AI security

What is Shadow AI?

The business guide to shadow AI, the unapproved use of AI tools at work, and the controls that keep your data out of public models.

What is Shadow AI
Key takeaways
  • Shadow AI is the use of AI tools at work without IT or security approval, the AI branch of shadow IT.
  • It spreads fast because the tools are free, need no installation and now arrive built into approved software.
  • The three main harms are leaked data, unreliable output and compliance breaches.
  • Free consumer AI tiers may use what you type to train their models unless you opt out or use an enterprise tier.
  • In May 2023 Samsung restricted generative AI on company devices after staff pasted internal source code into ChatGPT. (Bloomberg, 2023)
  • In June 2023 two US lawyers were sanctioned for filing fake case law that ChatGPT had invented. (SDNY, 2023)
  • In 2023 Italy’s Garante briefly ordered ChatGPT offline over GDPR concerns. (Garante, 2023)
  • NIS2, in force in Sweden as Cybersäkerhetslagen since 15 January 2026, makes boards accountable and can fine essential entities up to €10M or 2% of turnover.
  • The EU AI Act has required staff AI literacy since 2 February 2025 under Article 4, a duty that unmanaged AI use directly undermines.
  • Fixing shadow AI is governance first, which means a sanctioned tool, a clear acceptable-use policy, staff training and monitoring.

Shadow AI Defined in Plain Terms

Shadow AI is the use of artificial intelligence tools, most often generative AI like ChatGPT, inside an organisation without the knowledge or approval of its IT and security teams. It is the AI branch of shadow IT. Staff adopt these tools to work faster and the data they share with them leaves the organisation’s control.

Shadow AI is a business problem because leaders cannot govern what they cannot see. A tool that needs no installation and runs in a browser tab spreads faster than any software before it and it now arrives switched on inside the SaaS products you already approved.

How Shadow AI Takes Hold

Shadow AI spreads for a simple reason. The tools are free or nearly free, they need no installation and using one is as easy as opening a browser tab. There is no purchase order, no security review and often no trace.

Three routes account for most of it. Staff sign in to consumer chatbots with personal accounts and paste in work content. Approved SaaS products ship new AI features that get switched on without review. And employees add AI browser extensions that can read whatever is on the screen.

The real exposure sits in the fine print. Free consumer tiers may use what you type to train future models unless you opt out or move to a paid enterprise tier. Once confidential text has been submitted, you cannot reliably pull it back.

Types of Shadow AI

Types of Shadow AI

Shadow AI is a category and these are the forms it usually takes inside an organisation.

  • Unsanctioned chatbots and assistants: Public generative AI used for drafting, summarising and analysis on work data.
  • AI features inside approved software: Assistants and summarisers built into tools you already use, switched on without a review.
  • AI browser extensions: Add-ons that can read, capture or send whatever appears on the screen.
  • Personal AI accounts on work data: Staff using their own logins, outside any company control or logging.
  • AI coding assistants: Tools that suggest code and can send snippets of your source to a third party.
  • Unvetted AI vendors and agents: New suppliers and automated agents added to workflows without a security or data check.

The Business Impact of Shadow AI

The cost of shadow AI is rarely a single dramatic event. It is a set of quiet exposures that add up over time.

The most immediate risk is data and intellectual property leakage. Source code, customer records, contracts and strategy documents pasted into a public tool may be stored, processed abroad or used to train a model you do not control. Once submitted, that content cannot reliably be recalled.

There is also direct compliance exposure. Personal data entered into an unapproved tool can breach GDPR and an AI system nobody has inventoried cannot be governed under the EU AI Act or reported under NIS2. The legal duty applies whether or not IT knew the tool existed.

Then there is unreliable output feeding real decisions. Generative AI can produce fluent answers that are confidently wrong and when that output is trusted without checking, the error moves straight into a filing, a report or a customer message.

Shadow AI also creates lost visibility. Security teams cannot protect data flows they cannot see, so an incident that begins in a tool nobody approved is harder to detect and slower to contain.

Finally, every AI tool is a new third party with access to your data. Under NIS2 and DORA that supplier is your responsibility and an unvetted one is an unmanaged dependency in your supply chain.

Real-World Shadow AI Cases

Three well-documented cases show the three main ways shadow AI goes wrong from leaked data to false output to a regulator stepping in.

Samsung and Leaked Source Code (2023)

In 2023 Samsung allowed engineers in one division to use ChatGPT. Within weeks the company found that internal data had been entered into the tool on separate occasions including semiconductor source code and the contents of an internal meeting.

The data was not stolen by an attacker. Staff had simply pasted confidential work into a public tool to get help with it. In May 2023 Samsung restricted generative AI on company-owned devices and started building an internal alternative (Bloomberg, 2023).

A sanctioned AI tool with data loss prevention and a plain acceptable-use policy would have given those engineers a safe place to work and kept the source code inside the company.

Fake Case Law in a US Court (2023)

Two New York lawyers filed a legal brief that cited six court decisions which did not exist. The citations had been generated by ChatGPT which one of the lawyers had used believing it worked like a search engine.

In June 2023 the court sanctioned both lawyers and their firm. The tool had invented plausible, well-formatted rulings and nobody had checked whether they were real before the brief was filed (US District Court, Southern District of New York, 2023).

The fix here is a rule, not a product. AI output is verified by a person before anyone relies on it and unvetted AI is kept away from professional work product.

Italy’s Regulator Pauses ChatGPT (2023)

On 31 March 2023 Italy’s data protection authority, the Garante, ordered a temporary stop to ChatGPT for Italian users. It cited GDPR concerns about the legal basis for using personal data, the accuracy of the information the tool produced and the lack of age checks.

Access returned on 28 April 2023 after OpenAI made changes. In December 2024 the Garante went further and fined OpenAI €15 million over how it had processed personal data. A popular AI tool can become unavailable or unlawful to use across a whole country almost overnight and the fine shows regulators treat AI data handling as firmly in scope (Garante, 2023 and 2024).

Running a data protection impact assessment and agreeing a lawful basis before an AI tool touches personal data keeps a business on the right side of that line.

Shadow AI and Compliance

Shadow AI carries legal weight as well as security risk. Four regimes bear on it directly and each is harder to satisfy when AI use is invisible.

Under NIS2 in Sweden, in force as Cybersäkerhetslagen since 15 January 2026, the board is responsible for approving and overseeing security measures and can be held personally accountable under Article 20. Article 21 requires security awareness training and supply-chain security, both of which unmanaged AI use undermines. Fines reach €10M or 2% of global turnover for essential entities and a serious incident must be reported to MCF (formerly MSB) within 24 hours.

The EU AI Act adds more. Since 2 February 2025 its Article 4 has required organisations to ensure staff reach a sufficient level of AI literacy, a duty that shadow AI directly undercuts. Its obligations for general-purpose AI models began to apply on 2 August 2025 with the bulk of the Act following on 2 August 2026. You cannot document or govern AI systems you do not know are running.

GDPR is engaged the moment personal data is involved. Pasting customer or employee data into a public tool can be an unlawful disclosure and a resulting breach must be reported to IMY within 72 hours under Article 33.

For financial entities, DORA Article 17 requires managed ICT incident handling, supervised by Finansinspektionen and its third-party rules treat every AI vendor as a dependency you must oversee.

Governing all of this starts with knowing which AI is in use which is the purpose of AI detection and response.

How to Spot Shadow AI in Your Organisation

How to Spot Shadow AI

You cannot manage shadow AI until you can see it and most of it is findable if you look in the right places.

  • Network and DNS logs: Traffic to known AI service domains shows which tools are being reached and how often.
  • Browser extension inventory: A review of installed add-ons across the fleet surfaces AI extensions that can read screen content.
  • Expense and subscription records: AI subscriptions charged to cards or expenses reveal paid tools bought outside procurement.
  • SaaS discovery and CASB: A cloud access security broker maps sanctioned and unsanctioned cloud services including AI ones.
  • DLP alerts: Data loss prevention can flag sensitive content being sent to an AI endpoint.

Discovery has a limit worth being honest about. Finding the tools does not fix the risk and a blunt ban usually just pushes people to their phones and personal accounts where you have no visibility at all. The aim is to bring AI use into the light where it can be made safe rather than to drive it underground.

How to Defend Against Shadow AI

Defending against shadow AI is a governance job before it is a technical one. It works across people, process and technology and the goal is to make the safe path the easy path.

  • Give staff a sanctioned AI tool: People use shadow AI to get work done, so provide an approved enterprise option that does not train on your data.
  • Write a clear acceptable-use policy: State what may and may not be entered into AI tools, in plain language everyone can follow.
  • Train your people: Make sure staff understand why pasting confidential data into a public tool is a risk and what to use instead.
  • Apply DLP and CASB: Use data loss prevention and a cloud access security broker to see and control what leaves for AI services.
  • Gate access with SSO: Route approved tools through single sign-on so access can be granted, logged and revoked.
  • Review AI vendors and models: Check the data handling, training and hosting of any AI supplier before it touches company data.
  • Log and monitor AI use: Bring AI activity into your monitoring so unusual data flows are detected.
  • Put AI under board oversight: Assign clear ownership so AI governance is reviewed at the top, as NIS2 Article 20 now requires.

Start with the first two. Give people a safe tool and clear rules for using it and most shadow AI moves into the open where you can manage it.

Myths & Facts

Myth

Shadow AI is just people using ChatGPT, it is not a real security issue.

If we ban AI tools, the problem goes away.

Our staff would never paste anything confidential into a public AI tool.

The AI tool is free, so there is no cost to using it.

AI output is reliable enough to use as it is.

Shadow AI is an IT problem for IT to solve.

Fact

It is the uncontrolled flow of company data into tools you cannot see or govern, which is exactly how confidential information and IP leak.

A ban usually pushes staff to personal phones and accounts where you have no visibility, so a sanctioned safe tool works better than a block.

Samsung engineers did exactly that in 2023, and they were skilled professionals trying to work faster rather than careless people.

Free consumer tiers can use your input to train their models, so you may be paying with your confidential data.

Generative AI can produce confident, fabricated answers, as the US lawyers sanctioned in 2023 for citing invented case law found out.

Under NIS2 Article 20 the board is accountable for security measures, so AI governance belongs at leadership level and not with IT alone.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. A developer on your team asks whether it is fine to paste a block of the company's source code into ChatGPT to help debug it faster.

    What is the right answer?

    • Yes, it saves time and the code is not that sensitive.
    • Only through an approved enterprise AI tool that does not train on your data, following the acceptable-use policy.
    • No AI should ever be used for anything.
  2. A colleague used a free AI assistant to draft an important client report and wants to send it straight out.

    What do you advise?

    • Send it, the AI is usually accurate.
    • Have a person check every fact and claim before it goes out.
    • Rewrite it entirely by hand to be safe.
  3. Your marketing team wants to start using a new AI tool that processes customer data.

    What should happen first?

    • Sign up and start using it, then review later.
    • Run a data protection impact assessment and confirm a lawful basis before it touches personal data.
    • Ask the vendor if they are secure and take their word for it.
  4. You discover several teams are already using AI tools nobody approved.

    What is the best first move?

    • Block every AI domain immediately and issue a warning.
    • Provide a sanctioned tool, publish a clear policy and bring the usage into monitoring.
    • Ignore it, since staff are being productive.

Knowledge Test

  1. What is shadow AI?

    • AI built by a company's own data science team
    • The use of AI tools at work without IT or security approval
    • A type of malware that hides on a network
    • An AI regulation in the EU

    Shadow AI is the unapproved use of AI tools inside an organisation, the AI branch of shadow IT.

  2. Why can free consumer AI tools be risky for confidential data?

    • They are always infected with viruses
    • Their input may be used to train the provider's models
    • They delete your files
    • They are illegal in Sweden

    Free consumer tiers may use what you type to train future models unless you opt out.

  3. In 2023, what did Samsung do after internal data was entered into ChatGPT?

    • Sued OpenAI
    • Restricted generative AI on company devices
    • Ignored it
    • Made ChatGPT mandatory

    Samsung restricted generative AI on company-owned devices in May 2023 and built an internal alternative.

  4. Why were two US lawyers sanctioned in 2023?

    • They hacked a court database
    • They filed fake case law that ChatGPT had invented
    • They refused to use AI
    • They leaked client data to ChatGPT

    ChatGPT generated citations to cases that did not exist, and nobody checked them before filing.

  5. Under NIS2, who is accountable for an organisation's security measures?

    • The IT helpdesk
    • The board or management body
    • The AI vendor
    • Individual employees

    Article 20 makes the board responsible and allows it to be held personally accountable.

  6. What is the most effective first response to shadow AI?

    • Ban all AI tools
    • Provide a sanctioned tool and a clear policy
    • Do nothing
    • Fire staff who use AI

    A safe approved tool plus clear rules works better than a blunt ban that pushes usage underground.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Most shadow AI begins with a person trying to do their job faster rather than with an attacker. That is why training is the highest-leverage control. When staff understand why pasting confidential data into a public tool is risky and know which approved tool to use instead, most of the risk disappears before any technology is involved.

Security awareness training is also a legal expectation. Under NIS2, in force in Sweden as Cybersäkerhetslagen, it sits among the required security measures, and boards are accountable for making sure it happens.

Frequently Asked Questions

What is shadow AI?

Shadow AI is the use of AI tools, most often generative AI like ChatGPT, inside an organisation without the approval or knowledge of its IT and security teams. It is the AI branch of shadow IT. The risk is that confidential company data flows into tools nobody is governing or able to see.

What is the difference between shadow AI and shadow IT?

Shadow IT is any hardware or software used without approval, while shadow AI is the specific subset that involves AI tools such as chatbots and AI features inside other software. Shadow AI spreads faster because the tools are free and run in a browser, and it adds the risk that your data trains external models.

Is using ChatGPT at work a security risk?

Using ChatGPT at work can be a security risk when staff paste confidential data into it without approval or safeguards. On free consumer tiers that input may be used to train the model. In 2023 Samsung restricted generative AI on company devices after engineers entered internal source code into ChatGPT.

What are the main risks of shadow AI?

The main risks of shadow AI are leaked data and intellectual property, compliance breaches, unreliable output that feeds real decisions and a loss of visibility for security teams. Each AI tool is also a new third-party supplier whose data handling you are responsible for under NIS2 and DORA.

How do I find out if staff are using AI tools without approval?

You can find shadow AI by checking network and DNS logs for traffic to AI service domains, reviewing installed browser extensions and scanning expense records for AI subscriptions. A cloud access security broker and data loss prevention make this continuous. Discovery finds the tools, but fixing the risk takes policy and a safe alternative.

Should we just ban AI tools at work?

Banning AI tools outright rarely works, because staff move to personal phones and accounts where you have no visibility at all. A better approach is to provide a sanctioned enterprise AI tool, set a clear acceptable-use policy and train people on it. The aim is to make AI use safe and visible rather than to push it underground.

Does shadow AI create GDPR or NIS2 problems?

Yes. Entering personal data into an unapproved AI tool can breach GDPR, and a resulting data breach must be reported to IMY within 72 hours under Article 33. Under NIS2, in force in Sweden as Cybersäkerhetslagen, boards are accountable for security measures and unmanaged AI undermines the required training and supply-chain controls.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.