← All terms

Shadow AI

Shadow AI is employees' use of AI tools without IT approval — chatbots, assistants, note-takers — creating invisible data leakage and compliance risk.

Shadow AI is the use of artificial intelligence tools — chatbots, coding assistants, browser extensions, meeting note-takers — by employees without the knowledge or approval of IT and security teams. It is the AI-era descendant of shadow IT, with one critical difference: an unapproved AI tool's core function is ingesting whatever data the user gives it, which makes every unsanctioned prompt a potential data disclosure.

How it works

Shadow AI rarely looks like rule-breaking from the inside. An employee under deadline pressure pastes a contract into a free chatbot for summarization, a developer drops proprietary code into an assistant to find a bug, or a manager lets an AI note-taker join a confidential call. When the tool runs on a personal account, the organization has no visibility into what left, no contractual protection over how it is stored, and no guarantee it will not be retained for model training. IBM's Cost of a Data Breach 2026 research found shadow AI figured in 43% of breached organizations — more than double the prior year — and those breaches cost more than the global average. The risk also flows in reverse: employees act on unvetted AI output, and assistants processing untrusted content can be manipulated through prompt injection.

How to defend against it

Bans mostly relocate the behavior to personal devices, where visibility drops to zero. Effective programs instead discover actual usage from proxy and SSO logs, publish a short policy naming approved tools and prohibited data classes, and provide a sanctioned enterprise AI alternative good enough that the approved path is the easiest path. Data loss prevention on the prompt path — with real-time coaching when sensitive data is detected — turns violations into teachable moments, and scenario-based training builds the durable rule of thumb: anything pasted into an unapproved AI tool should be treated as published. Tracking shadow AI events per team alongside phishing and credential behavior in a human risk score shows where the risk concentrates, so controls follow the behavior rather than the org chart.

Full guide
Read the deep dive on this attack →

Related terms

Shadow ITShadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.Prompt InjectionPrompt injection is an attack that hides malicious instructions in content an AI assistant processes, manipulating it into leaking data or taking harmful actions.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo