Explainer

What is Shadow AI

Shadow AI is people using personal ChatGPT or similar for work because the official tool is too slow or missing — which leaks data and leaves no record of what changed.

Shadow AI is employees using personal ChatGPT, Claude, Gemini, or similar tools for work because the official company tool is too slow, too locked down, or missing.

The work is real. The risk is off the books. Security often hears about it first as an incident.

It is the AI-era cousin of shadow IT: unsanctioned software people adopt because it helps them finish the job. The pattern is older than ChatGPT — personal Dropbox, unsanctioned notebooks, Excel macros that became load-bearing. Generative AI sped it up because the tools are excellent, cheap, and one paste away from a customer list.

IBM’s 2025 Cost of a Data Breach research found that 20% of organisations reported security incidents involving shadow AI, and that organisations with high levels of it paid $670,000 more per breach. Sixty-three percent lacked AI governance policies.

Shame does not fix those numbers. Substitution does. People paste work into personal accounts because the deadline is tonight and the official programme is a waitlist. If the approved tool cannot see Salesforce, they will export a spreadsheet. If the approved tool is ten times slower than paste, shadow wins.

Words you’ll hear

  • Shadow IT. Unsanctioned systems. Shadow AI is often unsanctioned generation on a sanctioned laptop — a personal account, not a new product install. At work, the browser is allowed; the tenant is not yours.
  • Sanctioned tool. The company’s official AI, with company login and a vendor agreement. At work, ChatGPT Enterprise on the company tenant can be sanctioned and still be ungoverned for writes if people copy output into CRM.
  • Data leakage. Prompts become logs at a vendor you have no processing agreement with. At work, a customer list in a consumer chat is a processing event you cannot inventory.
  • Acceptable-use policy. A PDF. Necessary. Not a substitute for a tool people can actually use.
  • DLP / CASB. Network or cloud tools that watch paste-out and unsanctioned apps. Useful. They do not quote a CRM change or bind a named signer.
  • Personal API key. A pass-through that looks like engineering hygiene and is often shadow AI with a credit card. See What is AI token economics.
  • Pressure valve. A logged sandbox with fake data and no production writes. Not shadow. A way to experiment without a customer list.

ENISA’s Threat Landscape 2025 notes fake AI-tool sites and malware posing as AI installers. People hunting for “a free assistant” are the audience. Blocking the official vendors without a substitute trains that hunt.

Why you should care

That can mean:

  • Customer or internal data sitting in a consumer vendor’s logs. Legal later asks which model saw it. Nobody can say. GDPR does not pause because the employee used a personal account.
  • Changes with no record. Someone types model output into CRM. No approver of record. That is ungoverned write-back with extra steps.
  • Two versions of policy. The official playbook says one thing. A shadow chat invented another. See What is a company wiki for AI agents.
  • Institutional amnesia. The reasoning lived in a thread the company cannot query. See What is institutional memory in enterprise AI.
  • A wider attack surface. Fake installer sites, prompt leakage, and keys in plugins.

Blocking websites without offering a sanctioned path does not end shadow AI. It trains people to use personal phones.

What actually reduces it

Find the jobs people are already doing in personal chats: drafting, summarising, extracting tables, writing the email. Put those jobs on an official path that can see the right files without a paste.

Read-only links to live systems in an approved product are how you stop the spreadsheet. Make the official path not much slower than paste. The honest metric is time to finish the job.

Perimeter blocking can tighten after a real path exists — not before. AI governance that is only a block list is guidance with extra steps.

What changes by role

Finance. Shadow spend hides on personal cards and departmental tools. Shadow output typed into the ledger has no trail. Finance should want a sanctioned path with quotes and caps, not a ban that moves the bill onto expenses.

Legal. Processing without an agreement, invented customer commitments, and no inventory of what left the tenant. Air Canada’s chatbot was official and still made a false commitment — CBC. Shadow tools add the same class of fiction with even less control. Legal should not allow “non-sensitive only” personal accounts; employees are bad at classifying.

Operations. Deadline pressure is the demand signal. Ops should treat missing connectors and waitlists as root causes, and should offer sandboxes so experimentation does not need production data.

Go-to-market. Fastest to shadow, because the consumer tools are excellent at email and decks. GTM needs read-only CRM in the official path or they will export. They also copy invented pricing into the opportunity — a write-back problem dressed as productivity.

Security. Detection (surveys, DLP, key scanning) plus substitution. Punishment first yields dishonest surveys. IBM’s uplift in breach cost is the board-level argument; ENISA’s fake-tool landscape is the practical one. A secure web gateway is not a named signer.

What people get wrong

Blocking as strategy. Phones exist.

Sanctioned equals governed. Company ChatGPT can still be copy-paste into Salesforce.

Allowing personal accounts for “non-sensitive” work. Classification fails under deadline.

Shame. Drives better hiding, not better behaviour.

Assuming shadow is a people problem. It is usually a missing-path problem: no connectors, no speed, no permission to try.

Good looks like: self-service workstreams, wiki, read-only connectors, a named signer on writes, time-to-job close to paste, perimeter controls after substitution, sandboxes with fake data. Failure looks like a blocked URL, a PDF, and a personal Claude project full of customers.

ICO guidance on AI and data protection still applies when the employee is the one pasting. Lawful basis and purpose do not wait for an official rollout. That is why substitution is a legal control as well as a security one: the unofficial path is still processing.

How this shows up in Nimbus

Nimbus is built so the legitimate path is the easy path: operators open workstreams themselves, use approved playbooks and read-only connectors, and only write to live systems after a named person signs.

Nimbus does not “detect shadow AI” the way a network tool that watches cloud apps would. Those perimeter tools still matter. The product bet is gravitational: if governed work is live quickly, shadow has less to do.

See Governance and Workstreams.

Questions people actually ask

Is using ChatGPT Enterprise still shadow AI?

If it is the organisation’s tenant, with company login, a processing agreement, and a defined use policy, it is sanctioned — not shadow. It can still be ungoverned for writes (people copy output into CRM). Sanctioned is not the same as sufficient.

Does blocking OpenAI at the office network solve it?

It reduces one channel. It does not stop phones, home networks, or other vendors. Without a substitute, it also reduces productivity.

Can we allow personal accounts for “non-sensitive” work?

Employees are bad at classifying. If you allow it, assume leakage of whatever they think is non-sensitive.

How do we find existing shadow AI?

Anonymous surveys, credit-card review, data-loss monitoring, scanning for personal API keys, and talking to the teams under deadline pressure. Do not start with punishment if you want honest answers.

Why do people prefer the unofficial tools?

Speed, quality, missing connectors in the official tool, and fear of “the AI team.” Treat those as requirements, not as moral failure.

Is a logged sandbox shadow AI?

No. Fake data, no production writes, company login: that is a pressure valve. Production customer lists in a personal account are not.

How is this different from shadow IT?

Shadow IT is often an unsanctioned system. Shadow AI is often unsanctioned generation on a laptop you issued. Your asset inventory will look clean while the prompts leave.

What does IBM’s research actually say here?

IBM reported shadow-AI incidents, higher average breach cost where shadow AI was high, and a large share of organisations lacking AI governance policies. Use it as evidence that this is a control topic, not a manners topic. Read the newsroom summary.

Will a better acceptable-use policy be enough?

Write it. Then put the same rules in a product people can finish the job with. PDFs do not see Salesforce.

How do writes sneak in?

The model never calls Salesforce. A human pastes the answer. That is still a change to a live system with no quote and no named signer. See What is write-back governance.

Should we ban plugins and personal API keys?

Treat them as unsanctioned processing until they sit on a company path with a ceiling. Keys in wikis are an unmetered utility and a credential incident.

What is the first sanctioned path worth shipping?

Read-only connectors on the jobs people already paste — email, extract, summarise — plus a wiki they can cite. Writes come later, fail-closed. Speed matters more than a perfect platform launch.

What is AI governance and What is write-back governance.

Sources

See what governed AI looks like on your stack.

Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.