Cybersecurity glossary

What is Shadow AI?

Learn what shadow AI is, how employees paste company data into unmanaged chatbots and agents, why it bypasses DLP and vendor review, and how to discover, approve, and replace unsanctioned AI tools.

AI and LLM securityUpdated August 13, 2026
Also known asUnsanctioned AIShadow generative AIAI shadow IT

Definition

Shadow AI is the unsanctioned use of AI systems—public chatbots, browser extensions, coding agents, or personal MCP servers—for work data and workflows, outside IT’s approved models, logging, and contractual controls.

Why shadow AI matters

Employees will use the model that unblocks them today. Shadow AI is that behavior without a contract, a data-processing addendum, tenant isolation, or logging you can subpoena.

A paste of a customer export into a consumer chatbot is a disclosure incident that never hits your SIEM. A personal coding agent with a filesystem MCP server is an unreviewed integration running on a developer laptop. Both are now normal.

How unsanctioned AI shows up

1

A work task is painful

Writing, summarizing, or coding is slow in the approved toolchain.

2

A public tool is one click away

Consumer chat, a free extension, or a viral MCP server promises speed.

3

Work data is pasted or screen-read

Source, tickets, PDFs, or the live admin page leave the tenant.

4

Vendor terms apply

Retention, training-use, support access, and sub-processors are whoever’s default.

5

No enterprise control plane

You cannot revoke, redact, or audit that conversation.

6

The pattern spreads

Teams share prompts and plugins. Shadow AI becomes how the work actually gets done.

Common shadow AI channels

Consumer chatbots

Paste-in of code, legal, and customer content into personal accounts.

Browser sidebars

Extensions that summarize the current tab, including privileged consoles.

IDE agents

Unofficial coding assistants with repo and secret-file access.

Personal MCP

Laptop servers wired to SaaS tokens the company never issued for AI.

Block versus replace

ApproachWhat usually happensBetter move
Block onlyPeople use phones, home Wi-Fi, or screenshotsBlock plus a sanctioned assistant that is actually good
IgnoreSilent disclosure and unvetted agentsDiscover, amnesty, and migrate
Approve everythingSupply chain and DLP collapseA short allowlist with DPAs and logging
Train onceForgotten in a weekContinuous discovery and manager-level metrics
  • Offer an approved LLM path with SSO, no-training contracts, and clear data classes.
  • Discover AI domains, extensions, and MCP installs; do not rely on a policy PDF.
  • Classify what may never leave: secrets, regulated PII, unpublished vulns, customer exports.
  • Put DLP on paste and file-upload to known AI endpoints where legally and technically feasible.
  • Inventory browser extensions that read page content.
  • Give engineering an official coding assistant so unofficial ones are less tempting.
  • Run an amnesty: report unofficial tools without punishment, then migrate or ban.
  • Measure usage of the sanctioned tool; empty dashboards mean shadow AI is winning.

The practical takeaway

Shadow AI is unsanctioned models and agents handling real work data. It bypasses the vendor review you did for everything else.

You will not lecture it out of existence. Provide a capable approved assistant, discover the rest, and treat consumer chatbots as data egress—not as a harmless novelty.

Related security terms

Frequently asked questions

What is shadow AI in simple terms?

Staff use ChatGPT, a random coding agent, or a browser sidebar for work because it is faster than the approved tool—and they paste source code, contracts, or customer lists into it.

Is this just shadow IT with a new name?

It is shadow IT focused on models. The new twist is that the ‘app’ is a probabilistic system that may train on, log, or leak what you paste, and that agents can act, not only store files.

Why do people do it?

Approved tools are slow, blocked, or worse at the task. Security that only says ‘no’ without a good alternative guarantees shadow AI.

What is the harm?

Confidential data leaves the tenant, prompts become someone else’s training or support corpus, and unvetted agents run with SSO cookies on laptops.

How do you discover it?

DNS and proxy logs for AI domains, CASB/DLP, browser extension inventories, SaaS discovery, and honest surveys beat a single block page.

Should you block all public LLMs?

Blocking without an approved path drives people to phones and home networks. Combine discovery, policy, and a sanctioned assistant that actually works.

Are browser AI sidebars in scope?

Yes. They often see the full page, including admin consoles, and send it to a vendor you never reviewed.

References

Explore authoritative guidance and frameworks related to shadow ai.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary