer applications such as ChatGPT, Claude, and Gemini are the most common entry point, but they're only part of the picture.

 

What Counts as Shadow AI

 

The category is broader than most organisations initially assume:

  1. Consumer AI tools used for work without IT approval, such as ChatGPT, Claude, Perplexity, or Copilot on a personal account
  2. AI features embedded in software that was approved before the AI arrived, a project management tool that quietly added generative AI, a CRM with AI-assisted drafting
  3. Browser extensions and plugins with AI capabilities installed locally on employee devices
  4. Departmental AI purchases made outside central IT, a marketing team's AI content platform or a finance team's forecasting tool, bought on a card and never registered
  5. AI used by third parties who process your data, a supplier that has built AI into its service delivery without disclosing it

The common thread is productivity. Employees don't need bad intentions for shadow AI to create exposure; they find a tool that helps them work faster and use it. What's missing is oversight.

How Shadow AI Spreads Inside Organisations

Shadow AI accumulates through dozens of individual decisions, each one feeling low-risk on its own, that add up to a large, untracked surface.

 

The individual workaround

 

An employee pastes a contract clause into a free AI tool to get a quick summary. A compliance analyst uses a chatbot to draft a policy section. A risk manager asks an AI assistant to reformat a spreadsheet. None of these feel like a security decision in the moment, yet each one may send business data to an external model with no data processing agreement in place.

 

The departmental purchase

 

Teams increasingly have their own budgets and the freedom to buy SaaS tools directly. When AI capability comes bundled into a tool procured outside IT, it bypasses the vendor assessment, data classification review, and contractual controls a central procurement process would normally apply. Under UK GDPR, using a third-party processor without a lawful basis and a Data Processing Agreement is a compliance failure, regardless of intent.

 

The platform update

 

Approved tools add AI features continuously. Microsoft 365 Copilot, Salesforce Einstein, Slack AI, and Notion AI sit inside your existing governance because you already approved the platform; the AI capabilities layered on top of them, though, can fall outside the scope of the original data processing review. An organisation that approved a collaboration platform in 2022 may be running AI summarisation across internal communications today without ever having updated its records of processing activities.

 

The governance gap that catches most teams out sits inside tools that were approved once and have quietly changed since.

What Shadow AI Actually Exposes

The risks of shadow AI are real, and the conversation about them is usually too narrow. Data leakage gets most of the attention. The full picture is wider.

 

Data and privacy exposure

 

When employees submit prompts containing personal data, confidential business information, or regulated content to external AI models, that data may be retained, used to train the model, or made accessible to third parties. Many free-tier AI tools state directly in their terms of service that user inputs can be used to improve the model. Cisco's 2025 Data Privacy Benchmark Study found that 42% of respondents have entered non-public company information into a generative AI tool. That's a substantial share of a workforce doing this routinely.

 

Under UK GDPR, that constitutes a transfer of personal data to a third-party processor. Without a Data Processing Agreement, a lawful basis for processing, and a transfer mechanism where the provider sits outside the UK or EEA, the organisation is in breach. That's true regardless of whether any harm results.

 

Audit and evidence gaps

 

For compliance and audit functions, shadow AI creates a records problem. If an employee uses an AI tool to draft a risk assessment, summarise a control test, or produce a supplier evaluation, the output survives, but the reasoning behind it usually goes unrecorded.

 

This matters under frameworks including ISO 27001:2022, DORA (the EU's Digital Operational Resilience Act), and the EU AI Act, all of which require organisations to show how a decision was made and by whom. An AI-assisted decision with no record of the tool used, the prompt submitted, or the human review applied is an audit finding waiting to happen.

 

Third-party and supply chain risk

 

Shadow AI extends into your supply chain too. If a supplier uses AI to process data on your behalf without disclosing it, your third-party risk management programme may never have captured that fact. Vendor questionnaires written before AI's mainstream adoption rarely ask whether AI is involved in service delivery at all, and most TPRM programmes are still catching up.

 

The attack surface

 

AI tools introduce their own attack vectors. Prompt injection, model poisoning, and data exfiltration through AI interfaces are documented threat categories. Tools that IT hasn't assessed sit outside the security monitoring perimeter by definition, and an organisation can't detect anomalous behaviour in a system it can't see.

 

Risk category

What it means in practice

Data leakage

Personal or confidential data submitted to external models with no Data Processing Agreement in place

Compliance breach

UK GDPR, DORA, or sector rules breached without the organisation ever finding out

Audit gap

AI-assisted outputs with no traceable process or human review record

Supply chain exposure

Suppliers using AI to process your data without disclosing it

Security blind spot

Unmonitored AI tools sitting outside the security perimeter

Why Banning AI Tools Backfires

The instinctive response to shadow AI is prohibition: block the tools, issue a policy, send the all-staff email. It's an understandable reflex that fails in practice.

 

KPMG's 2025 global study on AI trust and attitudes found that 44% of employees have used AI in ways that contravene their employer's policies. A written rule rarely changes behaviour that a productivity deadline is already pushing people toward. Employees who rely on AI to hit their targets keep using it; they just move to personal devices, personal accounts, or more obscure tools that are harder to detect. That's the trade-off: the organisation loses visibility rather than gaining it.

 

The real objective is to bring AI use inside governance.

 

Visibility, knowing what AI tools are actually in use, by whom, and on what data, usually starts with a discovery exercise: network traffic analysis, employee surveys, procurement reviews, and updated vendor questionnaires. Policy needs to be proportionate: a rule too restrictive gets ignored, and a rule too vague is useless. And controls are what make compliance realistic in practice: an approved-tool register, AI-specific data classification guidance, DPIA templates for AI use cases, and third-party questionnaires that ask directly about AI in service delivery.

 

The ICO's guidance on AI and data protection makes clear that organisations are responsible for how AI processes personal data, whether or not the tool was formally sanctioned. Ignorance of what employees are using still leaves the organisation accountable.

What Good AI Governance Looks Like

Addressing shadow AI is an ongoing governance capability that has to keep pace with a market that moves every quarter. Organisations that treat it as a one-time project, audit once, write a policy, file it, tend to find the problem has already moved on by the time the policy gets published.

 

An AI asset register tracks every AI tool in use: approved, under review, and flagged. It records the tool, the use case, the data it accesses, the vendor's data processing terms, and the review status. Without it, demonstrating compliance, responding to a data subject access request involving AI-processed data, or assessing exposure under the EU AI Act's risk classification framework all become guesswork.

 

AI-specific risk assessments treat AI use cases as distinct risk items rather than generic software. A DPIA for an AI tool needs to address model training practices, data retention, output accuracy, and human oversight, questions a standard software procurement review never asks.

 

Continuous monitoring keeps the register current. New tools appear constantly, approved tools add AI features, and suppliers change how they deliver a service. A programme that reviews AI use once a year is already behind by the time the review happens.

 

Human-in-the-loop requirements define where AI can act on its own and where a person has to review the output first. This matters most for regulated decisions: credit assessments, risk ratings, compliance determinations. The EU AI Act classifies many of these as high-risk AI use cases with mandatory human oversight built in.

 

That kind of traceability is what regulators are starting to expect by default.

 

 

"SureCloud's event-based architecture converts every user action into a discrete, traceable event. As regulatory scrutiny intensifies, this architecture will be particularly valuable for firms handling sensitive data in highly regulated sectors."

 

Verdantix, 14 Innovative Vendors Advancing GRC In 2026

 

SureCloud's AI Governance product is built to run this shape of work: an AI asset register covering every AI tool in the business, categorised against the EU AI Act's risk classification framework, alongside AI-specific risk assessments and incident capture that surfaces a problem before it becomes a reportable breach. Inside the platform, Gracie AI Agents with Personas and Skills perform the ongoing register maintenance and evidence collection that continuous monitoring actually requires, so a compliance team reviews exceptions and flagged risks instead of chasing an inventory by hand.

 

The organisations best placed to manage shadow AI are usually the ones that already run a mature governance, risk, and compliance (GRC) programme: they had somewhere to put a new risk category the moment it appeared. Shadow AI keeps expanding faster than most governance programmes are built to track, and it responds to the same governance discipline everything else in the business already runs on.

 

Choosing the right detection and governance platform is the next decision. See How to Detect and Manage Shadow AI Usage: A Platform Decision Guide for how the four platform categories compare.

Google preferred sources
Found this useful?

Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.

Bring Shadow AI Inside Your Governance Programme

SureCloud's Gracie AI Agents with Personas and Skills maintain your AI asset register, run AI-specific risk assessments, and flag incidents before they become reportable breaches, contributing to a 50 to 65% reduction in manual evidence collection once AI use sits inside the same programme as everything else. Book a personalised demo to see how it maps against your own AI footprint.
Latest articles:

Shadow AI Governance Guide: Best Platform 2026

  • Cyber Security

Cyber Security Risk Management: Process & Frameworks

  • SOC 2

Best SOC 2 Compliance Software for UK SaaS Teams in 2026

Share this article

FAQ’s

What is shadow AI?

Shadow AI is any AI tool, model, or capability used inside an organisation without the knowledge or approval of IT, security, or compliance functions. It includes consumer tools like ChatGPT used for work, AI features added to software you've already approved, browser extensions, departmental SaaS purchases, and AI used by suppliers who haven't disclosed it. Most shadow AI use is productivity-driven rather than malicious, which is exactly why oversight matters more than intent.

Is shadow AI illegal?

Shadow AI creates real legal exposure the moment personal data is involved. Under UK GDPR, using an AI tool that processes personal data without a Data Processing Agreement or a lawful basis is a compliance breach, regardless of intent. DORA and the EU AI Act add further requirements around auditability and human oversight that shadow AI use usually can't satisfy.

Why do employees use shadow AI?

Productivity. Employees find a tool that helps them work faster and use it, generally without weighing the governance implications first. It's what happens when AI adoption moves faster than the policy and controls meant to govern it.

Why doesn't a blanket ban work?

Bans push shadow AI further underground instead of eliminating it. Employees who relied on AI to meet workload demands switch to personal devices or harder-to-see tools, leaving the organisation with even less visibility than before. The better goal is bringing AI use inside governance, where it can actually be seen and managed.

What frameworks apply to shadow AI governance?

UK GDPR, DORA, ISO 27001:2022, the EU AI Act, and ISO/IEC 42001:2023, the international standard for AI management systems, all have a bearing depending on sector and use case. The EU AI Act carries the most specific obligations: it introduces risk classification requirements and mandatory human oversight for high-risk AI applications, exactly the kind of evidence shadow AI use usually can't produce.