Shadow AI is staff using AI tools nobody approved, and the fix is supply rather than prohibition: an approved tool good enough to use, a short route to approving another, and a clear line on what never goes in. A ban stops the reporting, not the use. Most of it can be found in an afternoon, starting with finance.
Shadow AI is what happens when the tools arrive faster than the rules. Someone has a deadline, the approved assistant is slower or has not been bought yet, and there is a free one open in the next browser tab. No malice, no policy breach in their own mind, and usually no record that it happened at all. It is not a sophisticated attack technique and nobody has to be careless for it to occur. What makes it a security problem (opens in a new tab) rather than a procurement one is where the information goes.
What Is Shadow AI and Why Does It Keep Happening?
Shadow AI is any use of an AI tool the organisation has not approved. That covers a personal account, an expensed subscription, a browser extension, or an AI feature switched on by default inside software already licensed for something else. It is the AI-specific case of shadow IT, and it is growing faster.
You will recognise the symptoms before you recognise the term. “Someone pasted the client list into a chatbot.” “The meeting notes came from a transcription tool nobody has heard of.” “Finance flagged three subscriptions to the same assistant on three different cards.” “The CRM started summarising calls last month and nobody switched it on.”
The figures come from IBM's Cost of a Data Breach Report 2026 (opens in a new tab), which covers the year to February 2026.
| Measure | 2025 report | 2026 report |
|---|---|---|
| Security incidents involving shadow AI | 20% | 43% |
| Average cost of a breach involving shadow AI | USD 4.63m | USD 5.39m |
| Organisations that had an incident involving an AI model or application | 13% | 21% |
| Breached organisations with no AI governance able to manage AI or detect shadow AI | n/a | 68% |
| Organisations using access controls on AI models and data | n/a | 40% |
Of the organisations that had a shadow AI incident, 49% reported data loss or compromise, 42% operational disruption, 35% reputational damage, and 21% paid a regulatory fine. The UK picture from the government's Cyber Security Breaches Survey 2025/2026 (opens in a new tab), published in April 2026, points the same way: around a third of businesses (31%) were using AI, adopting it or considering it, and about a quarter of those (24%) had any cyber security practices or processes for managing the risks that come with it.
That 68% is the actual finding. Most organisations are not failing to enforce their AI rules. They have no mechanism that would tell them the rules were being ignored.
It keeps happening because the workaround is shorter than the sanctioned route, and the sanctioned route is frequently missing altogether. Leave it and the first you hear of any of this is from a client, a regulator or a forensic report.
Before You Start Looking for Shadow AI
Discovery needs five things, and the fifth is the one people skip.
- An export from finance. Expense claims and company card statements for the last twelve months.
- Admin access to your identity provider. Microsoft Entra, Google Workspace, Okta, whichever holds the work accounts.
- The software licence list, with renewal dates, from whoever owns procurement.
- Access to browser management and DNS or proxy logs. IT will have these, or will have a reason they do not.
- A decision, made in advance, that nobody is disciplined for what turns up. Say so before you ask a single question. If the first discovery becomes a disciplinary, it will also be the last.
You will also want the AI policy (opens in a new tab) question settled in parallel, because the list you are about to build is the input to it. If there is no policy yet, check out our post on how to write one (opens in a new tab).
Solution 1: Read the Expense Claims and Card Statements
Start with finance, because individual AI subscriptions are cheap enough to go through as an expense without a second thought.
This is the least glamorous piece of detective work available to anyone. It will cost you an afternoon with a spreadsheet, which is roughly the last thing a security team wants to hear, and it is also the fastest route to a real list. Filter on the vendor names you know, then sort the remainder by anything under about £30 a month that recurs.
What it fixes: the paid tools.
What it misses: the free ones, and anything on a personal card.
Solution 2: Audit the OAuth Grants in Your Identity Provider
Read the list of third-party applications your staff have consented to with their work accounts. Every “sign in with Microsoft” or “sign in with Google” click leaves a record, along with what the application was granted access to.
Mail. Files. Calendar. Contacts. Go and read that list. In Entra it is under Enterprise applications; in Google Workspace it is under Security, API controls, App access control ⚠ menu paths as of September 2026, verify against the live console. Most organisations have never looked at it once.
What it fixes: the free tools people signed into with a work account, and the scope of what each one can reach.
What it misses: anything signed up with a personal email.
Solution 3: Check the AI Features Switched On in Software You Already Own
Ask each software owner what AI features have been enabled since the last renewal. A significant share of shadow AI is not shadow at all in procurement terms.
It is an AI feature switched on by default in a product licensed two years ago for something else, with data flowing somewhere the original contract review never contemplated. Meeting transcription in the video platform, call summaries in the CRM, drafting assistants in the office suite.
What it fixes: the tools you are already paying for and did not know were AI tools.
What it misses: nothing outside your own estate, but this one is usually the largest single category by data volume.
Solution 4: Review Browser Extensions
Pull the list of installed extensions from browser management. Extensions carry the same problem as Solution 3 with less oversight and frequently broader page access than anyone realises.
An extension that “summarises any page” is reading any page, including the ones with client data on them. If you have no browser management, this is the moment to get some.
What it fixes: the tools that never appear in finance or the identity provider.
What it misses: personal devices.
Solution 5: Query DNS and Outbound Traffic Logs
Search DNS and proxy logs for the domains of the AI services you know about, then for the ones you do not. This is the technical route, and it finds the tools nobody expensed and nobody signed into with a work account.
Start with a list of the twenty most common AI service domains and widen from there. Frequency matters more than presence: one lookup is curiosity, daily lookups from the same host are a workflow.
What it fixes: the free, unauthenticated tools on company devices.
What it misses: anything on personal devices and personal networks, which is not discoverable by any means you would want to deploy.
Solution 6: Ask People What They Use and What It Saves Them
Ask. Genuinely. Not as an investigation with a deadline and an audit trail, because that produces silence and nothing else.
Ask what people are using and what it saves them. The second answer is the useful one, because it tells you which approved tool is failing and why the workaround exists. That is intelligence you cannot get from a log.
What it fixes: the reason the shadow AI exists, which is the only thing that stops it recurring.
What it misses: anyone who has already learned that honesty gets punished, which is why the decision in the checklist above comes first.
Why Banning Shadow AI Makes It Worse
Walk across any university campus and you will find the paving where it made architectural sense. You will also find a worn brown line across the grass where it made walking sense. The grass loses. It loses every time, and it loses regardless of how many signs get put up, because the sign is arguing with the geometry.
A blanket AI ban is a sign on the grass.
The evidence is in the table above. Shadow AI use more than doubled in a year across a population that overwhelmingly did have opinions about AI and largely did not want staff pasting client data into public assistants. Prohibition did not fail because it was insufficiently strict. It failed because the route it was blocking was the shorter one.
There is a second, worse effect. A ban does not stop the usage; it stops the reporting. People carry on and stop telling you, which removes the only cheap source of intelligence you had about your own estate. You end up with the same exposure and less visibility than before you started, which is a genuinely impressive way to make a problem harder.
The mistakes, in the order people make them:
- Starting with the logs instead of finance. The logs are the fifth source, not the first. Finance takes an afternoon and produces a list.
- Running discovery as an investigation. Deadline, audit trail, HR copied in. You will find the paid subscriptions and nothing else.
- Approving a tool nobody wanted. If the sanctioned assistant is slower than the free one, the free one wins. Supply has to be at least as good.
- Building an approved list with no route onto it. The list is complete on the day it is published and never again.
- Treating every instance as equivalent. This is the one most people get wrong, and a policy that does it will be ignored on its first day. A transcription tool taking notes in an internal planning meeting is a different proposition from a public assistant being handed a client's contract terms, and both are different again from AI-drafted text going out over your name to a regulator. Two questions separate the cases: what information touches the tool, and where the output ends up.
So triage. The tools handling nothing sensitive and producing nothing that leaves the building can be approved quickly and reviewed later. The ones touching client data, personal data or anything under an NDA need looking at properly before anyone else starts using them. The ones already producing client-facing output need looking at this week. Most estates sort into those three piles in about an hour, and that sorting is what turns a list into a decision. A decision is the only thing on this page that reduces any risk.
What the 2026 Breach Data Says About Shadow AI in Practice
Read together, IBM's figures describe an organisation that has bought AI, has opinions about AI, and cannot see AI.
The incident share more than doubled (20% to 43%) whilst the proportion of organisations with access controls on AI models and data sat at 40%. That is not a population ignoring the problem. It is a population that has answered the policy question and not the visibility one. The 68% figure makes the same point from the other side: two thirds of breached organisations had no governance capable of even detecting shadow AI, which means the first evidence of it was the breach.
The cost line is the commercial argument, and it is less dramatic than the fear vocabulary suggests. The average cost of a breach involving shadow AI rose from USD 4.63m to USD 5.39m in a year, about 16%. The rise is real, but the base is the point: a breach was going to be expensive anyway. What shadow AI adds is a category of exposure you did not price and could not see, and the breakdown shows where it lands – data loss or compromise for 49% of affected organisations, operational disruption for 42%, a regulatory fine for 21%.
The 24% UK figure is the one to sit with. Three quarters of the UK businesses that have adopted or are considering AI have no cyber security practices for it at all. Discovery is the first of those practices, and it costs an afternoon.
Shadow AI FAQs
Is Shadow AI the Same as Shadow IT?
No. Shadow IT is any unsanctioned technology; shadow AI is the AI-specific case. The distinction matters because AI tools ingest and retain the data put into them, so the exposure is the information, not just the software.
Is All Shadow AI a Security Risk?
No. A transcription tool in an internal planning meeting is not the same as a public assistant holding a client's contract. Triage on two questions: what information touches the tool, and where the output ends up.
Will We Find All of It?
No. Some of it is on personal devices and personal accounts and is not discoverable by any means you would want to deploy. A partial list is enough to make the three decisions that matter: which tool to approve, what never goes in, and what happens when someone gets it wrong.
What Do We Do With the List Once We Have It?
Sort it into three piles: approve quickly, assess before wider use, and look at this week. Then write the rules into an AI policy and put each tool that stays through an AI risk assessment.
Does Shadow AI Count as a Data Breach?
It can. Personal data entered into a tool without a lawful basis or an assessed processor is a data protection matter under the ICO's guidance on AI and data protection (opens in a new tab). Route it into your existing incident process and let that process decide.
Shadow AI Is a Supply Problem, Not a Discipline Problem
Once you know what is in use, the question stops being “is this allowed” and becomes “what does this expose”. Which supplier holds the data, whether it trains a model, and what the contract you never read says about either. The NCSC's guidance on AI and cyber security (opens in a new tab), published in February 2024, argues for security built in from inception rather than bolted on by end users, and a tool assessed before adoption is a smaller problem than a tool discovered after an incident. That assessment is AI risk assessment (opens in a new tab); the wider question of who decides any of this is AI/LLM security (opens in a new tab).
Shadow AI is usually described as a discipline problem. It is almost always a supply problem. Give people something good enough to use and a short way to ask for something better, and most of it stops being shadow.
If you would like someone to run that discovery with you, or to look at what the tools you have already approved are doing with your data, think about getting in touch with us (opens in a new tab). It is considerably less work than the afternoon with the spreadsheet.
