Shadow AI: the AI your team already uses and you cannot see

By Kike Gandia · Co-Founder & CEO, OSCP

Shadow IT has been a known problem for years: applications entering the company without going through IT. Shadow AI is its accelerated version, and it spreads faster for two reasons: it requires installing nothing, and it produces an immediate, visible benefit for whoever uses it. A browser and a personal account are enough for corporate information to start leaving the organisation with no record at all.

What shadow AI actually is

Shadow AI is the use of artificial intelligence tools inside the organisation without approval, inventory or oversight. It takes three distinct forms, and they are worth separating because each is controlled differently.

The first is direct use of public assistants —ChatGPT, Gemini, Claude, DeepSeek— from personal accounts. The second is AI features switched on inside already-approved tools: a CRM that adds automatic summaries, a ticketing system that suggests replies, an office suite that ships an assistant. The third, and hardest to detect, are browser extensions and integrations requesting broad permissions over mail or file storage.

The second category is the one that surprises IT teams most: there was no decision to adopt AI — the vendor simply enabled it in an update.

Why it happens, and why it is not a discipline problem

Shadow AI does not appear out of bad faith. It appears because the tool solves a real problem —writing faster, summarising a long meeting, understanding a code error— and because the official channel, where one exists, is slower than opening a tab.

Treating it as a disciplinary problem has a predictable effect: usage does not drop, it just stops being visible. People keep using the tool from their phone and stop asking. The organisation loses the only source of information it had about what was going on.

The approach that works is the reverse: discover first, understand the use case, and offer an approved alternative that is at least as convenient. Banning without offering a substitute guarantees the usage continues out of sight.

How to find which AI tools are in your company

Discovery combines several sources, and none is sufficient alone:

  • Network, proxy or DNS logs: identify traffic to AI vendor domains. Fastest route to a first inventory, but blind to personal phones and to remote work outside the VPN.
  • OAuth applications connected to your tenant in Google Workspace or Microsoft 365: reveals integrations holding permissions over mail, calendar or files, which are the highest-impact ones. This is where the surprises usually are.
  • Browser extensions deployed on managed devices.
  • Spend: AI subscriptions paid on company cards or filed as expenses, sometimes the only trace of a tool used by an entire department.
  • Asking, genuinely and without consequences. A five-minute anonymous survey usually returns more tools than the network analysis, because it covers usage from personal devices.

Reviewing connected OAuth applications is the step most often skipped and the one concentrating the most risk: an assistant with read access to all corporate mail is a far larger exposure surface than someone pasting text into a chat.

What the real risk is

The dominant risk is information leaving: contracts, customer data, proprietary code or internal documentation ending up in a third-party service whose retention terms nobody has read. On free accounts, content can frequently be used to improve the model.

The second risk is unchecked dependence: decisions or deliverables built on AI output nobody verified, with the added problem that there is no record of what was generated and what was reviewed.

The third, quieter one is compliance: if your organisation is subject to the ENS, ISO 27001 or the AI Act, being unable to enumerate which AI systems are used and for what is itself an audit finding, regardless of whether an incident has occurred.

From discovery to control, without slowing the team down

The order that works is: inventory, classify by use case, approve corporate alternatives for the most frequent legitimate cases, publish a short policy naming the approved tools, and train the team with examples from the business itself.

The step most often skipped is the third. If the inventory shows twenty people using a public assistant to summarise meetings, the useful response is not to ban it: it is to enable that same capability in a tool with a processing agreement and no training on your data. Shadow AI shrinks by offering a better path, not by closing the existing one.

FAQ

How do I know whether there is shadow AI if nobody admits it?

Start with the OAuth applications connected to your Google Workspace or Microsoft 365 tenant, and with DNS or proxy logs pointing at AI vendor domains. Those two sources usually produce an initial inventory within hours. Complete it with an anonymous survey: usage from personal devices appears in no corporate log and is only discovered by asking without consequences.

Is an employee using ChatGPT on their personal phone shadow AI?

If they use it with company information, yes, and it is the hardest variant to control because it leaves no trace in corporate infrastructure. That is why purely technical control has a low ceiling: the combination that works is a convenient approved alternative, a clear policy on which data never leaves, and training with real examples.

What is the difference between shadow IT and shadow AI?

Classic shadow IT usually involves installing software or contracting a service, which leaves a trace in spend or on devices. Shadow AI needs only a browser and a personal account, spreads faster, and additionally appears passively when a vendor switches on AI features in a tool you had already approved, without anyone making a decision.

Does blocking AI vendor domains solve the problem?

It reduces usage on the corporate network and works as a temporary measure, but it pushes usage to personal devices, where you lose all visibility. As a standalone measure it usually makes the real situation worse: the same volume of information leaves the organisation, now with no record at all.

Related service

AI governance and safe AI use service

Related content

Sources

Discover which AI is being used in your organisation