Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialThe AI version of shadow IT is proving to be just as pernicious as its more traditional counterpart — and in some ways, it’s harder for organizations to see and control.
Shadow AI refers to AI tools or AI-powered features that employees use for work without the knowledge, approval, or oversight of IT, security, or compliance teams. That use can range from the relatively innocuous — an employee pasting a document into ChatGPT or Claude to summarize it — to far riskier things such as installing an unapproved AI coding assistant that touches proprietary source code or giving personal AI agents access to company data and systems.
Multiple surveys, including Proofpoint’s State of AI Security 2025 and Unseen Security’s State of Shadow AI 2026 report, have reported growth in unsanctioned AI use while warning about the security risks it creates for enterprises. These include sensitive data exposures and leaks, AI systems gaining unauthorized access to corporate applications, and employees relying on untrusted and unvetted AI-generated content.
One of the most significant risks associated with shadow AI is unreviewed access, said Gal Nakash, co-founder and chief product officer at Reco. A survey that Reco conducted last year showed that more than 70% of knowledge workers used AI tools without IT's approval or knowledge and that 38% admitted to uploading sensitive data to AI tools. OpenAI accounted for 53% of all shadow AI usage across the enterprises in the survey and represented by far the biggest single source of risk.
Here’s why shadow AI poses such a huge risk to your organization — and four steps to reining it in.
[ Webinar: Less Noise, More Signal: Have the Right Tools for a Modern SOC ]
Many employees turn to unsanctioned and unmanaged AI tools because those tools can solve immediate work problems faster than approved processes. Shadow AI can also emerge from gaps in governance. Both are issues that have long contributed to the prevalence of shadow IT.
But while some of the underlying causes might be the same, the security risks posed by shadow AI can be substantially different. Where shadow IT’s risk lies in unmanaged applications storing or processing company data, shadow AI adds action and autonomy, Nakash said.
“An unapproved file-sharing app may expose data placed inside it, but an unsanctioned AI agent can become an insider threat. It may read data from one system, trigger workflows, and continue operating after the employee who created it changes roles or leaves.”
—Gal Nakash
More concerning is that organizations often underestimate the extent of shadow AI in their environments. In a recent ThreatDown survey, 74% of responding organizations said they had found that employees were using substantially more AI tools than the organizations had suspected. In 30% of the cases, the organizations had discovered four times the number of AI tools they had expected. On average, 58% of employees at the surveyed organizations reported using AI tools at work.
Aviv Nahum, co-founder and CEO of Above Security, said a big danger is that employees can build shadow business processes that rely on AI agents having credentials, permissions, access to enterprise data, and the ability to take actions across multiple systems.
“At that point, you haven’t just introduced another SaaS application. You’ve effectively introduced a new insider into the organization.”
—Aviv Nahum
The organization can be unaware that the agent exists, much less who created it, what permissions it was given, what data it can reach, or whether its behavior continues to match the task it was intended to perform. Meanwhile, AI agents are using their credentials without supervision. “A valid credential tells you almost nothing about whether the activity behind it is safe,” Nahum said.
Besides expanding risk much more than shadow IT, shadow AI is harder to address because you can’t just identify and block unauthorized software or devices. AI that is embedded in approved applications such as Salesforce or Microsoft 365 or installed in personal devices is pretty much undetectable, and AI behaviors can change rapidly as employees adopt new tools. Security teams have little hope of building a complete inventory of where AI is being used and what data is being shared with it.
Seemant Sehgal, founder and CEO of BreachLock, saidshadow AI is harder to scope than shadow IT because the artifact is often just a prompt and a pasted response — nothing that registers on a network or an endpoint agent to alert security teams.
“An employee running an unsanctioned SaaS tool in 2015 left a DNS query. An employee pasting proprietary deal terms into a consumer AI assistant today leaves almost nothing visible to a security team. Organizations benchmarking their exposure against what they can see are almost certainly missing the full picture and only measuring a fraction of it.”
—Seemant Sehgal
Given the difficulty of spotting and inventoryingAI, organizations need an approach that combines visibility, governance, and access controls.
The challenge, security experts say, is that much of AI activity occurs outside the traditional security controls organizations rely on. They advise taking four actions.
Discovery is more effective than blocking usage, Reco’s Nakash said.
“A blanket ban usually pushes usage deeper into unmanaged channels.”
—Gal Nakash
Security teams should aim for a live inventory of AI tools, agents, copilots, browser extensions, OAuth grants, and AI-enabled app features operating across their ecosystem. From there, they should identify for AI connection the owner, the business purpose, the permissions scope, and the review cycle. “The highest priority should go to tools that touch sensitive data, customer records, financial workflows, source code, regulated information, or production systems,” Nakash said.
Organizations should establish clear, enforceable policies covering approved tools, prohibited data exposures, acceptable use, and consequences. The approved path should be easy enough that employees have no incentive to circumvent it. “Build an AI governance program with enforceable acceptable-use policies that name which tools are approved, which data categories are off-limits, and what the consequences are," advised Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs.
“Inventory which AI platforms employees actually use, including personal accounts on corporate devices, and audit the AI features inside your already-approved SaaS stack, because those likely never went through an AI-specific risk assessment.”
—Jacob Krell
Merely knowing which AI tools are present isn’t enough. It’s also important for organizations to assess what information each AI system can access and what it can do, said Donald McFarlane, advisory board member at Xcape.
“Asking AI to fix grammar is not the same risk as giving an agent access to production, payroll, or customer records.”
—Donald McFarlane
.Pay closer attention to tools that touch sensitive data, source code, production systems, or critical business processes, he said. Govern the information and the action an AI tool can take rather than just inventorying it by name. Organizations also need rules for AI memory such as what can be remembered, what must remain compartmentalized, who owns that context, and what happens to it when that person changes roles or leaves, he said.
AI agents that have been approved must adhere to rules on least privilege, strong authentication, narrowly scoped and time-limited permissions, logging, and human approval for consequential actions. Pay particular attention to combinations of data access, outbound connectivity, and the ability to trigger workflows.
“The goal is to make shadow AI visible, assign ownership, narrow risky access, and give security teams a way to revoke access when risk changes."
—Gal Nakash
Suzu Labs’ Krell summarized shadow AI’s dangers with this example: A single employee with an AI account on a personal phone can exfiltrate company data without touching a single system the organization monitors.


The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.
Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.
While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.


