Shadow AI is the use of AI tools your organisation has not approved or does not know about, usually employees reaching for tools like ChatGPT, Claude or Gemini to get their work done faster. In most organisations it is already happening, well before any formal policies are put in place.
Last updated: 30th July 2026
Author: Damien Mallon, AI Security & Governance Lead, Datapac
Shadow AI generally takes some common forms:
- Public AI tools used through personal accounts, such as pasting work into a free chatbot.
- AI features inside software you already run, switched on by an update pushed out by a vendor.
- AI adopted or built by a team on its own, outside any IT involvement.
None of it is usually the result of bad intent, and the instinct to respond with a ban is the one worth resisting. This piece covers what shadow AI actually is, the risk it genuinely carries, how to find it, and why the organisations that handle it well do not try to stamp it out.
Examples of Shadow AI
The public chatbots are the obvious case, but they are only the visible surface. The forms that tend to cause the most difficulty are the ones nobody is actively looking for.
| Form | Typical example | Why it is easy to miss |
|---|---|---|
| Public AI tools, personal accounts | An employee using a free chatbot to summarise customer data or redraft a document. | Happens on personal logins and devices, leaving little trace on company systems. |
| AI embedded in existing software | A supplier adds a generative feature to a tool you already use, enabled by default. | No new tool is bought and no login changes, so nothing flags that it has appeared. |
| Developer and technical AI tooling | Technical staff using AI assistants or unofficial alternatives to speed up their work. | Sits inside technical workflows that general monitoring rarely covers. |
| Department-built AI solutions | A team wiring up an AI tool through a no-code platform to solve a local problem. | Created entirely outside IT, so it exists with no central record at all. |
The last of these is usually the hardest to surface, because it was never a product anyone bought.
Taken together, these are the shape of what is actually in use, and most organisations are surprised by how much of it there is.
Why Shadow AI Is So Common
AI tools are useful, instantly available, and, from a user’s perspective, need no procurement process to start using. Someone who spends an hour a day on repetitive drafting can halve that with a tool they open in seconds, particularly when the organisation has offered no approved alternative that does the same job. Faced with that, people reach for whatever is closest to hand. That is the whole of it: shadow AI is rarely a decision to break the rules, it is people trying to do their job more effectively with the tools they can get to.
The Risks of Shadow AI
There are several risks associated with Shadow AI usage, including:
Loss of control over data
Information entered into a tool you do not control leaves your environment, and where it then goes, whether it is stored, retained, or used to train a model, is no longer something you can answer for. Two consequences of that matter most:
- Regulatory exposure: This is particularly concerning if employees upload personally identifiable or otherwise sensitive customer data. Under GDPR, as enforced in Ireland by the Data Protection Commission, responsibility for ensuring data protection sits with the organisation as data controller, and an employee acting on their own does not shift that responsibility.
- Intellectual property leaving the organisation: Internal processes, pricing models, proposal language and customer information pasted into an unmanaged tool are, in effect, handed to a third party whose terms you have not read and cannot enforce.
No record of use
When AI is used invisibly, there is nothing to show how it was used or what it influenced, which makes it hard to stand over a decision afterwards or to answer a question from a regulator, a client, or an auditor.
Unsupervised influence on decisions
Where AI output feeds a decision with no one checking it, an error or a fabrication can shape a choice before anyone notices. The risk is not the tool being used, but its output being trusted without the oversight a sanctioned process would apply.
Operational continuity
Teams can grow accustomed to using AI tools they sourced themselves, integrating them deeply into personal or even team workflows. That is to say, they become dependent on AI. This is a real risk, as these tools were never officially approved and therefore do not sit under any official support remit, so that if something should go wrong, they have no one to turn to.
How To Find Shadow AI Already In Use
Finding shadow AI is not a single check you run once. It is an exercise that combines technical signals with human ones, and the common mistake is to treat it as only one or the other. The technical side draws on what your systems can already tell you: the traffic leaving your network, the activity inside the platforms you run, the subscriptions showing up in expenses. Each of these reveals part of the picture, and each has blind spots: anything used on a personal device, or embedded inside an approved tool, can pass all of them without a trace.
Which is why one of the most useful steps is also the most straightforward, and the one organisations most often skip: asking people directly. A short, open conversation about what they use and why will surface things no system can, not just which tools are in play but what work they are doing and which problems they solve. The people who have found the most use in AI are usually glad to talk about it, because from their point of view they have solved a real problem, and that is precisely the information you need.
It is worth treating those conversations as more than a stocktake. Each unsanctioned tool in use is a signal of a need the organisation has not yet met through approved means. Once you can see the need clearly, you can meet it deliberately, with a supported tool that does the same job inside your own controls. This is how the discovery exercise turns into something useful rather than punitive: it tells you not only what to replace, but what to replace it with, and why people will actually make the switch.
Why Shadow AI Bans Fail
The instinct to ban Shadow AI outright is understandable, however it almost always makes things worse. Ban the tools and the usage rarely stops, rather it moves further underground: onto personal devices, personal accounts, and phones, where you have no sight of it whatsoever. The usage continues because the need for AI tools is still real, and the only thing that has actually changed is that your view of it is even more limited than before.
That is the trap at the heart of the subject. A ban feels like control, but what it really does is trade a visible risk for an invisible one. The exposure has not shrunk; your ability to see and manage it has. This is the single most important thing to understand about shadow AI: the organisations that handle it well are not the ones with the strictest rules, they are the ones that can see what is actually happening, because you can only manage what remains in view.
The more effective response works the other way around. Set a clear, usable policy that tells people what is acceptable and why, and pair it with an approved alternative good enough that the unofficial tool stops being worth the risk. A supported tool such as Microsoft 365 Copilot, provided within your own controls, removes much of the reason people reached for an unmanaged option in the first place. The policy draws the line; the alternative removes the incentive to cross it.
Where To Start
If this has left you convinced there is unapproved AI somewhere in your organisation, that instinct is usually right, and it is the place to begin. The productive first move is not a crackdown but a clear, blame-free look at what is actually in use. What you do with that picture, the policies and controls that turn it into lasting confidence, is the province of AI governance, and where the real work of adopting AI safely begins. For many Irish organisations that work now runs alongside NIS2, as it takes effect in Irish law, giving the same visibility a second, regulatory reason to matter.
Our AI Governance and Readiness service helps organisations take exactly that next step, from an honest view of what is in use through to the controls and capability that let AI be adopted with confidence.
Frequently Asked Questions
What is the difference between shadow AI and shadow IT?
Shadow IT is the broad term for any technology used without the organisation’s knowledge or approval. Shadow AI is the specific case involving AI tools. The distinction matters because the main risk with shadow AI is not the tool but the data fed into it and where that data then goes, a different kind of exposure to most traditional shadow IT.
Is shadow AI a GDPR concern?
It can be. Where personal data goes into an AI tool the organisation does not control, there are real questions about where it is processed and stored and on what legal basis, and the organisation stays responsible for answering them. You cannot assess an exposure you cannot see, which is why bringing it into view matters so much.
Is an AI policy on its own enough?
A policy is necessary but rarely sufficient by itself. A rule telling people not to use a tool, with no workable alternative for the need that drove them to it, tends to move the behaviour out of sight rather than stop it. Policy works best paired with an approved tool that does the job people were trying to do.