Guide · AI security
Shadow AI vs shadow IT
Shadow AI is the part of shadow IT that involves AI, in the UK NCSC's guidance and in IBM's. Most shadow IT advice still applies. AI adds three things: whether prompts may train the provider's models depends on the account used, AI features can arrive through updates to software already in use, and the output can be confidently wrong.
Last reviewed
Shadow AI is not a separate problem from shadow IT. It is the part of it that involves AI. The UK NCSC’s shadow IT guidance says shadow IT “can also include AI technologies used without permission, often referred to as shadow AI”. IBM draws the same line: shadow IT covers “any unauthorized application or service”, while shadow AI “zeros in on AI-specific tools, platforms and use cases”. So the useful question is not which one you have. It is which parts of the shadow IT playbook still work, and where AI needs something extra.
What carries over unchanged
Why people do it. The NCSC says shadow IT “is rarely the result of malicious intent”. It usually comes from employees struggling to get a task done with the approved tools or processes. One of the NCSC’s own examples of a missing capability is AI “that helps employees with administrative tasks such as rewriting documents, compiling information, or summarising meetings”.
How to respond. The NCSC’s remedies apply as written. Find the need behind the workaround and meet it with an approved tool. Make requests quick to approve. Take “a positive and no-blame approach”: if staff are blamed or punished, the NCSC says their peers “will be reluctant to tell you” what they use.
How to find it. Cloud access security brokers watch network traffic to cloud services. The NCSC says they “can help to identify use of unapproved cloud services”, and it lists unmanaged AI services, “such as chatbots”, among those services. Their blind spots carry over too, which How to detect shadow AI covers.
What AI adds
The account decides whether prompts train the model. With AI, the prompt is the data, and the provider’s terms decide what happens to it. OpenAI says that for its services for individuals, such as ChatGPT, “we may use your content to train our models”. Users can opt out for new conversations, but a conversation they give feedback on, with a thumbs up or down, “may be used to train our models” even after opting out. For its business products and API, OpenAI says “We do not train our models on your data by default”. The same site, reached from the same office, carries different terms depending on who signed in. The NCSC says a cloud access security broker cannot see “unapproved use of approved cloud services (i.e. personal accounts)” without breaking encrypted connections. Approving an AI service therefore does not end the problem. People have to be using the company’s account on it.
It can arrive through an update. OWASP’s governance checklist for large language model applications counts “third-party applications that introduce LLM features via updates or upgrades, circumventing standard software approval processes”.
The output is a risk too. An AI tool produces text, code or analysis that people then act on. IBM names “model outputs and decision-making” among the concerns that set shadow AI apart. NIST lists confabulation, “confidently stated but erroneous or false content”, as a risk of generative AI (see AI hallucination).
How much is new
The NCSC keeps AI inside its shadow IT guidance, and points to its separate guidance on the security of AI systems. Wiz, a vendor that sells AI security tools, also calls shadow AI “a newer variant of a problem security teams know well”. Wiz puts more weight on the difference. It says shadow AI “introduces different risks because of how quickly it spreads and how dynamically AI models evolve”, and that “Shadow IT skews toward technical users, while employees in every role adopt AI tools”. Its conclusion is that shadow AI needs “AI-specific controls, education, and governance rather than traditional shadow IT measures alone”. Wiz gives no source for the claim about who adopts which.
Questions and answers
Is shadow AI just shadow IT?
Mostly, yes. The UK NCSC's shadow IT guidance says shadow IT "can also include AI technologies used without permission, often referred to as shadow AI". What sets it apart is what AI does with data and output: prompts may be used to train the provider's models, AI features can arrive through updates to software already in use, and answers can be confidently wrong.
Does a company ChatGPT account stop shadow AI?
It helps, but only if people use it. OpenAI says it does not train on business accounts' data by default. On personal accounts it may train on conversations; opting out covers new conversations, but any conversation the user gives feedback on may still be used. The UK NCSC says a cloud access security broker cannot tell a personal account from an approved one on the same service without breaking encrypted connections.
Sources
- Shadow ITUK National Cyber Security Centre, 27 Jul 2023
- What is shadow AI?IBM, 25 Oct 2024
- How your data is used to improve model performanceOpenAI
- Enterprise privacy at OpenAIOpenAI, 8 Jan 2026
- LLM Applications Cybersecurity and Governance Checklist v1.1OWASP Gen AI Security Project
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)NIST, Jul 2024
- What Is Shadow AI? Risks, Governance, & How to Take ControlWiz