Cybersecurity glossary
What is Shadow AI?
Learn what shadow AI is, how employees paste company data into unmanaged chatbots and agents, why it bypasses DLP and vendor review, and how to discover, approve, and replace unsanctioned AI tools.
Definition
Shadow AI is the unsanctioned use of AI systems—public chatbots, browser extensions, coding agents, or personal MCP servers—for work data and workflows, outside IT’s approved models, logging, and contractual controls.
Why shadow AI matters
Employees will use the model that unblocks them today. Shadow AI is that behavior without a contract, a data-processing addendum, tenant isolation, or logging you can subpoena.
A paste of a customer export into a consumer chatbot is a disclosure incident that never hits your SIEM. A personal coding agent with a filesystem MCP server is an unreviewed integration running on a developer laptop. Both are now normal.
How unsanctioned AI shows up
A work task is painful
Writing, summarizing, or coding is slow in the approved toolchain.
A public tool is one click away
Consumer chat, a free extension, or a viral MCP server promises speed.
Work data is pasted or screen-read
Source, tickets, PDFs, or the live admin page leave the tenant.
Vendor terms apply
Retention, training-use, support access, and sub-processors are whoever’s default.
No enterprise control plane
You cannot revoke, redact, or audit that conversation.
The pattern spreads
Teams share prompts and plugins. Shadow AI becomes how the work actually gets done.
Common shadow AI channels
Consumer chatbots
Paste-in of code, legal, and customer content into personal accounts.
Browser sidebars
Extensions that summarize the current tab, including privileged consoles.
IDE agents
Unofficial coding assistants with repo and secret-file access.
Personal MCP
Laptop servers wired to SaaS tokens the company never issued for AI.
Block versus replace
| Approach | What usually happens | Better move |
|---|---|---|
| Block only | People use phones, home Wi-Fi, or screenshots | Block plus a sanctioned assistant that is actually good |
| Ignore | Silent disclosure and unvetted agents | Discover, amnesty, and migrate |
| Approve everything | Supply chain and DLP collapse | A short allowlist with DPAs and logging |
| Train once | Forgotten in a week | Continuous discovery and manager-level metrics |
- Offer an approved LLM path with SSO, no-training contracts, and clear data classes.
- Discover AI domains, extensions, and MCP installs; do not rely on a policy PDF.
- Classify what may never leave: secrets, regulated PII, unpublished vulns, customer exports.
- Put DLP on paste and file-upload to known AI endpoints where legally and technically feasible.
- Inventory browser extensions that read page content.
- Give engineering an official coding assistant so unofficial ones are less tempting.
- Run an amnesty: report unofficial tools without punishment, then migrate or ban.
- Measure usage of the sanctioned tool; empty dashboards mean shadow AI is winning.
The practical takeaway
Shadow AI is unsanctioned models and agents handling real work data. It bypasses the vendor review you did for everything else.
You will not lecture it out of existence. Provide a capable approved assistant, discover the rest, and treat consumer chatbots as data egress—not as a harmless novelty.
Related security terms
Sensitive Information Disclosure
The usual outcome when work secrets are pasted into unmanaged models.
AI Supply Chain
Approved and unapproved models and plugins are both supply-chain choices.
Large Language Model (LLM)
The typical consumer tool behind shadow AI usage.
MCP Server
Personal agents often attach unreviewed local servers.
Unbounded Consumption
Personal API keys on company tasks can also create surprise bills.
Frequently asked questions
What is shadow AI in simple terms?
Staff use ChatGPT, a random coding agent, or a browser sidebar for work because it is faster than the approved tool—and they paste source code, contracts, or customer lists into it.
Is this just shadow IT with a new name?
It is shadow IT focused on models. The new twist is that the ‘app’ is a probabilistic system that may train on, log, or leak what you paste, and that agents can act, not only store files.
Why do people do it?
Approved tools are slow, blocked, or worse at the task. Security that only says ‘no’ without a good alternative guarantees shadow AI.
What is the harm?
Confidential data leaves the tenant, prompts become someone else’s training or support corpus, and unvetted agents run with SSO cookies on laptops.
How do you discover it?
DNS and proxy logs for AI domains, CASB/DLP, browser extension inventories, SaaS discovery, and honest surveys beat a single block page.
Should you block all public LLMs?
Blocking without an approved path drives people to phones and home networks. Combine discovery, policy, and a sanctioned assistant that actually works.
Are browser AI sidebars in scope?
Yes. They often see the full page, including admin consoles, and send it to a vendor you never reviewed.
References
Explore authoritative guidance and frameworks related to shadow ai.
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.