Shadow AI
Shadow AI is the use of AI applications, models, APIs, or agent tools inside an organization without the knowledge, approval, or oversight required by its technology, security, or governance functions. It is the AI-specific form of shadow IT, but adds risks tied to prompts, training data, generated outputs, model decisions, and autonomous tool activity. The term describes an organizational condition, not a particular product or attack technique.
Origin and context
McGrathNicol documented Shadow AI in December 2023 as AI solutions used without a business's or IT department's official approval or oversight and described associated data-security and governance risks. IBM published a broader explanation in October 2024 and distinguished the concept from shadow IT. By June 2026, Microsoft had operationalized it in security documentation for network-based discovery of generative-AI applications, model-provider APIs, and SaaS MCP servers. The evidence shows movement from an enterprise-risk label to a detectable security category, but it does not identify who coined the term.
Why it matters
An organization cannot govern AI use it cannot see. Employees may paste confidential material into consumer assistants, connect unapproved agents to corporate systems, or rely on generated output in a regulated workflow without review. That can create data leakage, compliance, quality, and accountability risks even when the underlying AI service is legitimate. Discovery gives security teams an inventory of applications and usage patterns; governance then needs approved alternatives, clear data-handling rules, education, and proportionate controls rather than assuming that blocking a list of websites will remove the demand.
Example
A sales analyst uploads a customer spreadsheet to a personal AI assistant because the approved reporting tool is slow. The assistant produces a useful summary, but the upload bypasses the employer's vendor review, retention policy, access controls, and audit trail. That is shadow AI even if no breach occurs. If the same assistant is formally approved, configured under an enterprise agreement, and used within documented data rules, its use is no longer shadow AI merely because it is externally hosted.
How it differs
AI Security Posture Management / AI-SPM
Shadow AI is the underlying unsanctioned-use condition. AI security posture management is a broader governance and security practice or product category for discovering AI assets, evaluating configurations and risks, and enforcing policy. An AI-SPM capability may help find shadow AI, but it can also govern approved models and infrastructure; conversely, policy, procurement, network analysis, and employee reporting can identify shadow AI without an AI-SPM platform.
Maturity and evidence
Maturity is rated 3. The term has a stable enterprise meaning in independent technical analysis and appears as an operational discovery category in current security documentation. That supports established use beyond marketing shorthand. The rating remains below 4 because measurement depends on network visibility and organizational policy, terminology varies, and the reviewed evidence does not provide a cross-industry standard for what must count as sanctioned AI.
Limits and open questions
Detection can miss local models, encrypted traffic, personal devices, embedded AI features, or indirect API access. Network activity also does not reveal whether a use was authorized or harmful, and aggressive monitoring may create privacy or labor concerns. A useful program therefore combines technical discovery with policy, procurement, training, approved tools, and escalation processes rather than treating every unknown AI connection as an incident.
Related terms
References
- Shadow AI discovery in Global Secure AccessMicrosoft Learn · 2026-06-11 · class A
- What Is Shadow AI?IBM · 2024-10-25 · class B
- The Emergence of Shadow AIMcGrathNicol · 2023-12-13 · class B
Last updated: 2026-08-27
This term is also covered in the Skills Atlas as ai risk management skill.
This term is also covered in the Skills Atlas as ai data security skill.