AI Governance

What Is Shadow AI?

Shadow AI is the use of AI tools, models or features at work without the approval or oversight of IT, security or compliance. It covers personal chatbot accounts, browser extensions, AI features switched on inside approved software, and model APIs or agents that teams set up on their own. Most of it is well meant: people reach for AI to work faster when no approved option exists.

  • Reliability & Governance
  • 10 min read
  • Updated October 2, 2026
  • VDF AI Team
01
In short

Shadow AI is the use of AI tools, models or features at work without the approval or oversight of IT, security or compliance. It covers personal chatbot accounts, browser extensions, AI features switched on inside approved software, and model APIs or agents that teams set up on their own. Most of it is well meant: people reach for AI to work faster when no approved option exists.

Key takeaways

  • 01 Shadow AI is widespread. In the 2024 Work Trend Index from Microsoft and LinkedIn, 78% of AI users said they bring their own AI tools to work.
  • 02 It now shows up in breach data: IBM reports that 43% of the organizations it studied had a security incident involving unapproved AI, up from 20% a year earlier.
  • 03 Detection needs several sources at once: CASB or SSE discovery, DNS and proxy logs, browser-extension inventory, code and secret scanning, expense and identity data, and simply asking.
  • 04 Blocking alone moves usage to personal phones. Pair controls with an approved assistant, a short acceptable use policy and a fast route for requesting new tools.
02

Shadow AI, defined

Shadow AI is the AI-specific part of shadow IT, meaning technology used without the organization’s knowledge or approval. What sets it apart is the data flow. An unapproved file-sharing tool stores documents; an AI tool receives the text of contracts, code, customer emails and plans in every prompt, and when it runs as an agent it can act on connected systems.

It takes several forms: personal accounts on consumer chatbots used for company work; embedded AI features that a vendor switches on inside software the company already approved; browser extensions that read every page a user opens; model APIs and local models wired into scripts and products without review; and, increasingly, agents, connectors and MCP servers that link an AI tool to internal systems with someone’s own credentials. Microsoft’s network-based shadow AI discovery, for example, looks for traffic to chatbots such as ChatGPT and Claude, to model provider APIs and to SaaS MCP servers (verified October 2026).

03

Why shadow AI happens

The 2024 Work Trend Index, a survey of 31,000 people in 31 countries, found that 75% of knowledge workers used generative AI at work and that 78% of those users brought their own tools. The pressure to work faster arrives long before procurement can respond, and only 39% of people using AI at work had received AI training from their company.

The same survey found that 52% of people who use AI at work are reluctant to admit using it for their most important tasks. That reluctance matters for detection: usage people hide will not show up in a survey, and usage on a personal phone will not show up in network logs. Shadow AI also grows without any decision by staff, whenever a vendor enables a new assistant inside a product that is already on the approved list.

04

Shadow AI risks

Data leakage. Consumer chatbot plans, ChatGPT’s among them, can use conversations for model training unless each user opts out, and the employer has no logs or retention control over a personal account. The ChatGPT data guide shows how that differs by plan.

Compliance gaps. A tool nobody reviewed has no data processing agreement, no entry in the records of processing and no assessment of where data goes. Under the EU AI Act, Article 4 has required AI literacy measures for staff since 2 February 2025, and an organization cannot train people on tools it does not know they use.

Security incidents and cost. In IBM’s 2025 Cost of a Data Breach study of 600 organizations, one in five reported a breach due to shadow AI, and organizations with high levels of shadow AI paid USD 670,000 more per breach than those with little or none. IBM’s 2026 figures show incidents involving unapproved AI rising from 20% to 43% of organizations, with 49% of those incidents leading to data loss or compromise and 21% to regulatory fines (verified October 2026).

Intellectual property and confidentiality. Source code, unreleased designs and client material pasted into an outside service leave the company’s control, and some data classes, such as privileged legal material or health records, carry duties a consumer tool cannot meet. Gartner predicts that by 2030 more than 40% of enterprises will have security or compliance incidents linked to unauthorized shadow AI; in its 2025 survey of 302 cybersecurity leaders, 69% suspected or had evidence of employees using prohibited public GenAI (Gartner).

05

How to detect shadow AI

No single source sees everything, so combine several and reconcile the results into one register. The comparison table below shows what each source finds and what it misses.

CASB and SSE discovery. Cloud access security brokers and security service edge platforms classify web traffic by application. Microsoft Defender for Cloud Apps, for example, has a Generative AI category covering more than a thousand apps, with a risk assessment for each, and lets admins sanction or block an app or block new ones automatically by risk score (verified October 2026).

DNS, proxy and firewall logs. Query for consumer AI domains and for model API hosts such as api.openai.com and api.anthropic.com. Model API traffic from a server or a developer laptop usually means code calling a model with a personal or team key.

Browser extension inventory. Managed browsers can report installed extensions. The apps and extensions usage report in Chrome Enterprise Core shows install counts, requested permissions and third-party risk scores across enrolled browsers, which helps spot AI assistants that can read every page.

Code and secret scanning. Search repositories for model SDKs in dependency files, and add model API key formats to the secret scanning you already run.

Expense, procurement and identity data. Card and expense claims reveal paid AI subscriptions, and OAuth consent logs in your identity provider show which AI apps staff have connected to company accounts.

Ask. A short survey, or an amnesty period in which staff can register tools without penalty, finds the usage that never touches company networks, including on personal phones.

06

A shadow AI policy and enablement playbook

1. Register what you find. Record each tool with an owner, the data it touches and a risk tier. The AI inventory and shadow AI discovery use case and the academy lesson on AI system registers show the structure.

2. Write rules people can follow. Name the approved tools, ban company data in personal accounts, and say which data classes may go where. The acceptable use policy template has model wording to adapt.

3. Offer a better approved option. Blocking without an alternative pushes work onto personal devices. Give staff an assistant with company knowledge, single sign-on and logging; the guide to building an internal ChatGPT compares buying seats, assembling open-source parts and deploying a platform.

4. Enforce in proportion. Block high-risk apps, coach users on medium-risk ones, apply data loss prevention to prompts and uploads, and stop staff from granting third-party AI apps access to company data without admin consent.

5. Train, and give a fast path. Pair the rules with AI literacy training and a request process that answers within days, so the approved route is quicker than working around it.

6. Measure and repeat. Re-run discovery every quarter, track how much traffic moves to approved tools, and review vendors that switch on new AI features.

07

Shadow AI Detection Methods Compared

What each data source reveals, what it misses and who usually owns it. Combine at least three for a usable picture.

MethodWhat it findsWhat it missesUsual owner
CASB or SSE discoveryWeb use of known AI apps, by user and data volumePersonal devices, unknown apps, AI inside approved SaaSSecurity operations
DNS, proxy and firewall logsCalls to AI domains and model API hostsTraffic off the corporate network; encrypted DNSNetwork team
Browser extension inventoryAI extensions and the permissions they holdUnmanaged browsers and devicesEndpoint or IT team
Code and secret scanningModel SDKs and API keys in repositoriesCode outside managed repositoriesApplication security
Expense and procurement dataPaid AI subscriptions and team purchasesFree tiers and personal paymentsFinance and procurement
Identity and OAuth consent logsAI apps connected to company accountsTools used without signing inIdentity team
SaaS admin reviewsAI features vendors switched on in approved softwareAnything outside the vendor listApplication owners
Surveys and amnestyDeclared use, including on personal phonesUsage people prefer to hideAI governance lead
08
How VDF AI fits

From concept to a governed, on-premise reality

Detection shows where the demand is; an approved tool absorbs it. VDF AI Chat gives staff a ChatGPT-style assistant that runs on your infrastructure, whether on-premises, in a sovereign cloud region or air-gapped, with conversation history, uploaded files and retrieval indexes in storage you control and an append-only record of every turn. On self-hosted deployments Microsoft Entra ID single sign-on is built in and maps Entra groups to roles, and other identity providers connect through an SSO-aware reverse proxy. Role-based access control is available on every plan.

For engineers, the AI gateway gives applications one approved endpoint to call instead of reaching model providers directly, with allow and deny lists and a per-call audit record. The MCP gateway turns internal services into governed tools through an approval step, so nobody has to install an MCP server on a laptop to connect an agent to company systems.

09

Frequently asked questions

What is shadow AI?

Shadow AI is any use of AI tools, models or AI features at work that IT, security or compliance has not approved or cannot see. Typical examples are company documents pasted into a personal chatbot account, browser extensions that summarise web pages, AI features a vendor enabled inside existing software, and model API keys or agents set up by individual teams. It is a form of shadow IT with a larger data flow, because every prompt carries content.

What are examples of shadow AI tools?

Common examples are consumer chatbots such as ChatGPT, Claude or Gemini used on personal accounts, AI writing and meeting-note extensions installed in the browser, AI features inside approved SaaS products that were switched on without review, coding assistants connected with personal keys, and agents or MCP servers that link an AI tool to internal systems. Whether a tool counts as shadow AI depends on how it is used: the same assistant can be approved under a company contract and unapproved on a personal account.

What are the risks of shadow AI?

The main risks are data leakage, compliance gaps and security incidents. Prompts can carry confidential or personal data to providers with no processing agreement, consumer plans may use conversations for training, and nobody keeps logs. IBM found in 2025 that one in five organizations reported a breach due to shadow AI, and that high levels of shadow AI added USD 670,000 to breach costs. Intellectual property and client confidentiality are also exposed once content leaves company control.

How do you detect shadow AI?

Combine several sources. Use a CASB or security service edge platform to discover AI apps in web traffic, query DNS and proxy logs for AI domains and model API hosts, inventory browser extensions on managed browsers, scan code repositories for model SDKs and API keys, check expense claims and OAuth consent logs, and ask staff through a survey or amnesty. Each source misses something, so reconcile the results into one register with an owner and a risk tier for every tool.

Should we block ChatGPT to stop shadow AI?

Blocking alone tends to move usage to personal phones and other tools, where it becomes invisible. A sturdier sequence is to approve an assistant that meets your data rules, publish an acceptable use policy that bans company data in personal accounts, and then block or coach on unapproved apps with your CASB or proxy. Keep a quick request path for new tools so that the approved route stays the easiest one to take.

What is the difference between shadow AI and shadow IT?

Shadow IT is any technology used without approval, such as personal file sharing or unapproved SaaS. Shadow AI is the AI-specific part of it. The difference is in what flows: AI tools receive the content of prompts and files, may keep or learn from it depending on the plan, and can act on connected systems when they run as agents. Microsoft’s documentation lists the main shadow AI risks as data leakage to AI models, compliance violations and uncontrolled AI tool activity.

See it in your environment

Put these concepts to work on infrastructure you control.

VDF AI runs governed agents, private retrieval, and model routing inside your own cloud, data center, or air-gapped network — or start free in our managed cloud today. Book a walkthrough mapped to your stack.