Back to glossary

Shadow AI

2 min read

In security, shadow AI is the use of AI tools inside an organisation without approval or oversight: staff pasting company data into public assistants, teams wiring unsanctioned models into workflows. It is the new, uncontrolled data-leak channel, and it is what makes the older understanding of data loss prevention out of date.

July 29, 2026
Compartir:

How it works

Shadow AI is shadow IT for the AI era: capability adopted by staff faster than governance can approve it. An analyst pastes a customer list into a public chatbot to summarise it, a developer routes source code through an unapproved coding assistant, a team builds an internal workflow on a model API nobody in security signed off. Each is a reasonable attempt to get work done, and each moves data outside the organisation’s controls. Because the tools are consumer-grade and browser-based, they leave no trace in the traditional monitoring built for email and file transfer, which is why the exposure is invisible until something surfaces.

What goes wrong

From a data-protection standpoint, the failure is a leak with no exfiltration event to catch. The information leaves through a paste into a text box, not through an attachment or an upload a legacy control would inspect. What we see is that the data most likely to be pasted is exactly the sensitive kind (a support transcript, a contract, a chunk of code with secrets in it), because that is what people need help with. There is also a downstream risk: an unsanctioned model or plugin is an unreviewed part of the AI supply chain, and its own security is unknown. The organisation cannot protect what it cannot see, and shadow AI is deliberately out of sight.

Where this shows up in an audit

We assess shadow AI as a governance and exposure problem, not a technical vulnerability in one system. The questions are what AI tools are in use (sanctioned and not), what data classes are reaching them, and whether the controls (browser, network, endpoint) can even observe the flow. Data classification is the starting point, because you cannot restrict what you have not labelled. Regulatory exposure under the EU AI Act is noted where relevant. This is part of how we assess unsanctioned AI exposure.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.