Most enterprise IT teams learned about Shadow IT the same way: after an incident. The post-mortem named a tool nobody knew was in use.
Shadow AI follows the same pattern, faster and with a wider blast radius. One prompt to a public generative AI tool can move sensitive code, customer data or commercial detail outside your control in seconds. Once data crosses that boundary, your ability to govern retention, review, reuse and access depends entirely on the provider, the plan tier and whatever happened to be configured.
No policy matters until you can see what is actually being used.
Key takeaways
- Shadow AI is AI use without oversight. IT, security and legal never saw it. It covers public tools and the AI features quietly enabled inside approved SaaS.
- Bring-your-own-AI is the norm. 78% of AI users bring their own tools to work (Source: Microsoft and LinkedIn, 2024 Work Trend Index).
- Sensitive data is going in. 68% of employees use free-tier AI tools through personal accounts, and 57% input sensitive data (Source: Menlo Security, 2025 report on AI and the modern workspace).
- The cost is measurable. Breaches involving a high level of Shadow AI cost around $670,000 more than average, and 20% of breached organisations were compromised through Shadow AI (Source: IBM, Cost of a Data Breach Report 2025).
- 2026 is a regulatory tipping point. EU AI Act obligations phase in, with key dates already live.
- Governance needs four pillars. Visibility, Optimization, Management, Governance — in that order.
What is Shadow AI?
Shadow AI is the use of AI tools, AI features or AI agents inside an organisation without IT review, security approval or governance oversight.
In practice it appears in three patterns:
- Public AI tools on work accounts. Someone signed up to try it and never stopped.
- Personal AI accounts on work devices. Harder to detect and harder to govern.
- Hidden AI inside approved SaaS. Features enabled by default, or switched on quietly during a renewal or a rollout.
Most enterprises have learned that bans alone rarely stop usage. They push it onto personal devices and home networks, which reduces visibility further. The sustainable move is to discover, govern, then provide a sanctioned path.
Shadow AI versus Shadow IT: what is different now
Shadow AI is sometimes treated as another Shadow IT category. That understates it.
1. Data can leave the business in a single prompt
With legacy Shadow IT, an unapproved file share might sit unnoticed for months. With Shadow AI, sensitive content is copied into a prompt instantly, and what happens next depends on provider terms, plan tier and configuration you did not set.
Your SaaS list can look clean while AI features inside approved tools are live, licensed and in daily use. Feature-level governance matters as much as app-level governance.
3. AI is becoming agentic and permissioned
As AI tools move from answering prompts to executing tasks, the risk resembles an unmanaged digital worker. These agents often hold delegated access across mail, documents and business systems — and that access usually arrived through an OAuth grant nobody reviewed.
Shadow AI needs its own discovery and governance lens. Copying the Shadow IT playbook across will not cover it.
How big is the problem?
- 78% of AI users bring their own AI tools to work (Source: Microsoft and LinkedIn, 2024 Work Trend Index).
- 68% of employees use free-tier AI tools through personal accounts, and 57% of them input sensitive data (Source: Menlo Security, 2025 report on AI and the modern workspace).
- $670,000 in additional average breach cost is associated with a high level of Shadow AI involvement, and 20% of breached organisations were compromised through it (Source: IBM, Cost of a Data Breach Report 2025).
- 97% of breached organisations lacked proper AI access controls (Source: IBM, Cost of a Data Breach Report 2025).
Real incidents: what has already gone wrong
Shadow AI is not theoretical. The pattern is consistent: usage expands fast, data leaks, a ban follows, and usage moves out of sight.
In 2023, Samsung restricted the use of ChatGPT and other AI tools after reports of sensitive internal code being uploaded. The operational lesson is the same one every time. You cannot govern what you cannot see.
Regulation and standards: the 2026 shift
In 2024 and 2025, Shadow AI was treated as an internal IT and security issue. In 2026 it becomes an external assurance issue, driven by regulation, customer scrutiny and auditable standards.
EU AI Act (Regulation (EU) 2024/1689)
The Act applies in stages rather than on a single date. Several implementation requirements are already in motion.
NIS2: supply chain security and risk management
NIS2 calls for risk-management measures covering supply chain security and the governance of the systems and service providers you rely on. Shadow AI tools bypass vendor due diligence entirely, which is an obvious gap against those expectations.
ISO/IEC 42001: an emerging AI management standard
ISO/IEC 42001 sets out requirements for an AI management system. It is still maturing, but the practical takeaway holds: you need a clear, current view of what AI is in use, where it runs and who owns it.
If your teams cannot produce an AI inventory covering tools, embedded AI features and ownership, your governance is not operational.
The four blind spots that make Shadow AI hard to govern
- Hidden AI inside approved SaaS. Features enabled by default or rolled out mid-contract.
- Blanket bans. They push usage onto personal devices, which means less telemetry and less control.
- Agentic tools and integrations. Tools that act across systems with delegated permissions.
- AI cost sprawl. Duplicate subscriptions, overlapping add-ons and consumption procurement cannot see.
What a workable AI use policy looks like
A policy that survives contact with reality is simple, clear and enforceable. It needs:
- Approved use cases. What is allowed, for which roles, in which tools.
- Prohibited data classes. What must never go into a non-approved tool.
- A review path. How a team requests a new tool or a new use case.
- Legal, privacy and procurement sign-off. Terms, DPAs and a commercial route.
- Practical training. Short rules people actually remember.
- An inventory and an ownership model. Named, accountable owners.
A policy without discovery is a paper exercise. Discovery without policy is a list with no decision rights. You need both.
Discovery first: the standard for Shadow AI visibility
To govern Shadow AI you need a discovery layer that does four things:
- Sees AI tool use at the user and device level, usually browser-led.
- Sees AI applications through identity — SSO logs, Entra ID and Okta.
- Recognises the major AI providers directly, with evidence beyond a site visit.
- Catalogues and classifies what it finds. Without classification, the output is noise.
How CerteroX approaches discovery
CerteroX SaaS Management is built around a discovery-and-classification loop, and Shadow AI is a first-class part of it rather than a footnote.
Three converging discovery signals. A browser extension detects SaaS and AI domains with time-on-app and per-user attribution. Identity provider sync from Entra ID and Okta brings in users, groups and MFA enrolment. Vendor connectors — 47 shipping today — pull authoritative user and licence lists directly from the provider. OAuth grant discovery surfaces the third-party applications your users have consented to.
Classification that keeps up. Discovered applications resolve against a catalogue of more than 35,000 applications. AI tools are classified from application feature tags rather than a hardcoded list, so the detection set grows on its own instead of waiting for the next release.
Risk you can rank. The Shadow AI dashboard applies a three-tier adoption risk model and ranks tools by the share of your organisation using each one — because ten people on a public chatbot is a different problem from a thousand. OAuth grants are scored from 0 to 100 on data sensitivity, scope, consent and dormancy, and can be revoked in one click or by workflow.
Governance that closes the loop. Every discovered AI tool carries a status — managed, blocked or ignored. Risk assessment covers data sensitivity and exposure under GDPR, HIPAA and SOC 2. Per-application AI budgets carry warning and critical thresholds. The workflow engine can alert, block or revoke automatically on detection, and every provisioning and deprovisioning step is written to an audit log.
One honest limit: CerteroX does not automatically map findings to EU AI Act risk categories. That classification remains a judgement your governance function makes, with the inventory underneath it.
To see Shadow AI discovery classify a tool nobody approved and score what it was granted, get in touch.
Where to start: a plan across the four pillars
1. Visibility — discover and classify. Build the best inventory you can of AI tools, embedded AI features and access paths. Give every item a provisional risk tier so you can prioritise.
2. Optimization — turn usage into decisions. Ongoing telemetry tells you whether usage is shifting, escalating, or being driven into the shadows by a policy change. Use it to consolidate duplicate subscriptions, reclaim seats nobody has opened, and cut the overlapping add-ons that make AI spend hard to read.
3. Management — owners, policy, sanctioned paths. Assign an application owner and a data owner to every item. Codify the policy. Provide sanctioned alternatives so usage moves back into the light, where controls actually work.
4. Governance — evidence and assurance. Document the evidence so the policy holds up under audit or customer scrutiny. Tie it back to the regulations you have to answer to: the EU AI Act, NIS2, ISO/IEC 42001 and the assurance questionnaires your customers send.
Discover usage. Assign owners. Apply policy. In that order — because the first one is what makes the other two possible.