Shadow AI
Shadow AI is the use of AI tools or accounts outside an organization's approved processes or visibility.
The term builds on shadow IT, which describes technology used without the knowledge or approval of an IT department. Shadow AI can mean an employee using a personal chatbot account for work, a team paying for an AI tool no one has reviewed, or AI features switched on inside existing software without anyone tracking them. It overlaps with undisclosed AI use, where an approved tool is used but no one says so. Both leave gaps in oversight.
The main risks are data exposure, such as company or customer information entering public tools, along with work whose quality no one can check. Stricter rules alone rarely make it go away. Shadow AI often signals that people see value in AI but lack approved tools, clear guidance, or a safe way to share what they are doing. Many organizations respond by pairing firm data rules with approved options and a simple way to disclose how AI is used.
Examples
Personal accounts. An employee drafts client emails with a personal chatbot account.
Unreviewed tools. A team signs up for an AI note-taking tool without a security review.
Sensitive uploads. Someone pastes customer data into a public AI tool to analyze it.
Hidden features. New AI features in licensed software get turned on without anyone assessing them.
Undisclosed use. An analyst uses AI for a report but doesn't say so, so reviewers can't check that part of the work.

