While security teams have developed strategies to address traditional shadow IT, shadow AI introduces new risks around data processing, retention, and unmonitored machine identities.
Imagine a customer service representative uploading sensitive customer data into an AI tool to draft emails more quickly. When an employee uses an AI tool without IT approval, it is known as shadow AI — and such scenarios are becoming increasingly common. Among employees who use AI at work, 78% report using tools that have not been formally approved by their organization.
While security teams have developed strategies to address traditional shadow IT, shadow AI introduces new risks that require a more modern approach. The main difference between shadow IT and shadow AI is that shadow AI not only transfers and stores sensitive data, but also actively processes and potentially retains it.
What is shadow IT?
Shadow IT refers to any software or cloud service that employees use without IT’s knowledge or approval. This can include using personal email accounts to share work files, installing unauthorized browser extensions, or connecting personal devices to a company network.
Although shadow IT is mainly driven by productivity instead of malicious intent, it introduces several key security risks:
• Limited visibility: When IT teams are unaware of unauthorized applications, they cannot monitor usage or protect company data. Any security vulnerability in those applications becomes a hidden entry point.
• Compliance violations: Unauthorized software rarely meets the data handling criteria of regulations like GDPR or HIPAA, exposing organizations to serious penalties.
• Expanded attack surface: Each unapproved application is a potential attack vector for cybercriminals, making perimeter defense increasingly difficult.
What is shadow AI?
Shadow AI refers to the use of AI tools or applications without IT’s knowledge or approval. Common examples include employees using generative AI to draft internal communications with confidential data, or developers running code through AI tools using personal accounts.
What makes shadow AI particularly challenging is that employees aren't always intentionally bypassing security measures — many modern applications have AI features embedded by default.
Shadow AI introduces risks that go beyond what many organizations are prepared to address:
• Untraceable data leaks: When employees use AI tools through personal accounts, organizations typically have no access to interaction logs. There is no audit trail of what data was entered, processed, or retained.
• Identity security implications: Shadow AI introduces new security risks around autonomous AI agents and machine identities. When accounts are created on external platforms, organizations lose control over access to sensitive data.
Key differences between shadow IT and shadow AI
Shadow IT and shadow AI share the same root cause of employees adopting tools to work more productively, but they differ in how they introduce risk:
• Data processing and sharing: Shadow IT follows structured processes like file uploads or document sharing. Shadow AI operates through unstructured, conversational inputs transmitted over standard HTTPS traffic, making it difficult to distinguish from normal web browsing.
• Visibility and auditability: Shadow IT generates audit trails through application usage and file transfers. Shadow AI often lacks centralized visibility since consumer-tier AI platforms rarely provide detailed interaction logs.
• Data retention risk: Shadow IT introduces risk around unauthorized storage in identifiable locations. Shadow AI introduces the risk that sensitive prompt data may be used to train third-party AI models by default.
How to detect and manage shadow AI
Because shadow AI exposes sensitive data in ways that are difficult to detect, organizations must take a proactive governance approach rather than issuing outright bans that drive usage further underground:
• Create an AI acceptable use policy defining approved tools and data boundaries.
• Build an internal AI app catalog of vetted, approved AI applications.
• Deploy enterprise-grade AI solutions that offer strict data privacy controls.
• Conduct regular AI compliance audits and ongoing employee training.
Take control of shadow AI
Shadow AI spreads quickly, operates through channels that are difficult to monitor, and introduces risks that traditional security tools weren’t designed to catch.
Governing it effectively requires centralized visibility and control over every identity — human and machine — that interacts with AI systems and the sensitive data they access.
This article is an attributed reprint from Keeper Security. Reproduced for our readers with credit to the original author.