What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

Shadow AI

Shadow AI is the use of AI tools, models or AI features inside an organization without the approval or oversight of the people responsible for its IT and security. A common example, in IBM's account, is an employee using a generative AI app such as ChatGPT for work tasks without the IT team knowing it is in use.

Last reviewed

Key points

  • Shadow AI is shadow IT, meaning software used without IT's approval, narrowed to AI. The tool may be harmless; the risk is that nobody responsible for security oversees it.
  • It is not only chatbots. OWASP also lists unsafe browser plugins and third-party applications that add AI features in an update, outside normal software approval.
  • IBM lists data leakage first among the risks, alongside compliance fines and reputational damage. In IBM's 2025 study of 600 breached organizations, one in five reported a breach due to shadow AI.
  • IBM says eliminating every instance may not be feasible. Its advice mixes approved tools and blocked platforms, a governance framework, monitoring of usage, and regular reminders of the risks.

How it arrives

One route is an employee choosing a tool. IBM’s example is someone using a generative AI app such as ChatGPT for text editing or data analysis without IT knowing. Microsoft and LinkedIn’s 2024 survey of 31,000 knowledge workers found 78% of AI users bring their own AI tools to work. That counts tools the employer did not provide, which is not quite the same as tools it forbade.

OWASP’s list is wider than chatbots. It adds “unsafe browser plugins” and third-party applications that gain large language model features through an update, all of which get around the organization’s normal software approval.

Why it matters

The risk IBM names first is data leakage. A prompt sent to an outside AI service takes whatever was pasted into it, and when the tool is unsanctioned, nobody responsible for that data oversees where it went. IBM also lists compliance fines and reputational damage. OWASP ranks shadow AI, for many organizations, as the most pressing risk from language models that does not involve an attacker.

IBM and Ponemon’s 2025 Cost of a Data Breach study measured it for the first time. Of 600 organizations that had a breach, one in five reported a breach due to shadow AI. Those with high levels of shadow AI paid on average $670,000 more per breach than those with little or none. Only 37% had policies to manage AI or detect shadow AI.

In practice

IBM says eliminating every instance of shadow AI “might not be feasible”. Its advice mixes guardrails, such as approved tools, sandboxes and “firewalls to block unauthorized external platforms”, with a governance framework, monitoring of which applications are used, and regular reminders to staff of the risks.

Wiz, which sells AI security posture management (AI-SPM), looks at the development side. It recommends automated discovery of AI assets in the cloud to “stay ahead of shadow AI”. Citing “AWS AI security guidance and broader industry best practices”, it says shadow AI is hardest to eliminate when developers have easy access to unsanctioned tools “and no clear path to approved alternatives”.

Questions and answers

What is the difference between shadow AI and shadow IT?

Shadow IT is any software, hardware or service used without IT's approval, such as a personal cloud storage account. Shadow AI is the same problem limited to AI tools, models and features. IBM singles it out because AI adds its own concerns about what data goes in and how the outputs are used in decisions.

Is using ChatGPT at work shadow AI?

It is when the organization has not approved it or has no oversight of it. An employee using ChatGPT for work without IT's approval or oversight is IBM's own example of shadow AI. The same tool used through an account the organization approved and oversees is not.

Sources

  1. What is shadow AI?IBM
  2. LLM Applications Cybersecurity and Governance Checklist v1.1OWASP Gen AI Security Project
  3. IBM Report: 13% Of Organizations Reported Breaches Of AI Models Or Applications, 97% Of Which Reported Lacking Proper AI Access ControlsIBM, 30 Jul 2025
  4. AI at Work Is Here. Now Comes the Hard PartMicrosoft, 8 May 2024
  5. AI Security Posture Management (AI-SPM): How It WorksWiz

Guides that use this term