Shadow AI Defined in Plain Terms
Shadow AI is the use of artificial intelligence tools, most often generative AI like ChatGPT, inside an organisation without the knowledge or approval of its IT and security teams. It is the AI branch of shadow IT. Staff adopt these tools to work faster and the data they share with them leaves the organisation’s control.
Shadow AI is a business problem because leaders cannot govern what they cannot see. A tool that needs no installation and runs in a browser tab spreads faster than any software before it and it now arrives switched on inside the SaaS products you already approved.
How Shadow AI Takes Hold
Shadow AI spreads for a simple reason. The tools are free or nearly free, they need no installation and using one is as easy as opening a browser tab. There is no purchase order, no security review and often no trace.
Three routes account for most of it. Staff sign in to consumer chatbots with personal accounts and paste in work content. Approved SaaS products ship new AI features that get switched on without review. And employees add AI browser extensions that can read whatever is on the screen.
The real exposure sits in the fine print. Free consumer tiers may use what you type to train future models unless you opt out or move to a paid enterprise tier. Once confidential text has been submitted, you cannot reliably pull it back.
Types of Shadow AI

Shadow AI is a category and these are the forms it usually takes inside an organisation.
- Unsanctioned chatbots and assistants: Public generative AI used for drafting, summarising and analysis on work data.
- AI features inside approved software: Assistants and summarisers built into tools you already use, switched on without a review.
- AI browser extensions: Add-ons that can read, capture or send whatever appears on the screen.
- Personal AI accounts on work data: Staff using their own logins, outside any company control or logging.
- AI coding assistants: Tools that suggest code and can send snippets of your source to a third party.
- Unvetted AI vendors and agents: New suppliers and automated agents added to workflows without a security or data check.
The Business Impact of Shadow AI
The cost of shadow AI is rarely a single dramatic event. It is a set of quiet exposures that add up over time.
The most immediate risk is data and intellectual property leakage. Source code, customer records, contracts and strategy documents pasted into a public tool may be stored, processed abroad or used to train a model you do not control. Once submitted, that content cannot reliably be recalled.
There is also direct compliance exposure. Personal data entered into an unapproved tool can breach GDPR and an AI system nobody has inventoried cannot be governed under the EU AI Act or reported under NIS2. The legal duty applies whether or not IT knew the tool existed.
Then there is unreliable output feeding real decisions. Generative AI can produce fluent answers that are confidently wrong and when that output is trusted without checking, the error moves straight into a filing, a report or a customer message.
Shadow AI also creates lost visibility. Security teams cannot protect data flows they cannot see, so an incident that begins in a tool nobody approved is harder to detect and slower to contain.
Finally, every AI tool is a new third party with access to your data. Under NIS2 and DORA that supplier is your responsibility and an unvetted one is an unmanaged dependency in your supply chain.
Real-World Shadow AI Cases
Three well-documented cases show the three main ways shadow AI goes wrong from leaked data to false output to a regulator stepping in.
Samsung and Leaked Source Code (2023)
In 2023 Samsung allowed engineers in one division to use ChatGPT. Within weeks the company found that internal data had been entered into the tool on separate occasions including semiconductor source code and the contents of an internal meeting.
The data was not stolen by an attacker. Staff had simply pasted confidential work into a public tool to get help with it. In May 2023 Samsung restricted generative AI on company-owned devices and started building an internal alternative (Bloomberg, 2023).
A sanctioned AI tool with data loss prevention and a plain acceptable-use policy would have given those engineers a safe place to work and kept the source code inside the company.
Fake Case Law in a US Court (2023)
Two New York lawyers filed a legal brief that cited six court decisions which did not exist. The citations had been generated by ChatGPT which one of the lawyers had used believing it worked like a search engine.
In June 2023 the court sanctioned both lawyers and their firm. The tool had invented plausible, well-formatted rulings and nobody had checked whether they were real before the brief was filed (US District Court, Southern District of New York, 2023).
The fix here is a rule, not a product. AI output is verified by a person before anyone relies on it and unvetted AI is kept away from professional work product.
Italy’s Regulator Pauses ChatGPT (2023)
On 31 March 2023 Italy’s data protection authority, the Garante, ordered a temporary stop to ChatGPT for Italian users. It cited GDPR concerns about the legal basis for using personal data, the accuracy of the information the tool produced and the lack of age checks.
Access returned on 28 April 2023 after OpenAI made changes. In December 2024 the Garante went further and fined OpenAI €15 million over how it had processed personal data. A popular AI tool can become unavailable or unlawful to use across a whole country almost overnight and the fine shows regulators treat AI data handling as firmly in scope (Garante, 2023 and 2024).
Running a data protection impact assessment and agreeing a lawful basis before an AI tool touches personal data keeps a business on the right side of that line.
Shadow AI and Compliance
Shadow AI carries legal weight as well as security risk. Four regimes bear on it directly and each is harder to satisfy when AI use is invisible.
Under NIS2 in Sweden, in force as Cybersäkerhetslagen since 15 January 2026, the board is responsible for approving and overseeing security measures and can be held personally accountable under Article 20. Article 21 requires security awareness training and supply-chain security, both of which unmanaged AI use undermines. Fines reach €10M or 2% of global turnover for essential entities and a serious incident must be reported to MCF (formerly MSB) within 24 hours.
The EU AI Act adds more. Since 2 February 2025 its Article 4 has required organisations to ensure staff reach a sufficient level of AI literacy, a duty that shadow AI directly undercuts. Its obligations for general-purpose AI models began to apply on 2 August 2025 with the bulk of the Act following on 2 August 2026. You cannot document or govern AI systems you do not know are running.
GDPR is engaged the moment personal data is involved. Pasting customer or employee data into a public tool can be an unlawful disclosure and a resulting breach must be reported to IMY within 72 hours under Article 33.
For financial entities, DORA Article 17 requires managed ICT incident handling, supervised by Finansinspektionen and its third-party rules treat every AI vendor as a dependency you must oversee.
Governing all of this starts with knowing which AI is in use which is the purpose of AI detection and response.
How to Spot Shadow AI in Your Organisation

You cannot manage shadow AI until you can see it and most of it is findable if you look in the right places.
- Network and DNS logs: Traffic to known AI service domains shows which tools are being reached and how often.
- Browser extension inventory: A review of installed add-ons across the fleet surfaces AI extensions that can read screen content.
- Expense and subscription records: AI subscriptions charged to cards or expenses reveal paid tools bought outside procurement.
- SaaS discovery and CASB: A cloud access security broker maps sanctioned and unsanctioned cloud services including AI ones.
- DLP alerts: Data loss prevention can flag sensitive content being sent to an AI endpoint.
Discovery has a limit worth being honest about. Finding the tools does not fix the risk and a blunt ban usually just pushes people to their phones and personal accounts where you have no visibility at all. The aim is to bring AI use into the light where it can be made safe rather than to drive it underground.
How to Defend Against Shadow AI
Defending against shadow AI is a governance job before it is a technical one. It works across people, process and technology and the goal is to make the safe path the easy path.
- Give staff a sanctioned AI tool: People use shadow AI to get work done, so provide an approved enterprise option that does not train on your data.
- Write a clear acceptable-use policy: State what may and may not be entered into AI tools, in plain language everyone can follow.
- Train your people: Make sure staff understand why pasting confidential data into a public tool is a risk and what to use instead.
- Apply DLP and CASB: Use data loss prevention and a cloud access security broker to see and control what leaves for AI services.
- Gate access with SSO: Route approved tools through single sign-on so access can be granted, logged and revoked.
- Review AI vendors and models: Check the data handling, training and hosting of any AI supplier before it touches company data.
- Log and monitor AI use: Bring AI activity into your monitoring so unusual data flows are detected.
- Put AI under board oversight: Assign clear ownership so AI governance is reviewed at the top, as NIS2 Article 20 now requires.
Start with the first two. Give people a safe tool and clear rules for using it and most shadow AI moves into the open where you can manage it.
