An approved application can still support an unapproved workflow. Permission to draft public marketing copy does not authorize uploading customer records or connecting an agent to a production system, even when both use the same vendor. That gap is where shadow AI lives.
What Is Shadow AI?
Shadow AI is the use of AI applications, models or services for work without the organization's approval or oversight. It includes unauthorized chatbots, coding tools, model APIs and connected AI services.[1]
To manage shadow AI, identify the tools employees use, establish what data and permissions those tools receive, and approve specific workflows. Pair clear usage rules with tested technical controls and an accessible alternative for legitimate work.
For governance purposes, record both the tool and the permitted use. The question for IT is therefore broader than which AI websites employees visit: what information crosses the boundary, which identity grants access, and what actions become possible?
Shadow AI and Shadow IT Require Different Reviews
Shadow AI is a subset of shadow IT, which covers unauthorized applications and services more generally. AI introduces additional concerns around information sent to models and actions performed by connected tools.[1]
Figure 1. The conventional review still applies. The four questions beneath it are what a brand-name approval leaves unanswered.
A conventional application review remains useful, but an AI review should also establish:
- Input scope: What can employees paste, upload or retrieve through connectors?
- Output use: Is the result a draft, a technical recommendation or an instruction that another system executes?
- Action scope: Can the tool only read information, or can it send messages, change records and run commands?
- Approval boundary: Which account, subscription, configuration and workflow were reviewed?
Consider a hypothetical sales team. Drafting an email from public product information and connecting an AI assistant to the entire customer relationship management database are separate approval decisions, even when both use the same vendor. Reviewing a brand name alone leaves that distinction unresolved.
The Main Shadow AI Risks Depend on Data and Permissions
Treat an unapproved tool as a review trigger. Determine the actual exposure before assigning incident severity.
Figure 3. Finding the tool starts the investigation. Severity follows the exposure assessment, not the discovery.
Sensitive information can leave approved handling processes
AI inputs and outputs can expose personal information, confidential business material and credentials. Restricting data sources and applying least privilege are relevant safeguards.[2]
For each proposed workflow, ask where information is processed, how long it is retained, who can access it, whether it may be used for training, and how deletion works. Evaluate the specific service tier and contractual terms.
Do not use training disabled as the entire approval criterion. A review should also cover retention, access, integrations and the sensitivity of the information involved.
A useful policy distinction is between public information, internal information and restricted information. Map those categories to the company's existing classification system rather than creating an incompatible AI-only vocabulary.
Agents can turn an incorrect answer into an operational change
Connected AI systems can perform damaging actions when their functionality, permissions or autonomy exceed the task's requirements. Unexpected or manipulated model outputs can trigger those actions.[3]
For an agent, document the downstream identity and its effective permissions. Specify the allowed operations, require human authorization for selected high-impact actions, and enforce access restrictions in the connected systems.[3]
Figure 2. The diagram the approval record has to fill in: what reaches the tool, what the tool reaches, whose access it borrows, and where a person intervenes.
A proposed approval might allow an assistant to read a designated support queue while excluding permission to delete tickets or send refunds. The business owner should define the permitted task; IT should verify that the configuration enforces it.
Plausible output can bypass established quality checks
Generative AI can confidently produce incorrect information. Output evaluation and source verification remain necessary even when the application is approved.[4]
Define who checks work before it reaches customers, production systems or consequential decisions. Review generated code through the normal development process, including the security checks appropriate to the change.
Vendor approval and output approval serve different purposes. Neither should substitute for the other.
Unclear ownership complicates response
Assign a business owner before authorizing a workflow. That owner should identify the users, data involved, operational dependency and fallback process.
Without this record, an investigation must first establish who configured the tool and whether stopping it will interrupt essential work. Ownership is therefore a practical response control, not simply an entry in an inventory.
What Current Breach Research Shows, and What It Does Not
The 2026 Cost of a Data Breach Report reported shadow AI involvement in 43% of security incidents studied, compared with 20% in its 2025 report. Its research covered 602 organizations that experienced a breach between March 2025 and February 2026.[5]
Figure 5. Useful for justifying a review of unauthorized AI workflows; not a forecast of any single company’s likelihood of loss.
Those figures describe a sample of breached organizations. They do not establish that 43% of all businesses have suffered a shadow AI incident, and the annual studies use different organizational samples.[5]
Use the findings to justify examining unauthorized AI workflows. Avoid converting a breach benchmark into a forecast of the company's own likelihood of loss.
How to Detect Shadow AI Without Overstating Coverage
Build discovery around complementary evidence sources. Application discovery, data inspection and permission review answer different questions.
Network-based discovery can identify traffic to recognized AI services and show users, usage patterns and transferred data volumes. Application-level discovery does not itself establish the contents of a prompt; payload inspection is a separate capability.[1]
The following matrix is a proposed starting framework. Choose evidence sources and controls that your environment can support, then test their coverage.
| AI usage pattern | Evidence to review | Proposed control | Suggested accountable team |
|---|---|---|---|
| Browser chatbot | Network activity, managed browser events and employee disclosure | Approved account rules; data restrictions; supported upload or paste controls | Security and IT |
| Browser extension or desktop assistant | Endpoint software inventory, extension inventory and permissions | Managed installation policy; permission review; removal of prohibited tools | Endpoint management |
| AI feature inside existing SaaS | Tenant settings, feature configuration and vendor change notices | Feature-level approval and documented permitted data | SaaS application owner |
| Coding assistant or model API | IDE inventory, key ownership, billing and repository configuration | Approved integrations; credential management; defined repository access | Engineering and security |
| Local model or local agent | Installed software, processes, configuration and employee disclosure | Reviewed deployment; controlled data access and connectors | Endpoint management and engineering |
| Connected agent or MCP service | Connector grants, service identities, tool configuration and action logs | Restricted permissions; selected human approvals; revocation procedure | Identity team and business owner |
For workflows that use Model Context Protocol (MCP) services, include those connections in the review rather than treating the model provider as the complete system.[1]
Test discovery and enforcement separately
A dashboard entry does not prove that a tool can be blocked.
Figure 4. Question four is the one most often answered by implication rather than evidence. Validate it with synthetic data in each configuration you rely on.
For example, Microsoft's documented Shadow AI agent management feature was in preview as of August 2026. It listed several discoverable local AI applications, while its blocking capability was limited to OpenClaw on eligible managed Windows devices.[6]
Similarly, Microsoft Purview supports warnings or blocking for sensitive information shared with third-party AI sites through supported browser configurations. Coverage depends on prerequisites such as device onboarding, browser support, extensions or integrations, and billing configuration.[7]
Validate vendor answers with synthetic data. Record the device, browser, account type, attempted action and observed result. A successful test in one configuration should not become a claim of protection across every endpoint.
Record the blind spots
List routes outside the deployed monitoring scope, including unmanaged devices, unsupported clients, personal accounts and local workflows.
A network monitoring layer cannot establish what happened entirely offline. Review local installations and their data access separately.
Avoid interpreting the absence of an alert as proof that an application is unused. It may indicate that the relevant activity is outside the collection scope.
Keep monitoring proportionate
Approve a collection plan before capturing prompts or responses. Specify the purpose, authorized reviewers, retention period and circumstances requiring content-level investigation.
Start with metadata where it answers the question. Expand collection only when needed and permitted. Prompt logs can themselves contain confidential information, so include them in access and retention controls.
Approve AI Workflows With a Short Decision Record
Use one approval record per materially different workflow. The following fields make an approval concrete and reviewable:
- Business purpose and accountable owner.
- Vendor, application, subscription and account type.
- Authorized users and data classifications.
- Retention, deletion, training use and relevant vendor access terms.
- Connected repositories, SaaS systems and external tools.
- Identity, permission scope and allowed actions.
- Required output review and escalation process.
- Monitoring method, known coverage gaps and revocation procedure.
- Review date and conditions that require reassessment.
Write the outcome as approved within scope, approved with conditions, pending review or prohibited.
Pending review should not become indefinite permission. Set an owner and deadline. For exceptions, record the justification, compensating controls and expiry date.
Define reassessment triggers explicitly: a new connector, broader data access, a change in account tier, additional autonomous actions or a material vendor change. These triggers make approval a maintained control rather than a one-time questionnaire.
A Shadow AI Policy Template for Enterprise Use
The following is an adaptable policy starting point. Replace the placeholders and align its data categories with existing company rules.
1. Scope and approved use
Employees and contractors may use AI for company work only within an approved workflow. Approval applies to the specified application, account, data, integrations and actions.
The approved AI register is maintained by [team] at [location]. Requests and questions go to [channel].
2. Accounts and access
Use company-managed accounts where required by the approved workflow. Do not substitute a personal account for an approved business account or share credentials.
Access must be assigned through the approved identity process and removed when no longer needed.
3. Data handling
Public information may be used in workflows approved for public data.
Internal or restricted information may be submitted only when the approval record explicitly permits that classification. Do not submit passwords, private keys, access tokens or comparable authentication secrets.
Removing names does not automatically authorize a dataset. Submit a request when its classification or suitability is unclear.
4. Integrations and agents
Obtain separate approval before connecting AI to company systems, installing an AI extension, creating an API integration or enabling automated actions.
Use only the permissions recorded in the approval. Actions designated as requiring human authorization must remain subject to that authorization.
5. Output review
The employee or designated reviewer remains responsible for checking AI-assisted work before its intended use.
Apply the workflow's review requirements to factual statements, customer communications, generated code and consequential recommendations. Do not treat generated references as verified evidence.
6. Reporting and incident handling
Report suspected sensitive-data exposure, unexpected agent actions and previously undisclosed work use through [security channel].
Provide the application, account, approximate time, data category and connected systems involved. Follow security instructions for preserving evidence and containing activity.
Do not continue testing a suspected exposure with real company data.
7. Exceptions
Exceptions require a named owner, documented reason, defined data and access boundaries, compensating controls, and an expiry date.
An exception does not authorize uses outside its recorded scope.
8. Review and ownership
[Policy owner] maintains the policy and approved register. Business owners report material changes to workflows, permissions, integrations or vendor terms.
IT and security validate relevant controls before approval and after changes that could alter their effectiveness.
Publish the policy alongside concrete examples and a request form. Employees should be able to identify an approved route for their task without interpreting a lengthy security document.
A 30-Day Plan to Establish Initial Controls
Use the first month to establish a working baseline. The milestones below are a proposed sequence, not a promise of complete enterprise coverage.
Figure 6. Each week ends in a deliverable rather than a status update, which is what makes the sequence auditable afterwards.
Days 1 to 7: Establish ownership and discover usage
Assign a sponsor and operational owner. Ask department leads to disclose AI tools, embedded features and integrations already in use.
Combine those responses with available network, endpoint, identity, procurement and SaaS evidence. Record whether each inventory entry is confirmed, reported or still being investigated. Prioritize workflows involving restricted data, broad permissions or automated changes.
Days 8 to 14: Review the highest-risk workflows
Assess data access and action permissions for priority entries. Separate tools requiring immediate restriction from workflows that can proceed under documented conditions.
Select an approved route for common legitimate tasks. Publish interim rules explaining permitted data and how to request access.
Days 15 to 21: Validate and deploy controls
Test supported restrictions using synthetic inputs. Verify account boundaries, selected data controls, connector permissions and revocation steps.
Review warnings before broad enforcement where practical. Resolve false positives and document unsupported configurations. Handle confirmed sensitive-data exposure through the incident process rather than waiting for the rollout.
Days 22 to 30: Train teams and exercise response
Use role-specific scenarios: public copy for marketing, sanitized troubleshooting for support, and approved repository access for engineering.
Run a tabletop exercise involving an unauthorized upload or an agent with excessive permissions. Confirm who investigates, who can revoke access and who assesses business impact.
Measure Coverage and Resolution, Not Just Discovered Tools
A rising discovery count may reflect better visibility. Pair tool counts with measures that show whether identified risks are being resolved.
| Measure | Calculation |
|---|---|
| Ownership coverage | Confirmed AI workflows with a named owner, divided by confirmed workflows |
| Review completion | Priority workflows with a recorded decision, divided by priority workflows identified |
| Control validation | In-scope device and browser configurations with passing tests, divided by configurations requiring protection |
| Approval turnaround | Time from a complete request to a decision |
| Exception closure | Expired exceptions resolved by their due date |
| Permission remediation | Identified excessive grants removed or justified |
State each metric's scope. All managed Windows devices tested is a different claim from all employee AI use covered.
As AI moves further into existing software and connected agents, maintaining the approval boundary will require ongoing attention to changes in data access and action permissions. Assign responsibility for those changes now so the next feature rollout has a defined review path.
FAQ
Does a paid AI subscription make it approved for company work?
No. Payment establishes a commercial relationship, not company authorization. Approval should identify the account tier, permitted data, integrations and workflow.
Can employees use public information in an unapproved AI tool?
The organization must define that rule. A practical policy can provide a simplified approval path for public-data tasks while still reviewing installation requirements, accounts and output use.
Are local AI models automatically safer?
Local processing can change where information is handled, but it does not resolve every risk. Review the application's actual network behavior, local access, connectors, credentials and permitted actions before approval.
What should an employee do after uploading restricted information?
Report the activity promptly through the designated security channel. Identify the service, account, time and information involved. Preserve available evidence and follow the incident team's instructions rather than independently deleting records or testing further.
Should a company block every AI website?
Choose controls based on the workflows the company permits and the risks it needs to contain. Website restrictions should be evaluated alongside account controls, endpoint policies, integration permissions and an approved way to complete legitimate tasks.
Who should own the shadow AI register?
Assign one team responsibility for maintaining the register. Business owners should maintain workflow details, while IT, security and other relevant reviewers contribute approval decisions and control evidence.
Sources
- Microsoft, "Shadow AI discovery in Global Secure Access," 2026. learn.microsoft.com
- OWASP Gen AI Security Project, "LLM02:2025 Sensitive Information Disclosure," 2025. genai.owasp.org
- OWASP Gen AI Security Project, "LLM06:2025 Excessive Agency," 2025. genai.owasp.org
- National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, 2024. nvlpubs.nist.gov
- IBM and Ponemon Institute, "Cost of a Data Breach Report 2026," 2026. ibm.com
- Microsoft, "Manage agent shadow AI," 2026. learn.microsoft.com
- Microsoft, "Use Microsoft Purview to manage data security & compliance for other AI apps," 2026. learn.microsoft.com
AI Governance Regulations and Rules for Enterprise Businesses
Technology Strategy vs Digital Transformation: What’s the Difference and Why It Matters
Technology Strategy vs Digital Transformation: What’s the Difference and Why It Matters Organizations today rely heavily on technology to compete, innovate, and serve customers. As a result, two concepts frequently appear in business discussions: technology strategy...
What Is a Technology Strategy?
What Is a Technology Strategy? Modern organizations depend on technology not just to operate, but to compete. Customer expectations, remote work, automation, cybersecurity risks, and data-driven decision-making have fundamentally changed how businesses function. As a...
Palantir’s stock is winning over Wall Street. Another analyst just turned bullish.
**Palantir Technologies: Analyzing the Recent Market Selloff and Its Implications for AI Leadership** In recent weeks, Palantir Technologies has experienced a significant and, according to some analysts, “unjustifiable” selloff in its stock price. This downturn has...
The surprising reason why the U.S. economy is growing so fast
**Corporate Spending Set to Propel U.S. Economic Growth for Fifth Consecutive Year** As the U.S. economy continues to navigate the complexities of a post-pandemic landscape, corporate spending is emerging as a significant driver of growth, positioning the nation for...



