What is shadow AI and how to govern it

Shadow AI is employee use of AI tools without IT approval. What it means for your data and compliance, how to detect it, and how to control it.

by Elias Mahdavi · Published on · 8 min read

What is shadow AI and how to govern it

Shadow AI is the use of AI tools by employees without IT approval or visibility, such as pasting company data into a personal chatbot account. Unlike shadow IT, the prompt itself carries data outside the organisation's control. The EU AI Act (Regulation (EU) 2024/1689) and UK GDPR both make this a compliance issue, not just a security one.

Key takeaways

  • Shadow AI is any AI tool an employee uses for work without IT's knowledge or approval, from a personal chatbot account to an unauthorised browser plug-in.
  • The core risk differs from ordinary shadow IT: the prompt itself often contains the sensitive data, which can leave the company's control the moment it is typed.
  • Shadow AI is now a compliance problem, not only a security one, because the EU AI Act and UK GDPR both create obligations around how AI systems handle data.
  • Most shadow AI appears not because employees are careless, but because approved AI tooling is slower or more limited than what is freely available outside it.
  • Detecting it requires visibility into network egress and tool usage, not just a written policy nobody has read; governing it works best as a redirect, not a ban.

Contents

What is shadow AI?

Shadow AI is any artificial intelligence tool used for work purposes without the knowledge, review or approval of IT or security teams. It ranges from an employee pasting a contract into a free chatbot account to a whole team standardising informally on a coding assistant nobody in IT signed off.

The name deliberately echoes shadow IT, the older problem of employees adopting unsanctioned software tools, and the underlying dynamic is the same: people route around slow or restrictive official channels to get their job done faster. What makes shadow AI sharper is what actually leaves the building. A shadow IT tool might store a file; a shadow AI tool is handed the content directly, in the prompt, and that content can be logged or retained by the provider, often on a free consumer tier with the weakest data-handling terms of all.

What is shadow AI and how to govern it — schema

What are the risks of shadow AI?

The risks of shadow AI centre on data leaving the organisation's control with no record of what left, who sent it, or where it went. Each of the following compounds the others rather than existing in isolation.

1. Company data leaves the perimeter through the prompt itself

The prompt is the exposure. A consumer AI account's terms of service rarely offer the data-handling guarantees a business would negotiate directly, and once sensitive text has been submitted, it cannot be un-submitted.

2. No audit trail when something goes wrong

If a data protection query, a client dispute or a security incident later asks "what was shared with this tool, and when," a personal AI account run outside IT's visibility has no answer. There is no log to pull.

3. Inconsistent quality and standards across teams

When every team picks its own tool, quality, tone and factual reliability vary by whatever product an individual happened to choose, with no shared baseline for reviewing AI-assisted work.

4. Duplicate, uncoordinated spend

Multiple teams paying separately for overlapping AI subscriptions, often on personal cards later expensed, is money spent with zero visibility into whether it is used well at all.

5. Regulatory exposure under the EU AI Act and UK GDPR

Shadow AI use sidesteps whatever legal basis or risk assessment would normally apply to processing personal or commercial data, turning a compliance gap into a live one the moment a regulator asks.

6. Provider retention of prompts on free or consumer tiers

Free-tier AI products are frequently the ones with the least restrictive retention and training terms, precisely because they are free. Shadow AI usage skews toward exactly these tiers.

7. No way to revoke access when someone leaves

An approved tool can have a leaver's access switched off in minutes. A personal AI account that person used for client work cannot be revoked at all, because the company never controlled it.

Signs your organisation already has a shadow AI problem

Shadow AI rarely announces itself. It tends to show up first in small, easy-to-dismiss signals rather than one obvious event.

  • AI-polished writing appears where nobody procured a tool — proposals or reports with a tone that doesn't match how the team normally writes.
  • Network or expense records show AI subscriptions IT never approved, often on personal cards later claimed back.
  • A department's output speed jumps with no corresponding change in headcount or process.
  • Employees ask for an approved tool "like the one I already use at home." That's usually evidence the unapproved version is already in daily use.
  • IT cannot confidently answer "which AI tools are our people using, and on what data."

How to bring shadow AI under governance

Shadow AI is controlled by making the approved path faster than the unapproved one, backed by real technical visibility rather than a policy document alone. A ban with no viable alternative simply pushes usage further out of sight.

Detection signalWhat it typically revealsGovernance response
Unrecognised destinations in network/egress logsEmployees reaching AI tools outside any approved listGoverned egress with an authenticated, allow-listed proxy replacing open internet access
AI-related line items in expense reportsTeam-level tool adoption that never went through procurementA fast-track evaluation process so a new tool can become "approved" quickly, not never
Wide variance in AI-assisted output qualityNo shared model access or shared standard across teamsA single governed workspace with one LLM gateway, so everyone works from the same approved model set
No answer to "who used what, on which data"Absent audit trailPer-user virtual keys and request-level logging at the model-access layer
Repeated requests for tools IT hasn't reviewedA written AI policy that exists but isn't enforcedAn enforceable policy backed by technical controls, not a PDF nobody reopens

DevKira's approach is structural, not purely procedural: governed egress denies unlisted destinations by default while auto-approving low-risk ones, and the LLM gateway gives every person a legitimate, logged route to the same models shadow AI use was reaching for informally. The policy side of that response is covered in <a href="/en/blog/ai-policy-template-free">a usable AI policy template covering approved tools and enforcement</a>; the operational structure that keeps it enforced day to day is set out in <a href="/en/blog/ai-governance-framework-guide">how to build an AI governance framework that actually holds</a>.

Shadow AI, the EU AI Act and UK GDPR

Shadow AI turns a security question into a compliance one the moment personal or commercial data is involved, because both the EU AI Act and UK GDPR expect an organisation to know how AI is processing data it is responsible for. Neither expectation can be met for a tool IT has never seen.

The EU AI Act, formally Regulation (EU) 2024/1689, applies obligations by risk level to providers and deployers of AI systems, including ones whose output is used within the EU regardless of where the deploying company is based, a scope the European Commission sets out on its <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai" target="_blank" rel="noopener">regulatory framework for AI page</a>. A tool adopted informally by one employee has, by definition, had none of the risk assessment that framework assumes.

The Information Commissioner's Office is explicit in its <a href="https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/" target="_blank" rel="noopener">guidance on AI and data protection</a> that accountability under UK GDPR means being able to show what a system does with personal data, not merely intending to find out later. The National Cyber Security Centre's <a href="https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development" target="_blank" rel="noopener">Guidelines for Secure AI System Development</a> makes the same point from the security side: risk must be managed across an AI system's whole lifecycle, precisely what shadow AI removes visibility of. For UK organisations with EU customers, NIS2 (Directive (EU) 2022/2555) adds a further angle: an unmanaged AI tool inside a supplier's environment is exactly the kind of third-party risk essential and important-sector supply-chain rules are designed to surface.

Frequently asked questions

What is shadow AI?

Shadow AI is the use of AI tools by employees for work purposes without the knowledge, review or approval of IT or security teams. It includes personal chatbot accounts, unvetted browser extensions and AI features enabled inside other software without formal sign-off.

What are the risks of shadow AI?

The main risks are company data leaving the organisation's control through the prompt itself, no audit trail if something goes wrong, inconsistent output quality across teams, duplicate uncoordinated spend, and regulatory exposure under frameworks like the EU AI Act and UK GDPR that assume an organisation knows how its AI tools handle data.

Is shadow AI the same as shadow IT?

They are related but not identical. Shadow IT is any unsanctioned software; shadow AI is the AI-specific subset, and it carries an extra risk shadow IT does not: the sensitive content is typically submitted directly inside the prompt itself, not merely stored in an unapproved file or app.

How common is shadow AI in most organisations?

Very common and typically underestimated, because shadow AI usage is designed to be invisible by default: a personal account, a browser tab, a free-tier sign-up. Most IT teams asked to estimate their organisation's shadow AI usage significantly underestimate it until they have actual network or egress visibility.

Can you stop shadow AI just by writing a policy that bans it?

Rarely on its own. A policy with no faster, better-supported alternative simply pushes usage further out of sight, because the underlying reason people adopt shadow AI, a slower official process, has not been addressed. Policy has to be paired with a genuinely usable approved path and technical enforcement.

Getting shadow AI back under control

Shadow AI is rarely a discipline problem. It is almost always a supply problem: people found a faster route to a capability the official process wasn't offering. Closing that gap means understanding what AI governance actually requires end to end, covered in <a href="/en/blog/what-is-ai-governance">what AI governance means and how it works in practice</a>, then giving people an equally fast, approved alternative.

To see governed egress, per-user model access and audit logging replace shadow AI usage with sanctioned usage, without slowing teams down, <a href="/en/book-a-demo">book a DevKira demo</a>.

See DevKira on your workflow

30 minutes on the live product.

Book a demo

Keep reading