Shadow AI is the use of AI tools inside your organisation that security, legal and compliance do not know about. Unlike shadow IT, it rarely involves procurement - a browser tab and a free tier are enough. Which means the usual controls, built around purchasing and provisioning, never trigger.
What actually goes wrong
- Data leaves your boundary. Customer data, source code, contracts and incident details pasted into consumer tools with unknown retention and training terms.
- Privacy obligations breach silently. If personal data is involved, that is processing - requiring a lawful basis, a record, and often a processor agreement you do not have.
- Confidentiality commitments break. Many customer contracts restrict who may process their data. A free-tier tool is a subprocessor you never disclosed.
- Unreviewed output becomes a decision. AI-drafted analysis, code or advice entering workflows with nobody accountable for accuracy.
- Audit exposure. "How do you govern AI use?" is now a routine question in security reviews and increasingly in audits.
Discovering what is in use
Ask, then verify - and expect the two answers to differ:
- Identity provider logs - OAuth grants and SSO sign-ins to AI services.
- Network and DNS telemetry for known AI domains.
- Expense and card records - individual subscriptions rarely go through procurement.
- Browser extension inventories, which are a common and overlooked route.
- AI features inside tools you already own - your existing SaaS vendors have been adding them, often on by default.
- An amnesty survey. Ask people what they use, and make it explicitly consequence-free. You will learn more from this than from any scan.
That last point matters. If disclosure is punished, usage moves to personal devices where you have no visibility at all - which is strictly worse than sanctioned use with guardrails.
Bring AI use into your control framework
GRC Copilot helps you inventory AI systems, map them to ISO 42001 and EU AI Act expectations, and evidence the governance your customers and auditors now ask about.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
A policy people can actually follow
Blanket bans fail - they are ignored, and they push usage out of sight. What works is a classification-driven rule people can apply without asking:
- Public and internal data - approved tools permitted for general work.
- Confidential data - only sanctioned enterprise deployments with contractual terms in place.
- Restricted data - credentials, special category personal data, payment data, security findings - not permitted in any external AI tool.
Then make the sanctioned path genuinely easier than the unsanctioned one. Most shadow AI exists because the approved option was slow, absent, or worse.
Build the AI inventory
Treat AI systems as assets. For each, record the tool, its owner, the data classification it handles, whether it is embedded in another product, the vendor terms on training and retention, and whether output is human-reviewed before use. This inventory is the prerequisite for ISO 42001, for EU AI Act readiness, and for answering the AI questions now appearing in customer questionnaires.
Practical sequence
- Run discovery and an amnesty survey together.
- Publish a short, classification-based acceptable use rule.
- Sanction one good enterprise option quickly - speed matters more than perfect selection.
- Build the AI inventory from what discovery found.
- Add AI to onboarding and awareness training with concrete examples.
- Review vendor AI features on renewal, since they appear without notice.
Frequently asked questions
Should we just block AI tools?
Blocking without providing an alternative moves usage to personal devices. Sanction a viable option, define classification-based limits, and enforce from there.
Is pasting data into a chatbot a breach?
It can be. If it is personal data, it is processing subject to privacy law. If it is customer data under confidentiality terms, it may breach contract. Both depend on the tool's terms - which is why an approved list matters.
Do we need to disclose AI tools as subprocessors?
If they process customer personal data on your behalf, generally yes. Check your contracts - many require notification of new subprocessors.
How does this relate to ISO 42001?
ISO 42001 expects a governed inventory of AI systems with assigned accountability. Shadow AI is the gap between that expectation and reality, so discovery is usually the first step toward certification readiness.
Key takeaways
- Shadow AI bypasses procurement, so provisioning controls never fire.
- Discover through identity, network, expenses and a consequence-free survey.
- Classification-based rules beat blanket bans.
- An AI inventory is the prerequisite for ISO 42001 and customer AI questions.