Definition
Shadow AI is the use of artificial intelligence tools or applications by employees without the approval or oversight of their organization’s IT or security function. A marketer pasting a customer list into a personal ChatGPT account is shadow AI. So is a designer using an image generator the company hasn’t vetted, or a team switching on an AI feature inside a SaaS product before anyone has reviewed it.
The term extends “shadow IT,” which describes any technology used at work outside official channels. IBM’s 2025 Cost of a Data Breach Report, the first edition to study the subject, describes shadow AI as the unregulated, unauthorized use of AI.
A related term is BYOAI, short for “bring your own AI.” It refers to employees bringing personal AI tools to work. BYOAI describes the behavior. Shadow AI describes the risk that results when the organization can’t see or govern it.
See also: AI Governance Board (AIGB), Generative AI, Personal Identifiable Information (PII), General Data Protection Regulation (GDPR)
Why it matters for marketing
Marketing teams are heavy users of generative AI, and much of the work is easy to do in a free browser tool. Drafting ad copy, summarizing a research report, cleaning a spreadsheet, generating image concepts: none of it requires IT to install anything. That convenience is why shadow AI is common in marketing departments.
Marketing also handles the kinds of data that create exposure. Customer email lists, purchase histories, unreleased campaign plans and embargoed product details all pass through the department. When that material goes into an unapproved AI tool, the company may lose control of where it’s stored and whether it’s used to train a model. For customer personal data, that can be a compliance problem under privacy laws such as the GDPR.
There’s a brand dimension as well. Content produced in unvetted tools skips whatever review the company has set up for accuracy, intellectual property and disclosure.
The numbers show how widespread the behavior is. Microsoft and LinkedIn’s Work Trend Index found that 78% of AI users bring their own AI tools to work. In a Gartner survey of cybersecurity leaders, 69% said they had evidence or suspected that employees were using public generative AI at work.
How shadow AI happens
Shadow AI usually isn’t malicious. Employees are trying to get work done faster. A few patterns account for most of it.
| Form | Example | Main risk |
|---|---|---|
| Personal accounts on public AI tools | Using a personal chatbot login to rewrite a customer email | Company data stored outside company control |
| Unapproved AI applications | Signing up for an AI video or transcription tool with a work email | No security or legal review of the vendor |
| Embedded AI features | Turning on an AI assistant inside an existing SaaS platform | New data processing that wasn’t in the original vendor assessment |
| Browser extensions and plugins | Installing an AI writing extension that reads page content | Broad access to whatever is on screen |
| Unsanctioned agents and automations | Connecting an AI agent to a shared drive or CRM through a personal API key | Automated access and actions with no oversight |
Several conditions make it more likely. Approved tools may not exist yet, or may be weaker than free alternatives. The approval process may take months. Policies may be unwritten or unknown. And staff often don’t realize that entering data into a tool counts as sharing it with a third party.
The risks
Data exposure. Confidential or personal data entered into an unapproved tool leaves the company’s controlled environment. IBM found that breaches involving shadow AI compromised customer personal information in 65% of cases, against a global average of 53%. Intellectual property was compromised in 40%, compared with 33%.
Higher breach costs. Organizations with high levels of shadow AI saw breach costs an average of $670,000 higher than those with little or none, according to the same report. One in five organizations in the study reported a breach involving shadow AI.
Compliance. Unreviewed tools may process personal data in ways that conflict with privacy law, contracts with clients, or industry rules.
Inaccurate output. Content from unvetted tools doesn’t go through established review, so errors and fabricated claims are more likely to reach customers.
Intellectual property. Ownership of AI-generated material can be unclear, and some tools’ terms grant the vendor rights over inputs.
No visibility. Leaders can’t manage, measure or improve AI use they don’t know about.
How to measure shadow AI
There’s no standard metric. Organizations that track it typically start with an inventory and compare it against the approved list.
Shadow AI rate = (unapproved AI tools detected ÷ total AI tools detected) × 100
An illustrative example: a discovery exercise in a marketing department finds 20 AI tools in use, of which 8 are on the approved list. The other 12 are unapproved. The shadow AI rate is 12 ÷ 20 × 100 = 60%.
Other measures organizations use:
- The share of employees using at least one unapproved tool, from surveys or network data
- The number of incidents in which sensitive data was sent to an AI application
- The time it takes to review and approve a requested tool
- The share of AI spend that sits on personal or departmental cards outside procurement
How to manage shadow AI
Discover what’s in use. Combine an anonymous staff survey with technical discovery through network monitoring, single sign-on logs and expense reports.
Provide approved alternatives. Give staff sanctioned tools that are good enough to make workarounds unnecessary. Gartner’s guidance and other analysts make the same point: bans alone tend to push use out of sight.
Write an acceptable use policy. State which tools are approved, what data may be entered into each, and what review is required before publishing output.
Classify data. Define tiers, such as public, internal and confidential, and tie each tier to the tools where it’s allowed.
Speed up approvals. A tool request process that takes days instead of months removes a major reason people go around it.
Train staff. Cover why the rules exist and what happens to data entered into AI tools.
Monitor and audit. Gartner recommends regular audits for shadow AI activity and adding generative AI risk evaluation to SaaS assessments. Among organizations with AI governance policies in IBM’s study, only 34% performed regular audits for unsanctioned AI.
Set up governance. Assign ownership to an AI Governance Board or an equivalent group that includes marketing.
Comparison with related concepts
| Term | What it covers | How it differs from shadow AI |
|---|---|---|
| Shadow AI | AI tools used without organizational approval or oversight | The subject of this entry |
| Shadow IT | Any hardware, software or cloud service used without IT approval | The broader category. Shadow AI is a subset |
| BYOAI | Employees bringing personal AI tools to work | Describes the behavior. It can be sanctioned if the organization permits and governs it |
| Sanctioned AI | AI tools reviewed, approved and managed by the organization | The governed counterpart |
| Rogue AI | An AI system behaving outside its intended limits | Concerns the system’s behavior, not who approved its use |
| Shadow data | Data stored or copied outside governed systems | Often a consequence of shadow AI |
Shadow AI differs from older shadow IT in one practical way. A file-sharing app used without approval stores data. An AI tool may also learn from it, generate new content from it, or act on it. That raises questions about model training, output accuracy and automated actions that shadow IT didn’t.
Best practices
Assume it’s already happening. Survey data consistently shows unapproved use in most organizations. Start with discovery.
Ask before enforcing. An amnesty period in which staff can report tools without penalty gives a more accurate inventory than monitoring alone.
Make the approved path the easy path. If the sanctioned tool is slower or worse, people will keep using the other one.
Be specific about data. “Don’t enter confidential information” is vague. “Don’t enter customer names, emails or purchase records” is usable.
Review embedded AI features. New AI capabilities inside existing platforms such as a CRM or design tool need the same review as a new vendor.
Include agencies and freelancers. Outside partners handling the company’s data should follow the same rules.
Revisit the approved list often. New tools appear monthly. A list that’s a year old pushes people back to workarounds.
Treat reports as useful information. Shadow AI use shows which tasks staff want help with. That’s input for the AI roadmap.
Future trends
Shadow agents. Unapproved AI agents that can take actions, such as sending messages or changing records, carry more risk than chat tools. A Cloud Security Alliance research note from May 2026 points out that an unsanctioned AI application acts on data instead of passively receiving it.
More incidents expected. Gartner predicts that by 2030, more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI.
AI inside everything. As vendors add AI features to existing software by default, the line between approved and unapproved tools gets harder to draw.
Dedicated tooling. Security vendors now sell products for discovering and governing AI use, and these are being added alongside existing data loss prevention systems.
Regulatory pressure. Rules such as the EU AI Act, including its provisions on staff AI literacy, give organizations more reason to know which AI systems are in use.
Governance catching up slowly. IBM found that 63% of breached organizations either had no AI governance policy or were still developing one. Only 37% had policies to manage AI or detect shadow AI.
Frequently asked questions
What is shadow AI? It’s the use of AI tools at work without the organization’s approval or oversight.
What’s an example of shadow AI in marketing? A marketer uploads a customer list to a personal AI chatbot account to segment it. The company hasn’t approved the tool and doesn’t know the data has left its systems.
How is shadow AI different from shadow IT? Shadow IT is any unapproved technology. Shadow AI is the AI-specific subset. It adds risks around model training on company data, inaccurate output and automated actions.
Is shadow AI illegal? Not in itself. It can lead to legal problems if it results in personal data being processed unlawfully, or in breaches of contracts or industry regulations.
Why do employees use unapproved AI tools? Mostly for speed and convenience. Approved tools may be unavailable, less capable or slow to get, and policies are often unclear.
How common is it? Common. Microsoft and LinkedIn’s Work Trend Index reported that 78% of AI users bring their own AI tools to work.
What does shadow AI cost? IBM’s 2025 report found that organizations with high levels of shadow AI had breach costs averaging $670,000 more than those with low levels or none.
Should companies ban AI tools to stop it? Analysts generally advise against relying on bans. They tend to drive use underground. Providing approved tools and clear rules is the more common recommendation.
How can a marketing team find out what’s being used? Run an anonymous survey, check expense reports and software sign-ups, and ask IT for network and single sign-on data.
What is BYOAI? “Bring your own AI.” It describes employees using their personal AI tools for work. It becomes shadow AI when it happens without the organization’s knowledge or controls.
Related terms
- AI Governance Board (AIGB)
- Generative AI
- Large Language Models (LLM)
- AI Agent
- Artificial Intelligence (AI)
- General Data Protection Regulation (GDPR)
- Personal Identifiable Information (PII)
- Human-in-the-Loop (HITL)
- Total Cost of Ownership (TCO)
- Technology Adoption Model (TAM)
Sources
- IBM (via HPCwire). “IBM: 13% of Organizations Reported Breaches of AI Models, 97% of Which Reported Lacking Proper AI Access Controls.” July 30, 2025. https://www.hpcwire.com/aiwire/2025/07/30/ibm-13-of-organizations-reported-breaches-of-ai-models-97-of-which-reported-lacking-proper-ai-access-controls/
- Help Net Security. “Average global data breach cost now $4.44 million.” August 4, 2025. https://helpnetsecurity.com/2025/08/04/ibm-cost-data-breach-report-2025
- AI Business. “IBM Highlights AI Security Issues in 2025 Data Breach Report.” https://aibusiness.com/cybersecurity/ibm-highlights-ai-security-issues-in-2025-data-breach-report
- Infosecurity Magazine. “Gartner: 40% of Firms to Be Hit By Shadow AI Security Incidents.” https://www.infosecurity-magazine.com/news/gartner-40-firms-hit-shadow-ai/
- Cloud Security Alliance AI Safety Initiative. “Shadow AI Apps: The Enterprise Attack Surface That Outpaces Monitoring.” May 30, 2026. https://labs.cloudsecurityalliance.org/research/csa-research-note-shadow-ai-apps-enterprise-20260530/
- Fortra. “Shadow AI security breaches will hit 40% of companies by 2030, warns Gartner.” https://www.fortra.com/blog/shadow-ai-security-breaches-will-hit-40-companies-2030-warns-gartner
