AI tools are now part of everyday work, helping people summarize meeting notes, draft emails, debug code, analyze spreadsheets, and turn documents into presentations. Used without approval or oversight, however, they can raise serious AI privacy concerns, expose sensitive business information, and leave IT teams unable to see where company data is going.
This guide covers what shadow AI is, how it spreads inside organizations, and the serious risks it creates. We’ll show how to spot unapproved tools and implement practical safeguards to protect your business data — without slowing your team down.
- What is shadow AI?
- Shadow AI vs. shadow IT
- How does shadow AI happen?
- Does AI automatically train on your data?
- Examples of shadow AI
- What are the shadow AI risks?
- How to detect shadow AI
- How to reduce shadow AI risks
- What to do if sensitive data has already been shared
- A private AI assistant for teams
What is shadow AI?
Shadow AI is any use of artificial intelligence for work that falls outside a business’s approved systems and policies. It can involve an unapproved tool, a personal account used for company work, or an approved AI service used with data or for tasks the organization has not authorized.
Shadow AI often starts with everyday workplace pressures: a tight deadline, the need to find a faster or better way to work, or a tool that is not quite getting the job done. Sometimes, an approved AI tool is available, but people turn elsewhere because they are more familiar with another option.
Shadow AI vs. shadow IT
Shadow IT is the broader term for any software or hardware used without an organization’s approval or oversight. Common examples include personal cloud storage used for work, unauthorized messaging apps, and unapproved project management platforms.
Shadow AI is a specific form of shadow IT involving AI systems and AI-powered features. AI introduces an additional data governance challenge because company information may be submitted to an external system or processed in unfamiliar ways outside the organization’s control.
How does shadow AI happen?

Employees can enter large amounts of company information into an AI chat window within seconds. Depending on the AI’s settings, the tool may retain the input, share it with other parties (such as data brokers or analytics vendors, like in the OpenAI breach case), or use it for targeted ads or model development.
Shadow AI usually spreads because of a few common organizational gaps.
No approved alternative
Employees are more likely to use shadow AI tools when the business has not provided an approved option A BlackFog survey(nueva ventana) of 2,000 workers found 49% of employees adopt AI tools without employer approval, 63% think it’s acceptable to use AI when there’s no corporate-approved option, and 51% have connected AI tools to work systems without IT’s knowledge.
Unclear policies
Employees may be unsure which tools, tasks, and types of information are permitted. Company guidance may clearly restrict highly sensitive data while saying little about internal meeting notes, draft emails, spreadsheets, source code, or customer conversations.
IT Brew’s survey(nueva ventana) run on 241 IT professionals found that 35% have little to no confidence employees know their company’s AI usage and data security policies, and only 12% felt “very confident.” A separate WorkNest survey(nueva ventana) of 505 HR professionals/employers found 54% of organizations have no AI policy at all, 24% are still developing one, and only 13% have clear, documented rules.
Slow approval processes
Pressure to meet deadlines can make a lengthy security or procurement review feel impractical. When employees can access a free tool immediately, slow internal processes make unofficial workarounds more likely.
New AI features in approved software
A vendor may add generative AI features to an application that has already passed a security review, and the software stays on the approved list even though nobody has assessed how the new feature processes, stores, or shares company data. The employee hasn’t broken any policy, but the result is the same as the other causes: Company data is now moving through a channel nobody has actually vetted.
Limited awareness of data handling
Employees may not know how AI providers like ChatGPT and Gemini retain prompts, process uploaded files, use conversations for service improvement, or share data with other providers. They may assume their inputs disappear when they close the browser tab, even when copies remain in account histories, logs, backups, or connected systems.
Kolide’s report(nueva ventana) found that while 89% of employees use AI monthly, only 56% of companies have explained AI’s security risks to staff.
Examples of shadow AI
| Team | Example of shadow AI | Information potentially exposed | Potential impact |
|---|---|---|---|
| Software development | Pasting internal code into a public chatbot for debugging | Source code, credentials, system architecture, and unreleased features | Proprietary code or secrets may be retained outside company systems |
| Product | Uploading a roadmap for summarization | Launch dates, product strategy, pricing, and partner information | Confidential business plans may sit unmanaged on third-party servers |
| Marketing and design | Entering campaign plans into an AI writing or design tool | Unreleased products, customer research, brand assets, and audience data | Sensitive campaign information may be processed without legal or security review |
| Data analysis | Uploading customer datasets to an external analysis tool | Personal data, commercially sensitive records, and confidential insights | Protected or regulated information may be disclosed to unapproved third parties |
| Human resources | Using an AI tool to assess applications or summarize interviews | Candidate data, employment information, and assessment criteria | Personnel data exposure may breach GDPR or CCPA |
| Sales | Uploading call transcripts or account notes for analysis | Customer identities, contract details, pricing, and sales strategy | Customer data exposure may breach GDPR or CCPA |
| Customer support | Pasting support tickets into a public chatbot | Customer names, account details, complaints, and correspondence | Retained support records may violate GDPR or CCPA |
| Finance | Asking an AI assistant to analyze internal spreadsheets | Budgets, forecasts, payroll information, and transaction records | Financial data may be processed without appropriate safeguards |
| Legal | Uploading contracts or case files for summarization | Privileged advice, contractual terms, and client information | Client data misuse may breach GDPR or CCPA and affect privilege |
| Leadership | Using an AI service to review board documents or strategic plans | Acquisition plans, internal targets, and executive discussions | Highly sensitive corporate intelligence may become exposed |
Does AI automatically train on your data?
Large language models (LLMs) do not automatically retrain themselves on every prompt in real time, so a conversation won’t inevitably become part of the AI model or appear in another user’s response. However, the level of risk depends on the provider, account type, privacy settings, contract, and how the service has been configured.
An AI provider may retain prompts and uploaded files, make them available for human review, use them to improve its services, or share them with infrastructure and model providers.
Even when model training is disabled, information may appear in account histories, operational logs, abuse-monitoring systems, backups, browser records, connected services, or third-party integrations. If your content has already contributed to model training, turning off this option won’t make the model forget your past conversations.
What are the shadow AI risks?

AI can influence decisions, generate customer-facing material, write code, or analyze personal data, all of which create risks extending beyond the security of the tool itself:
Data breach
IBM’s 2025 Cost of a Data Breach Report(nueva ventana) found that one in five organizations had experienced a breach linked to shadow AI, yet only 37% had policies designed to manage or detect it.
Organizations with high levels of shadow AI faced breach costs averaging $670,000 more than those with little or no shadow AI. Further, incidents involving shadow AI exposed personal information and intellectual property more frequently than the global average.
Exposure of confidential information
Employees may share internal documents, source code, financial information, contracts, customer records, product plans, or trade secrets without realizing the AI provider retains their inputs. Even when information is excluded from model training, it can remain exposed to account compromise, security breaches, provider access, insecure integrations, or legal demands.
For example, Samsung banned ChatGPT(nueva ventana) company-wide in May 2023 after employees pasted confidential material into it three times in 20 days, including semiconductor source code, defect-detection algorithms, and a transcribed internal meeting.
Loss of intellectual property
Proprietary knowledge is often a company’s most valuable asset. Uploading code, research, product designs, processes, or strategy documents to an external AI service may conflict with confidentiality agreements or weaken the business’s ability to control that information. An employee may also use AI-generated content without understanding its origins, licensing restrictions, or similarity to third-party material.
Privacy and regulatory violations
Personal data remains subject to data privacy law when it is processed through an AI tool. Shadow AI can bypass privacy safeguards because the relevant legal teams never know that the processing is taking place. The UK Information Commissioner’s Office warns that AI systems can amplify existing security risks(nueva ventana). Serious GDPR infringements can lead to penalties of up to €20 million or 4% of the organization’s worldwide annual turnover from the previous financial year, whichever is higher.
Insecure integrations and excessive access
AI tools may connect to email, cloud storage, calendars, code repositories, customer databases, and collaboration platforms. Broad permissions, poorly secured APIs, leaked access tokens, malicious browser extensions, and compromised third-party services can expose company systems and data beyond the information entered in a single prompt.
In the Salesloft Drift breach, attackers stole OAuth tokens from Drift, an AI sales-assistant integration, and used them to pull data out of Salesforce instances at more than 700 organizations, including business contacts, API keys, and cloud credentials embedded in support cases.
Prompt injection attacks
This vulnerability exists in any connected AI system, approved or not — attackers can manipulate an AI system through instructions hidden in documents, webpages, emails, or other content it processes, causing it to reveal information, ignore its original instructions, or take unintended actions.
Shadow AI raises the stakes because an unapproved tool or AI agent may never have been assessed for prompt injection or limited to the permissions it needs. If an attack succeeds, security teams may have little visibility into what happened or how to contain it. The consequences are especially serious when the AI agent can access sensitive data or take actions without human review.
Lack of accountability
Shadow AI activity often leaves no central audit trail. Security teams may be unable to determine which information was submitted, which model processed it, what output it produced, or how the result influenced a decision. Investigating an error, complaint, data breach, or regulatory question becomes much harder without those records.
Unexpected costs and supplier dependence
Separate subscriptions and API accounts can create duplicated spending across departments. Experimental tools may also become embedded in important workflows before procurement teams have assessed their pricing, reliability, or long-term availability. A free service can become business-critical without a service agreement, continuity plan, or practical way to move the workflow elsewhere.
How to detect shadow AI
Shadow AI can be difficult to detect because employees may use personal accounts, browser extensions, embedded AI features, AI browsers, or tools that blend into normal web traffic. Organizations therefore need visibility into which services are being used and how company data moves through them.
Monitoring should remain proportionate and respect employee privacy. The goal should be to identify risky tools and data flows without routinely inspecting the contents of every prompt or conversation.

Here are some tips for identifying shadow AI within your organization:
Create an inventory of AI use
Ask teams which AI tools they currently use, what tasks they use them for, and what prevents them from using approved alternatives. A short survey, interviews with department leads, and a voluntary disclosure period can reveal uses that technical controls miss. Employees are more likely to be honest when the goal is to understand their needs rather than punish early experimentation.
Review network and application activity
Security teams can use network logs, software inventories, and cloud access security tools to identify connections to known AI services. Monitoring can show which services are being accessed and how much data is transferred without capturing the content of every conversation.
Audit browser extensions and plug-ins
Browser extensions can add AI writing, summarization, translation, meeting, and coding features to almost any workflow. Review which extensions are installed, what permissions they request, and whether they can read webpage content, email, documents, or login information.
Check expenses and procurement records
Employee expense claims, corporate card statements, and procurement records may reveal paid AI subscriptions that have never completed a security review. Repeated payments from different teams can also uncover duplicated tools and unofficial accounts.
Search for unmanaged API keys and integrations
Review code repositories, secrets managers, cloud environments, billing dashboards, and automation platforms for connections to external AI providers. Unmanaged API keys or unfamiliar usage charges may indicate a prototype, integration, or internal tool that has not been formally approved.
Use data loss prevention controls
Data loss prevention tools can identify attempts to upload sensitive categories of information such as personal records, credentials, financial data, and source code. Controls should be proportionate and clearly communicated. Employees need to understand what is monitored, why it is necessary, and how to complete legitimate work through approved systems.
Work with employees rather than around them
Technical monitoring alone will not reveal every instance of shadow AI. Employees may use personal accounts, mobile devices, or tools that appear as normal web traffic. Regular discussions with teams can identify where existing workflows create friction and why employees seek external tools.
How to reduce shadow AI risks

Reducing shadow AI requires practical alternatives, clear policies, appropriate access controls, employee training, and ongoing review. Effective safeguards should support legitimate AI use while keeping company data within approved systems:
Give employees an approved AI tool
Employees are less likely to search for alternatives when you provide a business AI assistant that meets their practical needs. Any approved tool should offer strong privacy protections, clear data handling terms, appropriate business controls, and enough capability to support common tasks.
Avoid a blanket ban
A complete ban can push AI use further underground, especially when employees already depend on these tools. Some may move to personal accounts, mobile devices, browser extensions, or less reputable AI services that are harder for the organization to identify.
Create an AI acceptable-use policy
Use examples based on real workflows. “Do not share sensitive information” leaves too much room for interpretation. A clearer policy might tell employees never to upload customer support exports, source code, contracts, credentials, unreleased financial results, or identifiable employee records to an unapproved service.
Classify data before setting AI rules
Identify which categories of information are public, internal, confidential, regulated, or highly restricted. Connect each category to permitted AI uses. Public marketing copy may be appropriate for a wider range of tools, while personal data, credentials, trade secrets, and privileged legal material may require a tightly controlled system or be excluded entirely.
Periodically review approved software for new AI features
An application may process data differently after adding an AI assistant, automatic transcription, content generation, or predictive analysis. Regular vendor reviews can identify these changes and confirm that previously approved tools still meet the organization’s security, privacy, and compliance requirements.
Limit permissions
Give AI tools access only to the data and systems needed for an approved task. Use company-managed accounts, single sign-on (SSO), two-factor authentication (2FA), role-based permissions, and centralized account removal where available. Avoid connecting a business AI assistant to an entire drive, inbox, or customer database when a narrower source will work.
Set rules by role and use case
Different teams have different needs and levels of risk. Developers may need API access for testing or prototyping. Marketing teams may need text and image generation. Legal or HR teams may work with information that requires much stronger restrictions. Role-based rules can keep the policy realistic while limiting access to sensitive data and high-risk functions.
Train employees
Employees need enough AI literacy to understand both the benefits and limitations of the systems they use. Training should cover AI privacy, confidentiality, hallucinations, bias, intellectual property, prompt injection, human review, and incident reporting. The appropriate training level depends on staff knowledge, experience, and the context in which the AI is used.
Create a simple approval process
A working process might collect the tool name, intended task, data involved, required integrations, and expected business benefit. Security and legal teams can then approve, restrict, test, sandbox, or reject it based on the actual risk. A long procurement process may encourage employees to find their own workaround. Set a reasonable review target and explain what information is needed to reach a decision.
Keep people responsible for the output
AI-assisted work should have a human owner. Require a review before outputs affect customers, employees, finances, legal decisions, production code, published information, or other high-impact areas. Any person using an AI tool remains responsible for checking its accuracy, appropriateness, confidentiality, and compliance with company policy.
Document important AI-assisted decisions
Keep a clear record when AI contributes to decisions that affect customers, employees, finances, legal matters, or other high-impact areas. A reliable audit trail supports accountability and helps organizations investigate errors, explain outcomes, and respond to complaints or regulatory questions.
What to do if sensitive data has already been shared
Treat an accidental disclosure to an AI tool like any other potential data incident. Move quickly through the following steps.
Identify what was shared: Confirm what information was entered or uploaded, which tool and account were used, when the disclosure happened, and who may have had access to the data.
Remove the information where possible: Delete the conversation and any uploaded files from the tool. Check the provider’s terms and support options to see whether you can submit a formal deletion request.
Check what the provider may retain: Removing a chat from view doesn’t always erase every copy. Review and document what the provider says about operational logs, backups, human review, model training, and deletion timeframes to help determine whether any data may remain.
Secure affected systems: Revoke permissions granted to the AI tool or connected plug-ins. Rotate any passwords, API keys, access tokens, or other credentials that appeared in the prompt or attached files.
Notify the relevant teams: Report the incident to the organization’s security, privacy, legal, or data protection team. They can assess contractual obligations, regulatory requirements, and whether affected customers or partners need to be informed.
Learn from the incident: Document what happened and use it to improve training, controls, and approved alternatives. Avoid punishing employees who report genuine mistakes, since a punitive response may discourage others from raising future incidents.
A private AI assistant for teams
Lumo for Business gives your team a reliable AI assistant for summarizing documents, analyzing data, reviewing code, drafting content, and exploring ideas while helping your business maintain control of confidential information.
Our business AI assistant does not keep logs of conversations or use them to train AI models, and any chat history you choose to save is protected with zero-access encryption, which means we never have access to your data
Lumo is fully open source, built in Europe, and designed to support GDPR and HIPAA compliance through Proton’s ISO 27001 certification and SOC 2 Type II attestation.
Giving your team a capable, privacy-focused AI assistant reduces reliance on unapproved tools and helps you keep AI use within systems you oversee.






