Update cookies preferences

Shadow AI

Updated:
 
August 14, 2026
Overview

Shadow AI is the use of AI tools and agents inside an organization outside the visibility and policy framework of IT and security. It covers public chatbots employees paste sensitive text into, browser-based assistants, AI features inside approved SaaS applications that nobody reviewed, and coding agents loading skills nobody scanned.

  • AI use operating outside the visibility and policy framework of IT
  • Includes AI features inside approved SaaS that never went through review
  • Coding agents loading unscanned skills and rules are a common blind spot
  • Unsanctioned use carries a measurable breach cost premium

Why is shadow AI important?

Shadow AI matters because most enterprises now have AI activity inside their environment that no security tool currently sees. It is also the bridge between a conversation leaders already understand – employees pasting company data into a public chatbot – and the agent-layer security conversation they have not started yet.

The forms it takes are ordinary rather than exotic. Someone pastes a customer list into a consumer assistant to reformat it. A sanctioned SaaS application ships an AI feature that was never part of the original review. A developer installs a coding agent that loads skills and rules nobody scanned. None of these require intent to circumvent policy, which is why policy alone does not address them.

IBM found that a high level of unsanctioned AI use added $670,000 to the average breach cost, and that customer personal data was exposed in a markedly higher share of those breaches than the overall average. A program without an inventory of that activity is operating blind on the part of the estate most likely to leak.

What is shadow AI?

Shadow AI is any AI system in use inside an organization that sits outside the inventory and policy framework security and IT maintain. The defining characteristic is invisibility to the control plane rather than malice on the part of the user.

It takes four common forms. Public tools reached directly through a browser, where the data leaving the organization is whatever an employee pasted. AI features embedded in approved applications, sanctioned at the application level but never assessed as AI. Locally installed assistants and coding agents that run on endpoints with the user's own permissions. And self-built agents, often produced with low-code builders, that reach production without passing a platform review.

Shadow AI is distinct from shadow IT in one important respect. A shadow SaaS application stores data. A shadow agent takes actions, holding credentials and changing systems on its own, which raises the consequence from exposure to impact.

Types of shadow AI

Shadow AI groups usefully by how the AI enters the environment, because the entry path determines which discovery surface finds it and which control addresses it.

Employee-adopted tools are consumer or freemium AI reached through a browser or a personal account. The exposure is outbound data, and browser-level visibility is what surfaces it. Embedded AI features arrive inside software already approved, so nothing looks unsanctioned from a procurement view; SaaS and API integration is what reveals them. Developer-installed agents run locally with a user's permissions and are found through endpoint telemetry. Self-built agents constructed in low-code platforms tend to appear only in identity data, as service accounts and tokens nobody mapped to an owner.

The fifth category is the one most programs discover last: agents created by other agents, where a coding agent generates a workflow that authenticates and runs on its own.

Shadow AI & Onyx

Onyx surfaces shadow AI across browser, endpoint, network, and SaaS application surfaces in a single inventory, typically within 24 hours of deployment. Reading several surfaces at once is what closes the gaps a single-surface tool leaves, since a browser assistant and a locally installed coding agent are found by different signals.

What follows discovery is the part that matters. Because shadow AI arrives in the same inventory as sanctioned assets, it can be tagged, scored for posture, and brought under policy rather than logged as a finding. Discovery and shadow AI coverage is a starting point for governing that activity, not just for counting it.

Frequently Asked Questions

Is shadow AI the same as shadow IT?
Related but not equivalent. Shadow IT is unsanctioned software. Shadow AI includes unsanctioned tools, but also AI features inside approved software and agents that hold credentials and take actions. The action capability is what raises the stakes beyond data exposure.
Why does approving a SaaS tool not cover its AI features?
Because the review assessed the application, not the model behind a feature added later. An AI assistant bolted onto an approved platform may send content to a third-party model, retain prompts, or act on data the original assessment never considered.
How do we find shadow AI without blocking everything?
Start with discovery rather than enforcement. Once you can see which tools are in use and what data they touch, you can sanction the useful ones and route the rest toward approved alternatives. Blocking first tends to push usage further out of view.
What makes coding agents a particular concern?
They load skills, rules, and packages that nobody scanned, and they run with a developer's permissions. That combination means an unreviewed instruction file can reach code and credentials without any of it appearing as a policy violation.
Which framework addresses unsanctioned AI use directly?

The NIST Generative AI Profile covers risks specific to generative systems including data leakage through third-party tools, and the OWASP Top 10 for LLM Applications covers sensitive information disclosure.

Related terms:
Table of Contents