Shadow AI: why it happens and why bans backfire

Cover image for Shadow AI: why it happens and why bans backfire

In late April 2023, three Samsung engineers pasted proprietary source code and an internal meeting recording into ChatGPT in under a month. By early May, Samsung had banned generative AI on company devices. The ban made headlines. It did not solve the problem.

Block ChatGPT, and the next request routes to Claude, Perplexity, or an AI feature quietly shipped inside a platform reviewed two years ago. Demand doesn't disappear; it just becomes invisible. That invisibility is shadow AI, sometimes called shady AI, and Gartner found 69% of organizations already suspect or know it is happening inside their walls.

This article explains why employees adopt shadow AI, why bans push it underground, and how governance frameworks such as NIST, ISO/IEC 42001, and the EU AI Act guide business, IT, and security leaders toward a governed path that works.

What is shadow AI, and why is it already inside your organization?

Shadow AI, closely related to shady AI, is the use of AI platforms, applications, and services by employees without the knowledge, approval, or oversight of business, IT, or security stakeholders. By definition, these applications sit outside policy.

Gartner's earlier research suggests most enterprises already have policies prohibiting the use of generative AI somewhere in the organization. The firm also expects a significant share of enterprises to experience security, compliance, or operational incidents tied to shadow AI by the end of the decade.

Shadow AI is the successor to shadow IT, but the risk runs in the opposite direction. A rogue SaaS subscription poses risk by connecting unvetted software to the network; shadow AI poses risk by sending sensitive data out via prompts and pastes that look like normal work, exposing the business to legal, financial, and reputational fallout. But the category keeps widening:

  • code assistants used by teams across the business

  • browser extensions across business functions 

  • locally run models

  • AI features inside already-approved platforms like Grammarly, Salesforce, and enterprise service platforms used by every department

An application your team reviewed two years ago can become a generative AI system overnight without triggering a new review. People can also route around their own company's rules. Employees at every level, from finance analysts to engineers to executives, adopt shadow AI when internal processes fail to provide a practical sanctioned path.

Why employees adopt shadow AI

Shadow AI reflects a supply gap, not a compliance problem. Employees use unsanctioned AI applications when approved options are unavailable or cannot meet their needs. Industry surveys consistently find that most employees consider it acceptable to use an unapproved application when no approved alternative exists.

Fear keeps the behavior underground once it starts. A 2025 KPMG study of 48,340 people across 47 countries found 57% of employees hide their AI use at work and present AI-generated output as their own. Employees who fear being seen as lazy or less capable don't file tickets asking for a sanctioned version of the application they're hiding.

The third driver is the gap between encouragement and provision. Business leaders tell teams to use AI to stay competitive while the governed path either doesn't exist or takes weeks of review to reach. The standard response, a ban, can drive the activity out of view and leave the demand unresolved.

Why banning shadow AI backfires

Blanket bans can leave demand unresolved while reducing the organization's ability to govern AI use. Employees can continue using AI through personal accounts and devices, and when organizations block ChatGPT specifically, usage can shift to Claude, Perplexity, Otter.ai, and other applications that business, IT, and security teams may find harder to track. Blocking one domain relocates shady AI.

Unmanaged personal accounts prevent organizations from applying corporate governance controls to work-related prompts and responses. Industry research indicates that roughly a fifth of pasted data contains personally identifiable information or payment card data. Those exposure patterns make access and oversight controls essential when employees use generative AI for work, whether the concern is customer trust, regulatory exposure, or intellectual property loss.

Several large financial institutions that initially restricted ChatGPT later introduced approved internal alternatives to address continuing employee demand. Goldman Sachs, for instance, launched its own AI assistant to 10,000 employees roughly two years after its early restriction, and other major banks followed a similar arc from ban to sanctioned tool.

The pattern is consistent: early restrictions bought time, but demand didn't go away, and organizations eventually met it with governed alternatives. Approved AI tools give employees a safer, more productive way to meet that demand than driving it onto personal devices.

What enterprise-grade shadow AI governance actually requires

The three major frameworks disagree on legal force and agree almost entirely on substance. The NIST AI framework is voluntary, ISO/IEC 42001 certification is voluntary but certifiable, and the EU AI Act obligations bind providers and deployers. 

These frameworks point to five controls a shadow AI program must provide evidence for, and each affects business owners, IT operators, and security reviewers alike.

  • An AI inventory: NIST's GOVERN 1.6 subcategory requires mechanisms to inventory AI systems and resource them according to organizational risk priorities.

  • Acceptable use policies: NIST's generative AI profile lists acceptable use policies as a required inventory field, and ISO/IEC 42001 requires an organizational AI policy as a central element of its management system.

  • Audit trails: NIST's AI RMF Playbook provides voluntary guidance for organizations to define and document governance-related monitoring and oversight processes that can produce governance evidence.

  • Human oversight: NIST oversight requirements call for organizations to define, assess, and document oversight processes in accordance with organizational policies.

  • AI literacy: The European Commission's AI literacy guidance explains the measures providers and deployers must take to ensure sufficient staff AI literacy under Article 4.

In Tines' 2026 Voice of Security report, 66% of teams with formalized AI policies reported being very optimistic about AI's impact. Governance can further increase confidence and set boundaries for adoption across the business.

These five governance controls require infrastructure that captures usage in real time. Spreadsheets, policy PDFs, stale inventories, and inaccessible logs do not provide sufficient audit evidence. Designing AI workflows with governance built in produces that evidence at the point of use. Organizations must then connect it to the systems that detect, approve, and execute AI use.

From shadow AI detection to governed workflows

Detection identifies shadow AI use. Organizations are moving toward governed paths to give employees an approved way to work. Cloud access security brokers (CASBs) flag AI SaaS traffic, while endpoint data loss prevention (DLP) watches for sensitive pastes. AI security posture management (AI-SPM) tools inventory AI assets across environments.

As AI execution scales inside enterprises, centralized controls become more urgent for business, IT, and security stakeholders alike. Industry research consistently finds that AI adoption outpaces the orchestration needed to govern it, leaving teams managing fragmented tools and disconnected logs.

AI gateways broker access to models and enforce policies at the point of use. AI-SPM tools inventory AI assets and surface posture risks, while AI governance platforms manage policies, assessments, and regulatory evidence. Each covers a necessary slice of the problem.

Turning a blocked request into an approved, usable workflow requires an execution layer that connects detection, approval, provisioning, and logging. Point-tool fragmentation is the practical failure mode: a dozen tools, each with its own logs and administrative processes. Organizations must choose whether controls remain isolated or work together as the request moves from discovery to approval.

When slow builds and thin change control make the governed path uncompetitive, teams need a surface where sanctioned work can run under consistent logging, permissions, and audit controls. Build speed matters because the approved route must compete with the workaround. The intake queue is the first test.

How to prevent shadow AI among employees

Prevention starts with recognizing that shadow AI is a supply problem, not a discipline problem. Organizations that reduce unsanctioned use tend to combine four practices rather than relying on any single control:

  • Provide a sanctioned alternative before restricting anything. Ideally, approved tools should exist and be usable before a block lands, though this isn't always feasible when risk is already being introduced and immediate action is needed. Where possible, giving employees a governed option that meets their needs makes it more likely they'll choose it over a personal account.

  • Shorten the intake path. Multi-week review cycles push employees toward workarounds. A fast-track approval process for common AI use cases keeps demand within the governed path rather than driving it onto personal devices.

  • Invest in AI literacy, not just AI policy. EU AI Act Article 4 requires deployers to ensure sufficient staff AI literacy and training that explains which data is safe to share, which tools are approved, and how to request new ones, removing the guesswork that fuels shadow use.

  • Replace punishment with coaching. Warnings at the point of use, rather than blanket blocks, help employees learn without hiding their AI activity. The KPMG finding that 57% of employees conceal their AI use points to a culture problem controls alone can't fix.

In practice, prevention is about making the sanctioned path faster, safer, and more useful than the workaround, so employees have no reason to route around it.

Making the sanctioned path the fast path

Every unsanctioned ChatGPT tab signals that the approved path is missing or too hard to use. Enterprises that recognize this signal tend to reach the same conclusion: the fix is a governed internal alternative that meets employee demand while keeping AI use visible to the business.

A governed, AI-native environment turns the AI activity teams uncover into workflows they control. Logging, permissions, approvals, and inventory records are captured automatically as each workflow runs, producing the evidence NIST, ISO/IEC 42001, and the EU AI Act require from deployers, without a separate compliance project to piece it together after the fact.

That's what makes the approved route worth choosing over the workaround. See how it works

Frequently asked questions

What's the difference between shadow AI and shadow IT?

Shadow IT is any unauthorized software, hardware, or service deployed without approval; shadow AI is the AI-specific subset. The two diverge most in practice in discoverability: an unapproved SaaS app is something you can find, whereas AI features arrive within platforms that have already been reviewed and cleared, without prompting a new review when the vendor ships them. Shadow AI introduces risks that shadow IT never had, including the reliability of model outputs, algorithmic bias in the business decisions those outputs influence, and agents that can take multi-step actions on their own.

Shadow AI can create real legal exposure, though its use is not inherently illegal. Italy's data protection authority imposed a €15 million fine on OpenAI under the General Data Protection Regulation (GDPR) for violations by the service itself, showing that generative AI services can face GDPR enforcement. Employees who send personal data to unapproved services can pose separate data protection risks to their employer. Under the EU AI Act, providers and deployers must take measures to ensure sufficient AI literacy among their staff and others who use AI systems on their behalf.

How do teams detect shadow AI across their environment?

Detection depends on several signals working together across business, IT, and security functions: network and firewall logs for traffic to AI endpoints, CASB data for unsanctioned AI SaaS, endpoint DLP for sensitive data pasted into prompts, and periodic audits of approved applications for AI features added after the original review. These signals reveal both dedicated AI services and AI capabilities that vendors add to approved applications. AI-SPM platforms extend this by inventorying AI models, agents, and APIs across cloud and on-premises environments.

When does blocking AI applications work, and when does it backfire?

Targeted AI blocking has a place, for instance, public tools that fail data-handling review, but blanket bans push usage onto personal devices and obscure alternatives. The sustainable pattern uses discovery to classify applications by approval and review status. Coaching controls warn before they block, and a governed alternative must be good enough that employees choose it on their own.

Sign up today to get started or schedule time with our team to learn more.