Nearly 90% of AI use inside large organisations goes unseen by IT.
That is worrying when you set it alongside a separate finding, reported by SC Media, that 38% of employees who use AI at work admit to putting sensitive data into AI applications without their employer’s knowledge or consent.
Shadow AI is growing, mostly through consumer generative AI applications such as ChatGPT and Claude. Businesses are at a crossroads: one of the most disruptive technologies in a generation, and a live risk to sensitive data, arriving through the same door at the same time.
What is Shadow AI?
Shadow AI is any application used without IT’s knowledge that carries an element of artificial intelligence.
You will think first of ChatGPT and its equivalents. But it could be anything with AI inside it — a CRM platform that interrogates customer interactions, a service desk tool, or a meeting recorder that produces AI-generated transcripts and notes.
It is spreading fast. In the UK, Microsoft’s research found 71% of employees admit to using unapproved AI tools at work, and more than half of those use them at least weekly (Microsoft / Censuswide, October 2025).
The distinction matters. Shadow IT is any asset running in your environment that you do not know about — hardware or software. Shadow AI is specifically an application that is either entirely AI or has AI inside it.
Arguably it is the more dangerous of the two. Unlike general IT, Shadow AI actively consumes sensitive data, can retain and reuse that data unpredictably to train models, and offers no transparency into how the information was used.
Why does Shadow AI happen?
It sounds sinister. It rarely is.
Usually an employee finds a tool that makes their day easier — and there are a great many of them now — and does not want to sit through a lengthy approval process. So they sign up for the free tier and start using it. Sometimes a team puts a little budget behind something they have found useful.
A salesperson downloads a call recorder. Marketing uses ChatGPT to draft buyer personas. Legal runs documents through an AI tool for research.
Very rarely is there any intent to cause harm. You could even read it as a good sign — people looking for better ways to work — if it did not create a stack of risk on the way.
What are the risks of Shadow AI?
Part of what makes Shadow AI more dangerous than Shadow IT is that nobody is entirely clear how the data going in is stored or used.
There is still no settled common practice for processing personal data in AI engineering, which means every tool may handle information differently. It is also unclear where that information goes once it leaves your organisation.
Regulators have noticed. The Information Commissioner’s Office has issued guidance warning about putting sensitive business or personal data into AI systems:
AI systems introduce new kinds of complexity not found in more traditional IT systems that you may be used to using. Depending on the circumstances, your use of AI systems is also likely to rely heavily on third party code relationships with suppliers, or both.
— Information Commissioner’s Office
Within that, there are four risks worth separating.
Data privacy and regulation
The largest single risk is sensitive information leaking, or a compromise in an AI application reaching further into your systems.
It has already happened. In August 2025, OpenAI removed a public sharing feature from ChatGPT after shared conversations began appearing in Google search results. OpenAI said at the time that the feature “introduced too many opportunities for folks to accidentally share things they didn’t intend to”.
Now imagine commercial or personal information inside those conversations, suddenly findable by anyone. Set that against GDPR and the fines attached to it, and the exposure is clear.
Reputation damage
The knock-on effect. If it emerged that your organisation had put customer data into an AI tool without permission — and worse, that the data then surfaced publicly — how much customer trust would survive it?
Ask the question the other way round. How much would you trust a business that had used your data like that?
Lack of visibility
You cannot govern what you cannot see. Not knowing which tools are in use, how they are being used or what they cost is the same fundamental problem as Shadow IT, and the growth rate is the reason it is urgent: AI-native application spend at large enterprises has risen 393%.
AI adds a second visibility problem on top of the first — you also cannot see what those tools are doing with your data.
Under rules such as GDPR you are obliged to maintain transparent audit trails of how data is collected, stored and used, to minimise its use, and to erase it on request. Submit that information into an unknown AI tool and you lose the ability to comply with any of it.
Complying with data regulation is hard enough without visibility of general IT. It is impossible without oversight of AI tools and no understanding of how each one treats your data.
A larger attack surface
Shadow IT extends your attack surface. Shadow AI extends it further, because employees are actively moving company and personal data into systems you do not control, cannot see and cannot secure.
A marketing manager pasting a customer list into a chatbot, or a developer pasting source code into a coding assistant, has bypassed your enterprise security entirely — and you would never know.
Compare it with a sanctioned SaaS tool. When that is compromised you get a breach notification, you have a contract to refer to, and you know what data was in it. With Shadow AI you have none of those things. You did not know the tool existed, there is no audit trail of what was uploaded, you cannot establish what was exposed, and you have no proof of compliance.
How to manage the risks of Shadow AI
The fundamentals are the same as managing any Shadow IT. What has changed is that the tooling to do it now exists.
1. Find out what is actually being used
You cannot manage what you cannot see, so visibility comes first.
CerteroX SaaS Management discovers applications through three converging signals rather than one: identity provider sync from Entra ID and Okta, connector sync pulling authoritative user and licence lists directly from the vendor, and a browser extension that detects SaaS domains, time-on-application and per-user attribution. That third signal is the one that catches personal-account AI use, which is precisely the traffic an identity provider never sees.
AI tools are then classified from application feature tags in a catalogue of more than 35,000 applications, not from a hardcoded list — so the detection set grows on its own as new tools appear, instead of waiting for someone to add them.
2. Understand how they are being used
The common mistake is a blanket ban. It throws away the tools your teams have already proved useful.
Once you know what is in use, look at how. There may be duplicates you can consolidate and adopt formally. There may be genuine productivity gains that only need guidelines around access or data handling.
The Shadow AI dashboard ranks adoption risk across three tiers by the share of your organisation using each tool, because ten people on a chatbot is a different problem from a thousand. App Rationalization then shows overlap ranked by recoverable saving, which is where consolidation decisions get made.
Look for the opportunity, not just the exposure.
3. Set an allowed and disallowed list — and enforce it
You may not want to ban every AI tool, but you do want control over what is used.
CerteroX AI Management carries a status workflow for exactly this: every detected AI tool is marked managed, blocked or ignored. Alongside it, OAuth grant discovery finds the third-party applications your users have consented to, scores each grant from 0 to 100 on data sensitivity, scope, consent and dormancy, and lets you revoke it in one click — or automatically, as a workflow action. Risk assessment covers data sensitivity and GDPR, HIPAA and SOC 2 exposure, and per-application budgets carry warning and critical thresholds.
Judge each tool against your own compliance standards and decide what control it needs. A tool might be genuinely useful for productivity while still requiring restrictions on what can be put into it.
This is not a one-off exercise. Scheduled data agents keep discovery running, so newly adopted tools surface as they appear rather than at the next review.
Managing innovation against Shadow AI risk
There is a genuine risk-and-reward trade here.
With any fast-moving technology there is an element of the unknown, and AI is changing quickly enough that keeping up with how each tool works, how it handles data and what it introduces is a real effort.
Used properly and with some control, though, these tools can change processes and lift productivity substantially.
However you choose to handle AI, the thing that matters is a clear picture of what is in use and how — so you can protect the business without shutting down the innovation.
Book a demo to see how CerteroX surfaces Shadow AI, or read more about AI governance.