Shadow AI is the use of artificial intelligence tools, models or AI-powered integrations inside an organization without the knowledge, approval or oversight of the IT or security team. It is the AI-specific successor to shadow IT, and it spreads faster because most AI tools are free, browser-based and one OAuth click away from company data.
Key facts
- Over one third (38%) of employees admit to sharing sensitive work information with AI tools without their employer's permission (National Cybersecurity Alliance / CybSafe research, as cited by IBM).
- According to industry research, roughly one in five UK companies has experienced data leakage linked to employees using generative AI.
- Shadow AI includes more than chatbots: AI meeting notetakers, browser extensions and email assistants connected via OAuth are the fastest-growing categories.
- Under the EU AI Act and GDPR, an organization remains responsible for personal data processed by AI tools its employees use, sanctioned or not.
Shadow AI vs. shadow IT
| Shadow IT | Shadow AI | |
|---|---|---|
| What it is | Unapproved apps, devices and cloud services | Unapproved AI tools, models and AI-powered integrations |
| Main risk | Unmanaged data, unpatched software, licensing | Sensitive data in prompts, training on your data, agents acting with real permissions |
| Data flow | Data stored somewhere IT cannot see | Data leaves in prompts, often retained and reused |
| How it enters | Sign-ups, personal devices, browser extensions | Free tiers, OAuth grants, AI features switched on inside approved apps |
| Discovery | App inventory, network and SaaS discovery | OAuth grant review, prompt and integration monitoring |
| Governance | Approve, replace or block | Approve, set data-handling rules, revoke grants |
Real examples of shadow AI
Generative AI chatbots
Employees paste customer lists, contracts, source code or financial data into ChatGPT, Claude, Gemini or free lookalike tools to summarize, translate or debug. If the tool retains inputs or uses them for training, that data has left your control permanently.
AI meeting notetakers
Bots from transcription services join video calls after a single employee connects a calendar. Every participant's words are recorded and processed by a third party nobody vetted.
AI email assistants connected via OAuth
Writing assistants, schedulers and "inbox copilots" ask for Google Workspace or Microsoft 365 permissions. One click can grant a third-party AI full read access to an entire mailbox, including confidential threads, invoices and password reset emails. This is the least visible and highest-risk category, because the access persists silently even after the employee stops using the tool.
AI browser extensions
Extensions that summarize pages or draft replies can read everything rendered in the browser, including internal web apps and webmail.
Embedded AI features
Approved SaaS tools quietly ship new AI features that send data to subprocessors the original security review never covered.
Autonomous AI agents
Employees experiment with agents that browse, click and act on their behalf using their real credentials and sessions, creating actions no policy anticipated.
Why employees use shadow AI
Shadow AI is rarely malicious. Employees adopt AI tools because they work: drafts get written faster, meetings summarize themselves, code gets reviewed instantly. When the sanctioned toolset offers no AI capability, or approval takes weeks, employees route around it. Any response that relies on banning AI outright tends to push usage further underground rather than reduce it.
The risks of shadow AI
Data leakage into models
Sensitive input can be retained by the provider, exposed through provider breaches, or in some cases used to train future models. Unlike a misplaced file, data absorbed by a model cannot be recalled.
Persistent OAuth access
AI tools granted mailbox, drive or calendar scopes keep that access until it is explicitly revoked. Abandoned grants accumulate into an invisible attack surface, and a breach at any of those AI vendors becomes a breach of your data.
Compliance exposure
GDPR obligations follow personal data into whatever AI tool an employee chose. The EU AI Act adds requirements on transparency and human oversight for AI use in areas like HR and finance. Regulators will not accept "we did not know the tool was in use" as a defense.
New attack paths
Attackers register lookalike AI apps and use OAuth consent phishing to trick employees into granting mailbox access, a technique increasingly seen alongside business email compromise and credential phishing. Malicious or compromised AI browser extensions carry the same risk.
No audit trail
When work happens inside unsanctioned AI tools, security teams cannot investigate incidents, respond to data subject requests or prove compliance.
How to detect shadow AI in Google Workspace and Microsoft 365
Most shadow AI touches the corporate email or identity layer, which makes it detectable:
- Audit OAuth grants. In Google Admin (Security > API controls > App access control) or Microsoft Entra (Enterprise applications), list every third-party app with granted scopes. Sort by mail, drive and calendar scopes. Flag AI tools nobody approved.
- Search inbound welcome emails. New signups leave a trail: welcome and verification emails from AI services arriving in employee inboxes reveal adoption within minutes of it happening.
- Review calendar and meeting logs for recurring third-party notetaker bots.
- Check the browser extension inventory via your managed browser policy, if you have one.
- Repeat continuously. A quarterly audit misses tools adopted and abandoned between audits. The OAuth grant, however, stays.
Reduce the risk without banning AI
An outright ban fails in practice. Instead: publish a short, clear AI usage policy that names approved tools and forbidden data types. Provide a sanctioned AI option so employees do not need workarounds. Require review before any tool receives OAuth scopes on company accounts. Revoke unused grants on a schedule. Train employees on what must never be pasted into a public model.
How Sentaro sees shadow AI
Because nearly every AI tool announces itself in email (welcome messages, verification links, billing receipts) and the riskiest ones connect through OAuth, the mailbox is where shadow AI becomes visible first. Sentaro's App and Message Defense vectors monitor exactly these signals in Google Workspace and Microsoft 365: new AI service signups, new OAuth grants and consent phishing attempts disguised as AI apps, so security teams see AI adoption as it happens instead of months later.
See every AI integration touching your inbox
Sentaro deploys on Google Workspace and Microsoft 365 in minutes and shows you every app, AI tool and OAuth grant in your email environment.
Get a demo