What Is Shadow AI? Risks for Businesses and How to Manage It

What is shadow AI?
Shadow AI is the use of AI tools at work without the company's knowledge, approval or oversight. A chatbot opened with a personal account is a typical case. So is a browser extension or a free text tool. Once company data enters these tools, you no longer control where it goes.
The idea grew out of shadow IT. An employee wants to work faster, so they open a tool without asking anyone. The intent is usually good. However, the result is a data flow that nobody can see.
In this guide we explain how shadow AI appears, which numbers have a real source, and what it means for GDPR and similar laws. We also show how to manage it without a blanket ban, using a simple policy outline.
Why did shadow AI spread so fast?
First, access is easy. You no longer need a credit card to try a generative AI tool. An email address and a few seconds are enough. So the tool is in use before IT even hears about it.
Also, speed pressure is the second reason. An employee saves minutes by summarizing a report or drafting a customer email. If the company has no approved option, a personal account is the easiest path.
Also, the tools keep changing. In practice, a new plugin or "assistant" appears every week. The team that writes policy cannot keep up, so a gap opens. Shadow AI grows inside that gap.
- Easy access: free accounts need no setup.
- Time pressure: fast output means fast delivery.
- No policy: nobody knows what is allowed.
- No approved tool: employees have to find their own.
What do the numbers say about shadow AI?
Let us look only at figures with a named source. In its 2024 Work Trend Index, Microsoft and LinkedIn report that 78 percent of AI users bring their own tools to work. The report calls this "Bring Your Own AI". At small and medium-sized companies the share is 80 percent (Microsoft Work Trend Index 2024).
IBM's 2025 Cost of a Data Breach report covers the cost side. One in five organizations in the study had a breach tied to shadow AI. These incidents added up to 670,000 US dollars to the average breach cost. Also, 63 percent of breached organizations had no AI governance policy (IBM Cost of a Data Breach).
These figures come from global samples. They may not match a small local business exactly. Still, they show the direction clearly.
You should also read them together. Microsoft measures behavior, while IBM measures cost. Combined, they say that usage is common and oversight is weak. So the risk comes less from one event and more from invisible build-up.
Which data do employees paste into AI tools most often?
In our experience, the story starts innocently. An employee wants a meeting note summarized. Also, the note may include a customer name, a price quote or a contract clause.
Therefore the type of data decides the risk, not the brand of the tool. The list below shows the inputs we see most often in teams.
- Customer lists, email threads and contact details.
- Price quotes, contract drafts and tender files.
- Source code, API keys and system configurations.
- HR data such as resumes, performance notes and salary tables.
- Financial statements, budget files and forecasts.
- Unreleased product plans and strategy decks.
However, nobody enters these with bad intent. Once the data is in, however, you cannot control what happens to it next.
There is also the problem of indirect data. Three harmless facts can identify a client when you combine them. For example, an industry, a city and a budget range together can reveal who the client is. So training should cover context as well as names.
What risks does shadow AI create?
The risk is bigger than a data leak. Shadow AI causes trouble in several layers, and a different team owns each layer. That is why you should look at the risks one by one.
Legal risk comes from processing personal data without a basis. Security risk comes from unmanaged accounts and extensions. Reputation risk starts when a wrong or invented answer reaches a customer.
- Data leakage: confidential information goes to a third-party system.
- Compliance risk: GDPR and other privacy duties may be breached.
- Intellectual property: company content and code move to uncontrolled places.
- Accuracy risk: AI output can be wrong, and nobody checks it.
- Lost visibility: you do not know which tool holds what, so incident response slows down.
How does shadow AI lead to a data leak?
A leak is often a paste, not an attack. First, the employee enters text into the tool. Depending on the provider's terms, the tool may store that input or use it to improve models. Business plans usually switch this off, while free personal accounts vary by provider.
So the business and personal versions of the same tool can differ a lot. Retention time, training use and admin controls depend on the contract. Read the terms before you decide.
Browser extensions are another door. An extension can read the content of the open page. Therefore a "writing assistant" installed while a customer panel is open can create a data flow.
IBM found that 97 percent of organizations with an AI-related breach lacked proper AI access controls. In other words, the problem usually comes from weak management, not from the technology itself.
Why is shadow AI a problem under GDPR?
GDPR expects any organization that processes personal data to take suitable technical and organizational measures. Article 32 ties this to security. Article 28 covers the relationship with processors (GDPR text on EUR-Lex).
An AI provider may act as a processor when it handles personal data for you. In that case you need a written contract. When an employee signs in with a personal account, no such contract exists.
Transfers matter too. If the provider's servers sit outside the EU, you need a transfer mechanism. Because nobody checks this in shadow AI, the gap widens.
The same logic applies under other privacy laws, such as Turkey's KVKK or US state privacy laws. The details differ by country. So the key question stays the same: do you know what data goes where?
This section is not legal advice. Work with your lawyer and your data protection officer on your own case.
What does the data protection regulator say about generative AI?
Regulators now publish guidance on this topic. Turkey's data protection authority released its "Generative AI and Personal Data Protection" guide on 24 November 2025. It explains that personal data processing can occur directly or indirectly at the training, usage and output stages. It also reminds readers to check output accuracy regularly (KVKK guide, Publication No 113).
For a company, the message is practical. In practice, you act as the data controller, even when an employee made the choice alone. So you should be able to answer a few questions. What data is processed? What is the legal basis? Does the data leave the country? Does your privacy notice cover it?
For the wider picture, see our guide on how to build a GDPR compliant website. You can also read our overview of generative AI in Turkey.
What is the difference between shadow AI and shadow IT?
Both share the same root, but AI adds a twist. In shadow IT, data usually sits in one place. For example, a document uploaded to a file-sharing tool stays there, and you can delete it.
In shadow AI, the data interacts with a model. Also, the tool creates output and keeps a chat history. In some cases, the input may feed model improvement. So pulling the data back is harder.
| Feature | Shadow IT | Shadow AI |
|---|---|---|
| --- | --- | --- |
| Typical example | Unapproved cloud storage | Chatbot with a personal account |
| Data flow | Upload and storage | Input, processing and output |
| Ease of deletion | Usually high | Depends on provider terms |
| Output risk | Low | Wrong or invented answers |
| Detection | Network and app logs | Browser, extension and network logs |
How can you tell if your company has shadow AI?
You almost certainly have it. Microsoft's figure points that way, because most users bring their own tools. So the real question is how much, and where.
Do not use accusing language when you look for it. If employees fear getting caught, they will hide their use. Instead, focus on building an inventory.
- Send an anonymous survey: which tools do you use, and for what tasks?
- Search network and DNS logs for known AI domains.
- Export the browser extension inventory from your admin console.
- Look for AI subscriptions in expense reports.
- Review OAuth grants: which third-party apps connect to company accounts?
This work takes a few days. At the end, you hold a real usage map that you can use when you write the policy.
Should you ban AI tools completely?
Usually not. However, a ban does not remove the need. It only hides the use. In practice, the employee continues on a phone or a home laptop, and you see nothing.
A ban also hurts competitiveness. Also, your rivals speed up with AI while your team waits. Therefore the right approach for most companies is to open a safe path.
There are exceptions. For very sensitive public-sector data, health records or tender files, closing certain tools completely can make sense. Even then, place an approved alternative next to the ban.
A ban also costs trust. If employees think a rule exists to make their work harder, cooperation drops. A traffic-light model works better. Green tools are free to use, yellow tools need conditions, and red tools stay closed. Employees should see the color at a glance.
How do you write a company AI policy?
A good policy is short, clear and usable. Nobody reads ten pages. One page should say what is allowed, what is not, and whom to ask.
For a framework, you can draw on NIST's AI Risk Management Framework. The steps below give a simple outline that we use when we work with teams.
- Define the scope: which tools and which employees are covered?
- Classify your data: public, internal, confidential and personal.
- List the approved tools for each class.
- Set the approval path: who handles requests for a new tool?
- Add an output rule: customer-facing content passes a human check.
- Open a reporting path, so a person who makes a mistake can report it without fear.
- Review the policy every three months.
Also assign an owner. Also, a rule without an owner fades away. In a small company this may be the managing director. In a larger one, security and legal work together.
Which data can go into which tool?
Data classification is the heart of the policy. An employee should answer "can I paste this?" in two seconds. Complex matrices do not work.
The table below is a sample starting template. You need to adapt it to your sector, contracts and local law. It is not legal advice. It is a starting point based on field experience, with no guarantee.
| Data class | Example | Unapproved public tool | Approved business tool |
|---|---|---|---|
| --- | --- | --- | --- |
| Public | Published blog text | Allowed | Allowed |
| Internal | Meeting notes, draft plans | Limited | Allowed |
| Confidential | Price quotes, strategy | Banned | Conditional |
| Personal data | Customer list, resumes | Banned | With legal sign-off |
How do you build an approved tool list?
A list that makes work easier is the best way to cut shadow AI. People go to the easy tool, not the banned one. So the approved option must be easy too.
When you pick a tool, read the contract. Ask the vendor in writing whether inputs train models. Also ask about retention time and deletion rights. Look for an admin panel, user logs and single sign-on.
Even a small company can start with a short comparison table. For example, score three tools on the same five criteria and pick one as a pilot. For a broader view, read our post on how to use AI in business.
To keep the list alive, add a request form. When an employee spots a new tool, they submit it and get an answer within two weeks. If the answer is late, they will go their own way again.
How should employee training work?
Training is about building habits, not scaring people. Saying "do it this way" works better than saying "don't". Choose short sessions with examples over a two-hour slide deck.
Use concrete examples. Try anonymizing a real customer email together. That way the rule stops being an abstract sentence.
Also, make the training role-based. Sales faces customer data, while developers face source code and keys. So give each team examples in its own language.
AI literacy is also becoming a duty. The EU AI Act asks providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff (EU AI Act on EUR-Lex). For the basics, see our AI literacy guide.
How does shadow AI show up in marketing and agency teams?
Indeed, marketing teams are among the heaviest AI users. Ad copy, emails, blog drafts and report summaries are part of the daily flow. That is why the risk concentrates there.
Here is an example scenario. It is a fictional flow, not a real case. For example, a specialist exports a table from an ad account and uploads it to a free chatbot to write a monthly report. The bot returns a neat summary, and the specialist sends it to the client.
Weeks later, others copy the habit. Nobody thinks it is wrong, because the result is good. However, the table holds the client's budget and conversion numbers. If the contract has a confidentiality clause, this may be a breach. Besides, the company holds no record of the use.
The fix is simple. Give the team an approved tool and an anonymization rule. That way, you keep the speed and cut the risk. For our approach to safe setups, see our AI automation services.
How do AI plugins and agents make shadow AI bigger?
However, chatbots are only the surface. Also, many tools now offer plugins that connect to email, calendars and file storage. An employee clicks "Sign in with Google" and grants access.
These permissions are often broad. An app can ask to read email or open files. So shadow AI is no longer only pasted text. It is also data that flows in the background.
AI agents make the picture harder. An agent acts on your behalf, connects to systems and makes choices. Treat the access you give an agent as seriously as the access you give a new hire. Our guide on AI agents for marketing goes deeper.
- Review plugin permissions every three months.
- Remove OAuth connections you do not need.
- Give agents the least access they need.
- Add an approval step for new connections.
Why is output accuracy also a shadow AI risk?
A data leak comes to mind first. However, a wrong answer matters too. Generative models can produce text that looks real but is false. People call this a hallucination.
Without an approved process, nobody verifies the output. The employee sends the text to a customer as it is, or puts it into a report. As a result, your company owns a wrong figure or an invented source.
The KVKK guide also stresses regular accuracy checks. So add a simple rule to your policy: any AI output that reaches a customer or the public gets a human check, with sources.
In short, verification protects quality as much as security. To see the limits on the content side, read our post on the limits of AI content creation.
How can you get value from AI while protecting your data?
The goal is not to turn AI off. Instead, it is to use it safely. A few simple habits reduce the risk a lot. Instead, most of them cost nothing extra.
The first habit is anonymization. Write "Client A" instead of the real name, and use approximate figures. The model does the same job, and a leak would mean little.
The second habit is to work with business accounts. These plans offer admin controls, retention settings and contract protection. Personal accounts give you none of these.
The third habit is to keep prompts small. Give the model the smallest context it needs. For example, share one clause instead of the whole contract.
- Remove real names and ID details.
- Prefer managed business accounts.
- Share the smallest context needed.
- Check the output against its sources.
Which technical controls help against shadow AI?
However, policy alone is not enough. Technical controls back it up. The first layer is identity. If you use single sign-on with business accounts, you can see who uses approved tools.
Second, network and browser control forms another layer. You can monitor known AI domains, block risky ones or show a warning only. An allowlist for browser extensions also works well.
Third, data loss prevention adds a layer. These tools detect patterns such as card or ID numbers and can stop a paste. However, not every budget covers this. So start with your riskiest data class.
Finally, keep records. Note which tool was approved, when and by whom. In an audit or an incident, this log saves time. For security basics, see our website data security guide.
What mistakes do companies make when they manage shadow AI?
The first mistake we see is writing the policy in legal language only. If employees do not understand it, they will not follow it. So write a short text in daily language, with examples.
The second mistake is banning without an alternative. People still have to do their jobs, so they find a way. The third mistake is writing the policy once and leaving it. Tools change fast, so the policy must change too.
The fourth mistake is a punishment culture. If the person who reports a mistake gets punished, the next incident never gets reported. Therefore write the principle "reporters are protected" in plain words.
- A long and confusing policy text.
- A ban with no alternative.
- Rules that nobody reviews.
- Fear-based communication.
- Leadership exempting its own use.
What should you do in the first 30 days?
You do not need a big program. However, a simple thirty-day plan removes most of the risk. What matters is that you start and measure.
- In week one, run an anonymous survey and build the usage inventory.
- By week two, write the data classes and the one-page policy.
- During week three, open one business tool as a pilot and check the admin settings.
- Finally, give short training in week four and announce the reporting path.
Start with a small team, such as marketing or sales. Next, spread what you learn across the company. That way, you see the mistakes at a small scale.
At the end of the month, measure three things: the share of staff using approved tools, the number of reported incidents, and the share who understand the policy. If the numbers look bad, question ease of use, not the policy. Also, you can suggest our password generator to your team.
When should you get outside help?
Sometimes internal resources are not enough. If you work in a sector with sensitive data, review contracts and data flows with a specialist. So a lawyer handles legal questions, while a security consultant handles technical ones.
On the marketing and web side, we can help. We place AI into your workflow safely, review data collection points on your site and prepare usage rules for your team. For broader support, you can also look at our SEO consulting service.
Start small, measure and expand. That way, you protect your data without slowing your people down.




