Shadow AI: Risks, Examples, and 5 Prevention Best Practices
- 12 minutes to read
Table of Contents
What Is Shadow AI?
Shadow AI refers to the unauthorized use of artificial intelligence tools, platforms, and third-party integrations by employees without IT or security approval. Driven by a desire for increased productivity, workers often use unvetted chatbots, plugins, and SaaS AI features to complete tasks faster.
The Risks of Shadow AI
Unlike traditional “shadow IT” (unapproved software that simply stores data), shadow AI involves dynamic models that can process, learn from, and potentially leak your proprietary data:
- Data leakage: Employees frequently paste sensitive company data, source code, or financial projections into public chatbots, which may then be used to train external models.
- Regulatory non-compliance: Sharing customer records or personal information (PII) on unsecured AI platforms can violate strict frameworks like GDPR or HIPAA, leading to severe fines.
- Security gaps: Unapproved AI browser extensions and embedded AI features can act as backdoors, exposing companies to malware and providing high-level access to company systems.
This is part of a series of articles about AI cyber security
The Risks of Shadow AI
Data Leakage
Shadow AI increases the risk of data leakage because employees may input sensitive or proprietary information into external AI tools without considering where that data will be stored or how it will be processed. For example, submitting confidential client information to a public generative AI chatbot can result in that data being retained by the service provider, potentially exposing the organization to unauthorized access or unintended data sharing. Such incidents can compromise intellectual property or violate contractual confidentiality agreements.
This risk is amplified by the lack of visibility and control over these tools. When IT and security teams are unaware of which AI services are being used, they cannot enforce data protection policies or ensure compliance with internal standards. The absence of logging and monitoring further complicates incident response and data breach investigations, making it difficult to track what data has left the organization and who is responsible for the exposure.
Regulatory Non-Compliance
Shadow AI can lead to regulatory non-compliance when unsanctioned AI tools process personal or sensitive data in ways that violate legal or industry requirements. For example, using AI services that store data in jurisdictions with weaker privacy protections may breach regulations like GDPR, HIPAA, or other data residency laws. Organizations may inadvertently expose themselves to fines, legal action, or reputational damage if they cannot demonstrate proper controls over data usage.
Many regulatory frameworks require organizations to maintain an inventory of systems that handle regulated data, conduct regular risk assessments, and ensure third-party vendors meet specific security standards. Shadow AI undermines these requirements by introducing unknown tools into business processes, making it impossible to certify compliance or respond effectively to audits and regulatory inquiries.
Related content: Read our article about AI regulations and LLM regulations
Security Gaps
The use of unapproved AI tools can create significant security gaps in an organization’s technology ecosystem. Shadow AI often bypasses established security controls such as authentication, data loss prevention, and endpoint protection, leaving sensitive data exposed to potential breaches. These tools may also introduce vulnerabilities if they are poorly maintained, lack encryption, or are subject to supply chain attacks.
Security teams are left unable to monitor, patch, or respond to incidents involving Shadow AI, as these systems operate outside of official channels. This fragmented approach to AI adoption can result in inconsistent security practices, unpatched vulnerabilities, and increased risk of exploitation by threat actors targeting shadow infrastructure. Over time, this erodes the organization’s overall security posture and increases the likelihood of successful attacks.
Shadow AI vs. Shadow IT
Shadow AI and Shadow IT share similarities in that both involve the use of unsanctioned technology within organizations. However, Shadow AI specifically refers to artificial intelligence tools and services, while Shadow IT encompasses any unapproved hardware, software, or cloud service. Shadow AI is a subset of Shadow IT but brings unique risks due to the complexity and data-centric nature of AI technologies. These risks include the potential for data leakage, model bias, and regulatory non-compliance that are less common with traditional Shadow IT.
The growing adoption of AI tools by employees often happens in parallel with other forms of Shadow IT, further complicating governance. While Shadow IT might involve using unauthorized file-sharing apps or productivity tools, Shadow AI can directly impact business-critical data and decision-making processes. This distinction makes it essential for organizations to adopt targeted controls and governance frameworks that address the specific challenges posed by Shadow AI, rather than relying solely on existing Shadow IT management practices.
Tips from the expert

Steve Moore is Vice President and Chief Security Strategist at Exabeam, helping drive solutions for threat detection and advising customers on security programs and breach response. He is the host of the “The New CISO Podcast,” a Forbes Tech Council member, and Co-founder of TEN18 at Exabeam.
Tips from the expert:
In my experience, here are tips that can help you better manage Shadow AI:
- Track AI usage at the identity level, not just the application level: Measure which departments, roles, and users are adopting AI services. Identity-based visibility often reveals high-risk adoption patterns long before a new AI platform becomes widespread.
- Create an “approved AI alternatives” catalog: Employees often adopt Shadow AI because they lack an approved option. Maintaining a catalog of vetted AI tools with defined use cases reduces the incentive to bypass governance.
- Monitor outbound API traffic for AI providers: Many Shadow AI integrations never appear as browser activity because they communicate directly through APIs. Inspect outbound API destinations and authentication patterns to identify hidden AI usage.
- Classify prompts as sensitive data: Organizations often classify documents but overlook prompts. Prompts can contain source code, customer records, product plans, or legal strategies and should be protected with the same controls as other sensitive data.
- Review browser extensions separately from SaaS applications: AI-powered browser extensions frequently bypass traditional SaaS governance by capturing webpage content, emails, CRM data, or internal documents. They require dedicated discovery and approval processes.
Causes of Shadow AI
Employees Need Faster Ways to Work
Many employees turn to AI tools because they provide a faster, more efficient way to complete tasks, solve problems, or analyze data. Traditional business processes can be slow and cumbersome, especially when they rely on legacy systems or require multiple layers of approval. AI tools often offer automation, quick insights, and simplified workflows, making them attractive for employees who are under pressure to deliver results quickly or meet tight deadlines.
This drive for efficiency leads employees to bypass official channels and adopt AI solutions independently. When organizational processes are perceived as obstacles rather than enablers, employees are more likely to seek out tools that help them work smarter, even if it means ignoring established procurement or security procedures.
AI Tools Are Easy to Access
The accessibility of AI tools has dramatically increased, with many platforms offering free or low-cost access to powerful models and APIs. Publicly available generative AI chatbots, coding assistants, and analytics platforms require little more than an email address to sign up and start using. This ease of access lowers the barrier to adoption and makes it simple for employees to experiment with AI without involving IT or security teams.
Even employees without technical backgrounds can integrate AI into their daily work, often without understanding the implications. The widespread availability of AI tools on the internet, app stores, and cloud marketplaces means that organizations face an uphill battle in tracking and controlling every instance of unsanctioned AI usage. This trend is likely to continue as AI becomes more embedded in consumer and business software.
Procurement and Security Reviews Are Too Slow
Procurement and security review processes in many organizations are slow and bureaucratic, often requiring extensive documentation, multiple approvals, and lengthy vendor assessments. This can delay the adoption of new technology by weeks or even months, frustrating employees who need immediate solutions to business problems. In contrast, many AI tools can be adopted instantly, without waiting for formal approval.
The lag between employee needs and organizational processes drives the growth of Shadow AI. When users perceive official channels as barriers rather than support mechanisms, they are more likely to circumvent them and adopt tools on their own. This bypassing of established procedures increases risk, as IT and security teams lose visibility into what tools are being used, how data is being processed, and whether security and compliance requirements are being met.
Employees Do Not Understand the Risks
A significant driver of Shadow AI is the general lack of awareness among employees about the risks associated with unsanctioned AI use. Many users do not realize that inputting sensitive data into public AI tools can result in data retention, sharing, or exposure to third parties. They may also be unaware of regulatory requirements or the potential for model bias and unreliable outputs from unvetted AI systems.
This knowledge gap is compounded by the marketing of AI tools as safe, easy-to-use, and productivity-enhancing. Without proper training or clear policies, employees may assume that using any AI tool is acceptable as long as it helps them achieve their goals. Addressing this gap through education and communication is essential for reducing Shadow AI and ensuring that employees make informed decisions about technology adoption.
BYOA
Bring Your Own AI (BYOA) refers to employees using personal AI accounts or subscriptions for work-related tasks instead of organization-approved AI platforms. Employees may choose personal accounts because they already use them outside work, prefer specific features, or want to avoid restrictions imposed on corporate AI tools. Since these accounts are not managed by the organization, IT and security teams have little visibility into how they are being used or what data is being shared.
BYOA creates additional security and compliance challenges because business information may be processed outside approved environments. Organizations cannot enforce security settings, monitor usage, or apply retention and access controls to personal accounts. As a result, sensitive data can be exposed, intellectual property may leave the organization, and incident response becomes more difficult if an account is compromised.
Silent SaaS integrations
Many modern SaaS applications now include built-in AI features or allow users to connect external AI services with only a few clicks. Employees can enable these integrations without purchasing new software, making them easy to overlook during security reviews. In many cases, the integration begins processing organizational data immediately after it is enabled.
These silent SaaS integrations expand the organization’s AI footprint without the knowledge of IT or security teams. Data may flow between applications, AI providers, and cloud services in ways that are not fully understood or documented. Without centralized visibility and governance, organizations cannot accurately assess what data is being shared, whether regulatory requirements are being met, or whether the connected AI services meet internal security standards.
Common Examples of Shadow AI
Employees Using Public Chatbots for Work Tasks
A common example of Shadow AI is employees using public generative AI chatbots, such as ChatGPT or Google Bard, to draft emails, summarize documents, or generate reports for work purposes. These chatbots often reside outside the organization’s IT environment and may store user inputs for future model training. When employees input sensitive company or client data, they expose that information to third-party providers without any assurance of confidentiality or compliance with organizational policies.
Example:
A marketing employee copies a draft product roadmap into a public AI chatbot to generate presentation content. The chatbot processes confidential product plans on an external platform that has not been approved by the organization’s security team.
Developers Using Unauthorized Coding Assistants
Developers frequently turn to AI-powered coding assistants, such as GitHub Copilot or similar tools, to accelerate software development and automate repetitive coding tasks. When these tools are adopted without IT approval, they can access and process proprietary codebases, potentially exposing sensitive intellectual property to external vendors. Unauthorized use of coding assistants can also result in the integration of insecure or unlicensed code snippets into production systems.
Example:
A developer enables an unapproved AI coding assistant in their IDE and uses it while working on proprietary source code. The tool processes internal code without the organization’s knowledge or vendor security review.
Business Units Connecting AI Tools to SaaS Applications
Business units may independently connect AI-powered automation tools or analytics platforms to existing SaaS applications, such as CRM or ERP systems, to extract insights or automate workflows. These integrations often occur outside of IT governance, using API keys or OAuth tokens that are managed informally by business users. As a result, sensitive data flows between systems without proper monitoring or control.
Example:
A sales team connects an AI analytics platform to the company’s CRM using an OAuth integration to generate customer insights. The integration gains access to customer records without security approval or data governance oversight.
Unapproved AI APIs Embedded in Workflows
Organizations may unknowingly introduce Shadow AI when employees or development teams embed third-party AI APIs into internal applications or automated workflows without formal approval. These APIs can be used for tasks such as text generation, image analysis, translation, or document processing, often because they are easy to integrate and require only an API key. Because these integrations operate behind the scenes, they are often difficult for IT and security teams to detect.
Example:
A developer adds a third-party AI translation API to an internal document processing application to accelerate delivery. The integration sends customer documents to an external service that has not been reviewed for security or compliance.
Shadow AI Detection and Prevention Best Practices
Here are some of the ways to better protect an organization against the risks associated with shadow AI.
1. Establish Clear Ownership for AI Governance
Organizations should define clear ownership for AI governance by assigning responsibility to a dedicated team or cross-functional committee. This group typically includes representatives from IT, security, legal, compliance, procurement, and business units. Its role is to establish AI policies, evaluate new AI technologies, manage risk, and ensure AI adoption aligns with business objectives and regulatory requirements.
Clear ownership reduces confusion about who approves AI tools, responds to incidents, and maintains governance standards. It also creates accountability for ongoing oversight as AI technologies evolve. By centralizing decision-making while involving key stakeholders, organizations can encourage responsible AI adoption without unnecessarily slowing innovation.
Key actions:
- Assign executive ownership for AI governance and risk management.
- Define roles for IT, security, legal, compliance, and business teams.
- Establish policies for AI evaluation, approval, and ongoing oversight.
- Review governance responsibilities regularly as AI adoption grows.
2. Build an AI Inventory
Maintaining a centralized inventory of approved AI tools, models, APIs, and integrations gives organizations visibility into where AI is being used and what data it processes. The inventory should include information such as the business owner, vendor, purpose, data classifications involved, integration points, and results of security and compliance assessments. Keeping this information up to date helps organizations understand their AI footprint and prioritize risk management efforts.
An AI inventory should be reviewed regularly as new tools are introduced and existing services change. Automated discovery tools can help identify previously unknown AI applications by monitoring network traffic, SaaS usage, and API activity. Comparing discovered services against the approved inventory allows organizations to identify Shadow AI and take appropriate remediation or governance actions.
Key actions:
- Maintain an inventory of approved AI tools, models, APIs, and integrations.
- Record ownership, business purpose, and data classifications for each AI asset.
- Use automated discovery to identify unauthorized AI services.
- Review the inventory regularly to identify Shadow AI.
3. Create an Exception and Approval Workflow
Organizations should implement a simplified approval process that allows employees to request new AI tools without unnecessary delays. The workflow should define evaluation criteria covering security, privacy, compliance, vendor risk, and business value while establishing expected review timelines. A predictable and transparent process reduces the incentive for employees to bypass official channels.
Not every AI tool requires the same level of scrutiny, so organizations can adopt a risk-based approach. Low-risk productivity tools may qualify for an expedited review, while applications that process sensitive data or integrate with critical systems receive more comprehensive assessments. This balance helps support innovation while maintaining appropriate governance and security controls.
Key actions:
- Implement a documented process for requesting new AI tools.
- Use risk-based reviews based on data sensitivity and business impact.
- Define approval timelines and evaluation criteria.
- Periodically reassess approved AI tools and vendor risks.
4. Use DLP and Data Classification Controls
Data loss prevention (DLP) and data classification technologies help prevent sensitive information from being shared with unauthorized AI services. Organizations should classify data based on sensitivity and apply policies that restrict or monitor the transfer of confidential, regulated, or proprietary information to external AI platforms. These controls reduce the likelihood of accidental data exposure while allowing approved business use cases to continue.
Effective DLP strategies should extend across endpoints, email, web traffic, cloud applications, and API communications. When integrated with AI governance policies, DLP solutions can alert users before sensitive information is submitted to an unapproved AI tool, block prohibited actions, or generate alerts for security teams to investigate potential policy violations.
Key actions:
- Classify sensitive and regulated data before AI use.
- Block or monitor uploads of confidential data to unauthorized AI services.
- Extend DLP controls across endpoints, email, web traffic, and cloud applications.
- Alert security teams to policy violations involving AI platforms.
5. Monitor AI Activity with SIEM and Behavioral Analytics
Security information and event management (SIEM) platforms and behavioral analytics can improve visibility into AI usage across the organization. By collecting logs from endpoints, identity providers, cloud services, proxies, and network devices, security teams can identify access to unauthorized AI platforms, unusual API activity, or abnormal patterns of data transfers associated with AI services.
Behavioral analytics complements traditional monitoring by identifying deviations from normal user activity. For example, a sudden increase in uploads to external AI platforms or the use of previously unseen AI services may indicate Shadow AI adoption or potential data exfiltration. Continuous monitoring enables organizations to detect emerging risks early, investigate suspicious activity, and refine governance policies as AI usage evolves.
Key actions:
- Collect logs from endpoints, cloud services, identity systems, and proxies.
- Detect access to unauthorized AI applications and APIs.
- Use behavioral analytics to identify abnormal AI usage or large data uploads.
- Correlate AI activity with other security events to support investigations.
Related content: Read about how machine learning is transforming cybersecurity
Detecting and Managing Shadow AI with Exabeam
Detecting shadow AI requires analyzing network, proxy, and endpoint logs to identify unauthorized connections to external AI endpoints and public large language models. Exabeam New-Scale Analytics addresses this challenge by continuously monitoring web traffic and SaaS logs to surface unsanctioned AI tools and rogue API integrations. By applying behavioral analytics, the system establishes a baseline of normal data transfer patterns and flags anomalous outbound traffic, identifying sensitive corporate data leaks to public models. This continuous visibility allows security teams to map the entire AI footprint and enforce compliance before data exposure occurs.
Key capabilities of Exabeam New-Scale Analytics:
- Behavior-based detection: Learns normal behavior for both human and non-human identities and scores anomalies by rarity with business context, focusing analyst attention on the handful of events that truly require action rather than raw alert volume.
- Self-learning behavioral baselines: Builds dynamic baselines for human and non-human activity, adapts automatically to environmental changes, flags unusual behavior, and assigns multi-layered risk scores based on context and severity.
- Agent Behavior Analytics (ABA): Monitors AI agents and automated identities by collecting their activity, correlating it with users and devices, and highlighting actions that need review, with Observra standardizing agent telemetry across agents, models, and runtime environments.
- Pre-deployment verification (Praxen): Leverages the open-source Praxen framework to compare declared agent policies with code, configuration, and logs before deployment, identifying excessive permissions and configuration gaps before agents enter production.
- Runtime agent telemetry (Observra): Uses the open-source Observra SDK to capture, normalize, and enrich runtime activity such as model calls, tool execution, and token usage, eliminating visibility blind spots across different agentic frameworks.
- Secure model interoperability (MCP Server): Integrates AI models with Exabeam APIs via the Model Context Protocol (MCP) using user-delegated authentication, securing model-to-tool connections and logging all interactions in the Exabeam Audit Log.
- Shadow AI discovery: Automatically detects unauthorized AI tool usage, unmanaged API integrations, and rogue LLM subscriptions across the enterprise network by analyzing endpoint and network logs to prevent sensitive data exposure.
- SIEM augmentation without rip and replace: Integrates with your current architecture to add behavioral detections without replacing your SIEM, using hundreds of prebuilt integrations and the Open API Standard (OAS) to connect to thousands more tools.
- AI-driven triage and investigation: Exabeam Nova agents analyze detections, gather context, and build case summaries to move teams faster from alert to resolution, while accelerating detection engineering with AI-assisted rule creation and tuning.
- Entity context and risk prioritization: Attack Surface Insights aggregates identity and device data from multiple sources into a unified view, building detailed profiles and linking attributes to expose relationships and uncover hidden risk.
To see how behavioral analytics can surface the anomalous activity behind adversarial AI attacks before they affect downstream systems, explore Exabeam Agent Behavior Analytics.
Learn More About Exabeam
Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.
-
Video
Mizuho Financial Group Enhances Security Governance and Advances Internal Fraud Prevention with Exabeam
- Show More