GLOSSARY · AI SECURITY
Shadow AI
Shadow AI is the use of AI tools by employees or teams without the knowledge or approval of IT and security.
It is the AI-era version of shadow IT: personal chatbot accounts, browser extensions, and AI features quietly switched on inside approved SaaS. Surveys consistently find that most AI use at work is unsanctioned, and the gap keeps widening because the barrier to entry is a web login rather than a procurement cycle.
What makes shadow AI harder to govern than ordinary shadow IT is that much of it arrives inside tools you already approved. A sanctioned CRM ships an AI summarization feature. A note-taking app adds a bot that joins meetings and transcribes them. Nobody signed a new contract, no new vendor appeared in the expense report, and yet company data is now flowing to a model whose retention terms nobody reviewed. The second difference is what leaves: people paste in the thing they are actually struggling with, which tends to be the contract, the incident, or the board deck.
Discovery comes before policy. Usage leaves traces in places you already collect: web proxy and DNS logs for AI domains, OAuth grants and SSO logs for AI apps, browser extension inventories, expense reports, and the admin consoles of your existing SaaS, where AI features are usually a toggle you can audit. Only once you know the real picture is a policy worth writing, because the numbers tell you whether you are governing a handful of enthusiasts or most of the company.
The enforcement trap is the one shadow IT already taught. Blocking without a sanctioned alternative does not reduce usage, it moves usage onto personal devices where you have no visibility at all. Pair an acceptable use policy with an approved tool that is genuinely good enough for the work, and an approval path that resolves in days rather than quarters.