# What is shadow AI?

> Shadow AI is the unmanaged use of generative AI tools by employees. Definition, real-world risks, and how to respond without killing productivity.

Language: en · Category: governance · Author: Nicolas Corod (Founder & CEO) · Published: 2026-05-20

## TL;DR

**Shadow AI** is the use of consumer generative AI tools ([ChatGPT](https://chatgpt.com/), [Claude](https://claude.ai/), [Gemini](https://gemini.google.com/), personal Copilot…) by employees **without policy, without audit, and often without IT or security approval**.

It's the modern shadow IT, and it scales faster than anything that came before: [Microsoft's 2024 Work Trend Index](https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part) found that 75% of knowledge workers already use GenAI at work, and that 78% of those users bring their own AI tools. Unlike shadow SaaS (which usually involves signing up for a tool) shadow AI starts with a single copy-paste into a browser tab. There is no procurement step to catch.

## What "shadow AI" actually covers

The term spans a wider spectrum than most leadership teams realise:

- A salesperson pasting a prospect's email into ChatGPT to draft a follow-up.
- An engineer routing internal code through a personal Copilot subscription.
- A finance analyst uploading an Excel extract to Claude to summarise the quarter.
- A team building an undocumented automation on top of someone's personal OpenAI API key.
- A developer installing a community `SKILL.md` file nobody reviewed, the pattern that makes [agent skills the new frontier of shadow AI](/en/blog/skill-md-the-king-of-shadow-ai/).

Each one looks like a productivity hack to the individual. Together they form an unmanaged data-exfiltration surface that no DLP tool was designed to see, because the channel is a human typing into a browser, not a SaaS integration with a discoverable scope.

## Why shadow AI is a problem

### 1. Silent data leaks

When a teammate pastes a draft contract, a customer list, or a code snippet into a consumer chatbot, that data may be:

- **Stored by the vendor.** Retention policies vary by product, by tier, and over time. Personal-account terms are routinely different from enterprise ones, and they change without your knowledge.
- **Used to train future models.** Most consumer tiers retain a training opt-in by default. Anything sensitive that goes in can resurface in another company's outputs months later.
- **Transferred outside the EU.** Most consumer endpoints route through US infrastructure, putting any GDPR-covered payload onto the wrong side of a cross-border transfer.

The trigger is usually mundane: a customer name in a reply, a clause from an ongoing negotiation, a snippet of source code with internal endpoint names. Nothing alarming on its own. Multiplied across an organisation, it adds up to a continuous leak with no incident timestamp to point at.

### 2. No audit, no policy

You don't know:

- **Who** is using what: accounts are personal, billing doesn't reach you, SSO doesn't apply.
- **On which documents**: content is pasted from clipboards your endpoint controls can't introspect.
- **With which prompts**, including any system prompt the user copied off a forum thread.

If a regulator comes knocking, a customer files an Article 15 GDPR request, or you suffer an incident downstream, you have nothing to produce. You can't certify what wasn't used, because you don't know what _was_ used.

### 3. Lost value

Usage stays **individual**. Nobody compounds. The prompt that finally cracked a tricky customer-support reply dies in someone's browser history at the end of the week. The few teammates who get genuinely good at GenAI become tribal knowledge centres of one. They leave, the practice leaves with them. What walks out is not information but [know-how, the part of the job documents never capture](/en/blog/knowledge-vs-know-how/). The organisation pays the latency cost of every team rediscovering the same patterns alone.

## The wrong answer: banning

Banning doesn't work. GenAI is too useful to drop. If you ban it, your teams will:

- Keep using it on personal phones, outside any device-management posture.
- Open anonymous accounts using personal emails.
- Stop telling you about it, politely.

Every ban policy that goes into effect has the same six-month outcome: usage continues, surfaces nowhere on a dashboard, and you've added a layer of dishonesty to the relationship. The leak now happens with both hands tied behind your back.

## The right answer: ship a governed alternative

The fix is product, not policy. Make the controlled path the easy path. That means giving every employee an assistant **as capable as ChatGPT but under your governance**:

- **Data stays in the EU:** hosted on infrastructure you've contracted with, on terms you've read.
- **Every interaction is logged:** by user, by document, by tool, end-to-end. Audit is no longer a manual ask.
- **Individual usage compounds:** working prompts and procedures get captured as reusable [roles](https://docs.skilder.ai) the rest of the team inherits, instead of dying in browser tabs.

A practical starting checklist for next quarter:

1. **Survey honestly.** Ask the team where they're already using consumer AI. The list will surprise you, and it's the input for everything else. For a quick baseline on the practices around it, [run the AI check-up](/en/ai-skills-check/).
2. **Ship an internal alternative before banning anything.** People will switch if it's at least as good. They will not switch if you only take the existing option away.
3. **Make the audit trail visible to users**, not just to compliance. Knowing that interactions are logged changes behaviour more reliably than a policy memo nobody reads. Bounding what each assistant can reach is the other half of the job: [least privilege for AI agents](/en/blog/least-privilege-ai-agents/) walks through it.

That's exactly why we built [skilder](/en): so a CIO can give every employee an assistant that's worth using, while keeping the data, the audit and the institutional know-how on the company's side of the line.

## Key takeaways

> Shadow AI isn't a discipline problem. It's a product problem. As long as your internal offering is worse than ChatGPT, your teams will keep using ChatGPT.

To dig deeper, see [the skilder platform](https://docs.skilder.ai).
