Shadow AI
Also called: shadow AI agents · unsanctioned AI
Shadow AI is the use of AI applications, models, or agents inside an organization without the approval, oversight, or visibility of IT and security teams.
Shadow AI is the AI-era version of shadow IT. An employee pastes customer data into a personal chatbot account, installs a coding agent on a work laptop, or connects an unapproved MCP server to company systems, all to get work done faster, and none of it is known to the security team.
The risks are concrete: sensitive data leaving the organization, credentials and tokens granted to tools no one reviewed, agents acting with a person's permissions, and compliance obligations that assume you know where data goes. Agents raise the stakes over plain chatbots because they can take actions, not just receive text.
Bans are hard to enforce and often push usage further underground, so common responses combine an approved tool list, clear policy, visibility, and sanctioned alternatives.
Example
A developer connects a community-built mcp-server to their work repository with a personal access token to speed up code review. The server was never vetted, so the organization cannot tell what data it can read, and the token appears in no inventory.
How it differs
Shadow AI vs. prompt-injection: shadow AI is a governance gap (unknown, unapproved tools in use). Prompt injection is an attack technique against a specific agent. Shadow AI makes injection and leakage harder to detect because nobody is watching those tools.
Common misconceptions
FAQ
What is shadow AI?
Why is shadow AI risky?
How do organizations manage shadow AI?
Last checked: 2026-09-20