“While 80% of professionals use AI in their work, only 22% rely exclusively on tools provided by their company.” With this finding, IBM highlights the new dimension of shadow IT, a new category of risks that companies face when artificial intelligence tools and services are used outside the control, security, and governance processes defined by IT. As mentioned above, this is not the exception but the rule.
Let’s take a closer look at what shadow AI is, how widespread it is and, above all, how to address it effectively.
Key Points
- Most professionals use AI tools at work, but few rely exclusively on solutions provided by their company.
- Using AI without supervision can expose confidential data and personal information, creating compliance risks, financial losses and reputational damage.
- Shadow AI cannot be governed through bans alone: discovery, DLP, awareness and agent control can reduce risk without holding back AI adoption.
Shadow AI: when innovation slips beyond corporate control
According to the Cost of a Data Breach Report 2025, one in five organizations experienced a breach attributable to shadow AI, while only 37% have policies in place to manage artificial intelligence and/or identify unauthorized use.
We are therefore facing a kind of perfect storm: on the one hand, the use of AI outside corporate control processes is growing rapidly; on the other, fewer than one in two companies have defined governance rules and tools capable of addressing the phenomenon and, above all, enforcing those rules.
What is shadow AI?
Shadow AI is the use by employees of AI tools and services that are not governed by the company. It follows the same principle as shadow IT: external technologies enter work processes without going through IT controls.
In this respect, the key characteristic of AI is its extraordinary accessibility. Setting up ChatGPT, Claude or Gemini takes just a few clicks and, within certain limits, is also free. If, until yesterday, shadow IT involved sharing confidential documents on WhatsApp, using personal cloud services or independently activating SaaS applications, today a single action is enough to ask a chatbot to summarize a confidential document, analyze project materials or process data that, due to internal policies or regulatory requirements, should remain within the corporate perimeter.
The underlying behavior has not changed: the tools have changed, but the problem remains the same. Once information leaves the perimeter governed by the company, it is no longer possible to have full control over how it will be processed, stored, or potentially reused, nor can it be ruled out that the service provider itself could become involved in a data breach.
Shadow AI: here are the new risky behaviors
The potential consequences of shadow AI are fairly intuitive: data loss or breaches, financial damage, compliance issues, exposure of intellectual property, and reputational consequences.
Less obvious, and therefore more interesting, is understanding which everyday behaviors can generate these risks, considering that ChatGPT, Claude and similar tools are becoming part of an increasing number of personal and professional activities. As often happens with new technologies, adoption starts primarily among younger generations but tends to become part of the routine of the entire workforce, inevitably reducing risk perception.
The most obvious example is uploading confidential documents into a chat. Fortunately, it is also the behavior most likely to raise concerns among anyone with even a basic familiarity with digital tools. More insidious are other behaviors that risk going unnoticed:
- Entering sensitive and confidential information into prompts, such as customer names, project details, orders, and financial data;
- Pasting portions of application code to have them corrected or optimized;
- Submitting emails or internal conversations to AI for summaries and translations;
- Using AI browser extensions that access the content displayed while browsing and transcribe it into external documents (scraping);
- Using personal accounts for professional activities. Here, the risk is twofold: not only do users bypass corporate policies and controls, but they also cannot rely on the protection provided by the vendor to business accounts.
Just as with WhatsApp, with AI models too, the risk arises from how ordinary the action feels. The user does not feel they are doing anything wrong, let alone sharing confidential company information with an external party, but that is exactly what is happening.
Shadow Agent: the new IT challenge
So far, we have associated shadow AI primarily with the uncontrolled use of commercial generative AI models. This is still the most widespread and difficult risk to contain, but another phenomenon is also emerging in companies: shadow agents, meaning AI agents introduced, configured, or developed without going through IT supervision processes.
Once again, the key factor is ease of access. Today, there is no need to launch a software project to deploy an agent capable of performing relatively simple tasks such as sorting incoming emails, updating a CRM, or gathering information from multiple applications to prepare a report. SaaS services and low-code platforms make it possible to build basic agentic automations in a very short time.
It is therefore unsurprising that unauthorized agents are already becoming a problem, to the point that a 2026 study by the Cloud Security Alliance found unknown AI agents in IT at 82% of the companies surveyed, highlighting the scale of the phenomenon.
Compared with chatbots, not only the dynamics but also the scale of the risk changes. With a chatbot, the risk stems from an intentional action, because the system receives the data that a person decides to enter into the conversation; an agent, on the other hand, can act autonomously, working across email inboxes, SaaS applications, repositories, databases and other corporate systems. But where is the data stored? Who has access to it? Who is it shared with?
Shadow AI: effective strategies for containing it
Eliminating shadow AI is extremely complex and probably unrealistic. An employee can use a personal account, an unmanaged device, or a connection outside the corporate network, making part of the phenomenon invisible.
This does not mean that IT is without tools; on the contrary, it can reduce risk without compromising productivity by combining visibility, data protection, culture and access control.
- Start with discovery, while understanding its limitations
The first step is simply common sense: you need to understand which AI tools are actually present within the organization, including chatbots, browser extensions, and AI features built into SaaS applications.
Network monitoring, access and log analysis can uncover a significant portion of these uses, but not 100%, precisely because, for example, a personal account used from a smartphone over a mobile network may escape corporate visibility. Discovery should therefore not be interpreted as a definitive inventory, but as an observatory capable of highlighting patterns, widely used tools and organizational areas where the phenomenon is more intense. - Protect data at the source
With shadow AI, control needs to be applied to the data itself. Data classification and DLP (Data Loss Prevention) can prevent or limit the download, copying, sharing, and transfer of the most sensitive information, regardless of the application to which the user attempts to move it. This also makes it possible to avoid a binary approach based exclusively on allowed or forbidden.
- Focus on behaviour and awareness
No DLP system can absolutely prevent a person from reading information and manually entering it into an external service.
Awareness of risks and consequences remains essential, provided it goes beyond the usual recommendation not to share confidential information. The focus should be on gray areas in particular: Can I paste an email I received from a customer? Can I have a few lines of code corrected? Can I upload a presentation after deleting the company name?
At the same time, shadow AI can be a useful signal for the organization, because it shows which tools and features people consider most effective for speeding up their work and increasing productivity. Observing these uses therefore allows IT to identify real needs and assess the development or purchase of equivalent solutions.
- With shadow agents, control identity, privileges and capabilities
Since agents usually connect to corporate systems, this gives IT greater opportunities for detection and control. Once identified, IT can choose whether to block an agent or assess its usefulness and turn it into a governed component.
In the latter case, it is essential to assign it a specific identity, limit its privileges, precisely define which data it can access and which actions it can perform, apply logging and DLP, and introduce human approval for more sensitive activities.
Kirey: governing AI to accelerate adoption
One of our goals is to support customers on their journey toward becoming AI-first organizations. It’s an ambitious target that can generate enormous benefits, but it inevitably also introduces new areas of risk.
In this scenario, governance is a priority for Kirey: we help our customers define appropriate guardrails, protect data and systems, govern identities and privileges, but also, and above all, enable people to take full advantage of AI’s capabilities without exposing the organization to avoidable risks.
Contact us to start a journey together toward safer, more informed and better-governed AI adoption.
