Shadow AI: the security risk your business can’t see
The use of AI in the workplace has increased dramatically and not always through a company-approved rollout!
Shadow AI refers to the use of AI tools or assistants at work without the knowledge, approval or oversight of an organisationâs IT or security team. It might be the use of a meeting note-taker, through browser tabs or a quick request on ChatGPT. IBMâs research found that shadow AI-linked incidents more than doubled, from 20% to 43% of AI-related breaches last year. This comes at a huge cost to businesses.
What is the difference between shadow AI and shadow IT?
Shadow IT is where an employee signs up for a file-sharing tool or creates a cloud account without telling anyone. It is risky but has been around for years and is fairly well understood.
Shadow AI involves a different and higher level of risk because an AI tool doesnât just store your data, it processes it. If one of your team has shared a client contract or your pricing list with an AI tool, you will have no visibility as to where this information has gone, no audit trail and no contractual protection.
In addition, traditional security measures are unlikely to identify the moment a staff member copies client data into a chat window.
An escalating risk
AI agents donât simply answer questions, they browse, execute code, send emails, call APIs etc. So, if your staff are using shadow AI, your business may not only be leaking sensitive data, the unapproved AI tool could also be accessing your systems.
The numbers you need to know
- On average, it took companies 247 days to detect AI breaches, meaning organisations had more than eight months of unmonitored exposure.
- 65% of shadow AI incidents compromised customer personal data and 40% exposed intellectual property.
- 97% of organisations experiencing an AI breach lacked proper AI access controls, and 63% had no AI governance policy.
Is banning AI a realistic option?
Although it might be tempting to ban AI, in practice, this is likely to mean that AI usage simply moves onto personal devices and accounts, so organisational visibility becomes poorer, not better.
Your company aim should be to offer your team an approved AI tool or tools that work well, alongside clear AI governance.
AI governance guidelines
For most organisations, AI governance would include the following key essentials:
- An approved AI tools list. State which AI tools are permitted and ensure they are suitable for your business requirements.
- A short AI use policy. This should detail what company data can be input into an AI agent, what is strictly prohibited, and which outputs need human review before they reach a client.
- A named owner. Detail who is responsible if an AI-assisted process produces a wrong output.
- An AI register or risk log. Before you write any AI use policy, put together a list of what AI tools/agents are actually in use before writing any AI policies. You can’t govern what you can’t see.
- Staff awareness and training. Ensure your team are clear as to which AI tools are approved and what the AI Use Policy includes.
- Regular policy reviews. AI tooling is ever-changing so any policies/guidelines should be reviewed quarterly.
Finally
Donât forget the importance of identity controls. Nearly 50% of AI usage is through personal accounts, so conditional access and SSO (Single Sign-On) matter as much as the policy itself.
How CloudTech24 can help
Shadow AI is familiar territory for CloudTech24. Our 24/7/365 in-house security team helps organisations discover unsanctioned tool usage, tighten access controls, apply data protection at the point sensitive information would reach an AI system, and build AI governance that people actually follow.
Get in touch for a no-obligation conversation, book a FREE discovery call.



