← Glossary

Shadow AI

Shadow AI is the use of AI tools, models or AI-powered integrations inside an organization without IT or security team approval.

Updated

Shadow AI is the use of artificial intelligence tools, models or AI-powered integrations inside an organization without the knowledge, approval or oversight of the IT or security team. It is the AI-specific successor to shadow IT, and it spreads faster because most AI tools are free, browser-based and one OAuth click away from company data.

Key facts

  • Over one third (38%) of employees admit to sharing sensitive work information with AI tools without their employer's permission (National Cybersecurity Alliance / CybSafe research, as cited by IBM).
  • According to industry research, roughly one in five UK companies has experienced data leakage linked to employees using generative AI.
  • Shadow AI includes more than chatbots: AI meeting notetakers, browser extensions and email assistants connected via OAuth are the fastest-growing categories.
  • Under the EU AI Act and GDPR, an organization remains responsible for personal data processed by AI tools its employees use, sanctioned or not.

Shadow AI vs. shadow IT

Shadow ITShadow AI
What it isUnapproved apps, devices and cloud servicesUnapproved AI tools, models and AI-powered integrations
Main riskUnmanaged data, unpatched software, licensingSensitive data in prompts, training on your data, agents acting with real permissions
Data flowData stored somewhere IT cannot seeData leaves in prompts, often retained and reused
How it entersSign-ups, personal devices, browser extensionsFree tiers, OAuth grants, AI features switched on inside approved apps
DiscoveryApp inventory, network and SaaS discoveryOAuth grant review, prompt and integration monitoring
GovernanceApprove, replace or blockApprove, set data-handling rules, revoke grants

Real examples of shadow AI

Generative AI chatbots

Employees paste customer lists, contracts, source code or financial data into ChatGPT, Claude, Gemini or free lookalike tools to summarize, translate or debug. If the tool retains inputs or uses them for training, that data has left your control permanently.

AI meeting notetakers

Bots from transcription services join video calls after a single employee connects a calendar. Every participant's words are recorded and processed by a third party nobody vetted.

AI email assistants connected via OAuth

Writing assistants, schedulers and "inbox copilots" ask for Google Workspace or Microsoft 365 permissions. One click can grant a third-party AI full read access to an entire mailbox, including confidential threads, invoices and password reset emails. This is the least visible and highest-risk category, because the access persists silently even after the employee stops using the tool.

AI browser extensions

Extensions that summarize pages or draft replies can read everything rendered in the browser, including internal web apps and webmail.

Embedded AI features

Approved SaaS tools quietly ship new AI features that send data to subprocessors the original security review never covered.

Autonomous AI agents

Employees experiment with agents that browse, click and act on their behalf using their real credentials and sessions, creating actions no policy anticipated.

Why employees use shadow AI

Shadow AI is rarely malicious. Employees adopt AI tools because they work: drafts get written faster, meetings summarize themselves, code gets reviewed instantly. When the sanctioned toolset offers no AI capability, or approval takes weeks, employees route around it. Any response that relies on banning AI outright tends to push usage further underground rather than reduce it.

The risks of shadow AI

Data leakage into models

Sensitive input can be retained by the provider, exposed through provider breaches, or in some cases used to train future models. Unlike a misplaced file, data absorbed by a model cannot be recalled.

Persistent OAuth access

AI tools granted mailbox, drive or calendar scopes keep that access until it is explicitly revoked. Abandoned grants accumulate into an invisible attack surface, and a breach at any of those AI vendors becomes a breach of your data.

Compliance exposure

GDPR obligations follow personal data into whatever AI tool an employee chose. The EU AI Act adds requirements on transparency and human oversight for AI use in areas like HR and finance. Regulators will not accept "we did not know the tool was in use" as a defense.

New attack paths

Attackers register lookalike AI apps and use OAuth consent phishing to trick employees into granting mailbox access, a technique increasingly seen alongside business email compromise and credential phishing. Malicious or compromised AI browser extensions carry the same risk.

No audit trail

When work happens inside unsanctioned AI tools, security teams cannot investigate incidents, respond to data subject requests or prove compliance.

How to detect shadow AI in Google Workspace and Microsoft 365

Most shadow AI touches the corporate email or identity layer, which makes it detectable:

  • Audit OAuth grants. In Google Admin (Security > API controls > App access control) or Microsoft Entra (Enterprise applications), list every third-party app with granted scopes. Sort by mail, drive and calendar scopes. Flag AI tools nobody approved.
  • Search inbound welcome emails. New signups leave a trail: welcome and verification emails from AI services arriving in employee inboxes reveal adoption within minutes of it happening.
  • Review calendar and meeting logs for recurring third-party notetaker bots.
  • Check the browser extension inventory via your managed browser policy, if you have one.
  • Repeat continuously. A quarterly audit misses tools adopted and abandoned between audits. The OAuth grant, however, stays.

Reduce the risk without banning AI

An outright ban fails in practice. Instead: publish a short, clear AI usage policy that names approved tools and forbidden data types. Provide a sanctioned AI option so employees do not need workarounds. Require review before any tool receives OAuth scopes on company accounts. Revoke unused grants on a schedule. Train employees on what must never be pasted into a public model.

How Sentaro sees shadow AI

Because nearly every AI tool announces itself in email (welcome messages, verification links, billing receipts) and the riskiest ones connect through OAuth, the mailbox is where shadow AI becomes visible first. Sentaro's App and Message Defense vectors monitor exactly these signals in Google Workspace and Microsoft 365: new AI service signups, new OAuth grants and consent phishing attempts disguised as AI apps, so security teams see AI adoption as it happens instead of months later.

See every AI integration touching your inbox

Sentaro deploys on Google Workspace and Microsoft 365 in minutes and shows you every app, AI tool and OAuth grant in your email environment.

Get a demo

Questions we get asked.

Is using ChatGPT at work shadow AI?

Only if it is used without IT approval. If your organization has sanctioned ChatGPT (for example through an enterprise agreement with data controls), it is approved AI. The same tool pasted company data into from a personal account without approval is shadow AI.

What is the difference between shadow AI and shadow IT?

Shadow IT covers any unsanctioned technology. Shadow AI is the subset involving AI tools and integrations. It carries additional risks because AI tools ingest data as prompts, may retain or train on that data, and often gain broad access through OAuth permissions.

Is shadow AI illegal?

Using an unsanctioned AI tool is not illegal in itself, but it can put the organization in breach of GDPR, the EU AI Act, industry regulations or customer contracts if personal or confidential data is processed without proper controls.

How common is shadow AI?

Very. Over a third of employees admit to sharing sensitive work information with AI tools without permission, and adoption keeps rising because most tools are free and require no installation.

How do I detect shadow AI in my organization?

Start where the evidence is: audit third-party OAuth grants in Google Workspace or Microsoft 365, monitor inbound welcome emails from AI services, and review meeting logs for notetaker bots. Continuous monitoring of the email and identity layer catches new tools within minutes of signup.

Should companies ban AI tools completely?

Bans push usage underground where it cannot be monitored. A better approach is a clear AI policy, sanctioned alternatives, mandatory review before OAuth access is granted, and continuous detection of new AI signups.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.