[{"data":1,"prerenderedAt":168},["ShallowReactive",2],{"glossary:shadow-ai":3},{"term":4,"published":151,"modified":151,"mentions":152,"related":162},{"slug":5,"title":6,"lede":7,"blocks":8,"faqs":132},"shadow-ai","Shadow AI","Shadow AI is the use of AI tools, models or AI-powered integrations inside an organization without IT or security team approval.",[9,12,15,22,24,54,56,59,61,63,65,67,69,71,73,75,77,79,81,83,85,87,89,91,93,95,97,99,101,103,105,107,109,111,118,120,122,124,126,128,130],{"t":10,"text":11},"p","Shadow AI is the use of artificial intelligence tools, models or AI-powered integrations inside an organization without the knowledge, approval or oversight of the IT or security team. It is the AI-specific successor to shadow IT, and it spreads faster because most AI tools are free, browser-based and one OAuth click away from company data.",{"t":13,"text":14},"h2","Key facts",{"t":16,"items":17},"ul",[18,19,20,21],"Over one third (38%) of employees admit to sharing sensitive work information with AI tools without their employer's permission (National Cybersecurity Alliance \u002F CybSafe research, as cited by IBM).","According to industry research, roughly one in five UK companies has experienced data leakage linked to employees using generative AI.","Shadow AI includes more than chatbots: AI meeting notetakers, browser extensions and email assistants connected via OAuth are the fastest-growing categories.","Under the EU AI Act and GDPR, an organization remains responsible for personal data processed by AI tools its employees use, sanctioned or not.",{"t":13,"text":23},"Shadow AI vs. shadow IT",{"t":25,"rows":26},"table",[27,30,34,38,42,46,50],[28,29,6],"","Shadow IT",[31,32,33],"What it is","Unapproved apps, devices and cloud services","Unapproved AI tools, models and AI-powered integrations",[35,36,37],"Main risk","Unmanaged data, unpatched software, licensing","Sensitive data in prompts, training on your data, agents acting with real permissions",[39,40,41],"Data flow","Data stored somewhere IT cannot see","Data leaves in prompts, often retained and reused",[43,44,45],"How it enters","Sign-ups, personal devices, browser extensions","Free tiers, OAuth grants, AI features switched on inside approved apps",[47,48,49],"Discovery","App inventory, network and SaaS discovery","OAuth grant review, prompt and integration monitoring",[51,52,53],"Governance","Approve, replace or block","Approve, set data-handling rules, revoke grants",{"t":13,"text":55},"Real examples of shadow AI",{"t":57,"text":58},"h3","Generative AI chatbots",{"t":10,"text":60},"Employees paste customer lists, contracts, source code or financial data into ChatGPT, Claude, Gemini or free lookalike tools to summarize, translate or debug. If the tool retains inputs or uses them for training, that data has left your control permanently.",{"t":57,"text":62},"AI meeting notetakers",{"t":10,"text":64},"Bots from transcription services join video calls after a single employee connects a calendar. Every participant's words are recorded and processed by a third party nobody vetted.",{"t":57,"text":66},"AI email assistants connected via OAuth",{"t":10,"text":68},"Writing assistants, schedulers and \"inbox copilots\" ask for Google Workspace or Microsoft 365 permissions. One click can grant a third-party AI full read access to an entire mailbox, including confidential threads, invoices and password reset emails. This is the least visible and highest-risk category, because the access persists silently even after the employee stops using the tool.",{"t":57,"text":70},"AI browser extensions",{"t":10,"text":72},"Extensions that summarize pages or draft replies can read everything rendered in the browser, including internal web apps and webmail.",{"t":57,"text":74},"Embedded AI features",{"t":10,"text":76},"Approved SaaS tools quietly ship new AI features that send data to subprocessors the original security review never covered.",{"t":57,"text":78},"Autonomous AI agents",{"t":10,"text":80},"Employees experiment with agents that browse, click and act on their behalf using their real credentials and sessions, creating actions no policy anticipated.",{"t":13,"text":82},"Why employees use shadow AI",{"t":10,"text":84},"Shadow AI is rarely malicious. Employees adopt AI tools because they work: drafts get written faster, meetings summarize themselves, code gets reviewed instantly. When the sanctioned toolset offers no AI capability, or approval takes weeks, employees route around it. Any response that relies on banning AI outright tends to push usage further underground rather than reduce it.",{"t":13,"text":86},"The risks of shadow AI",{"t":57,"text":88},"Data leakage into models",{"t":10,"text":90},"Sensitive input can be retained by the provider, exposed through provider breaches, or in some cases used to train future models. Unlike a misplaced file, data absorbed by a model cannot be recalled.",{"t":57,"text":92},"Persistent OAuth access",{"t":10,"text":94},"AI tools granted mailbox, drive or calendar scopes keep that access until it is explicitly revoked. Abandoned grants accumulate into an invisible attack surface, and a breach at any of those AI vendors becomes a breach of your data.",{"t":57,"text":96},"Compliance exposure",{"t":10,"text":98},"GDPR obligations follow personal data into whatever AI tool an employee chose. The EU AI Act adds requirements on transparency and human oversight for AI use in areas like HR and finance. Regulators will not accept \"we did not know the tool was in use\" as a defense.",{"t":57,"text":100},"New attack paths",{"t":10,"text":102},"Attackers register lookalike AI apps and use OAuth consent phishing to trick employees into granting mailbox access, a technique increasingly seen alongside business email compromise and credential phishing. Malicious or compromised AI browser extensions carry the same risk.",{"t":57,"text":104},"No audit trail",{"t":10,"text":106},"When work happens inside unsanctioned AI tools, security teams cannot investigate incidents, respond to data subject requests or prove compliance.",{"t":13,"text":108},"How to detect shadow AI in Google Workspace and Microsoft 365",{"t":10,"text":110},"Most shadow AI touches the corporate email or identity layer, which makes it detectable:",{"t":16,"items":112},[113,114,115,116,117],"Audit OAuth grants. In Google Admin (Security > API controls > App access control) or Microsoft Entra (Enterprise applications), list every third-party app with granted scopes. Sort by mail, drive and calendar scopes. Flag AI tools nobody approved.","Search inbound welcome emails. New signups leave a trail: welcome and verification emails from AI services arriving in employee inboxes reveal adoption within minutes of it happening.","Review calendar and meeting logs for recurring third-party notetaker bots.","Check the browser extension inventory via your managed browser policy, if you have one.","Repeat continuously. A quarterly audit misses tools adopted and abandoned between audits. The OAuth grant, however, stays.",{"t":13,"text":119},"Reduce the risk without banning AI",{"t":10,"text":121},"An outright ban fails in practice. Instead: publish a short, clear AI usage policy that names approved tools and forbidden data types. Provide a sanctioned AI option so employees do not need workarounds. Require review before any tool receives OAuth scopes on company accounts. Revoke unused grants on a schedule. Train employees on what must never be pasted into a public model.",{"t":13,"text":123},"How Sentaro sees shadow AI",{"t":10,"text":125},"Because nearly every AI tool announces itself in email (welcome messages, verification links, billing receipts) and the riskiest ones connect through OAuth, the mailbox is where shadow AI becomes visible first. Sentaro's App and Message Defense vectors monitor exactly these signals in Google Workspace and Microsoft 365: new AI service signups, new OAuth grants and consent phishing attempts disguised as AI apps, so security teams see AI adoption as it happens instead of months later.",{"t":13,"text":127},"See every AI integration touching your inbox",{"t":10,"text":129},"Sentaro deploys on Google Workspace and Microsoft 365 in minutes and shows you every app, AI tool and OAuth grant in your email environment.",{"t":10,"text":131},"Get a demo",[133,136,139,142,145,148],{"q":134,"a":135},"Is using ChatGPT at work shadow AI?","Only if it is used without IT approval. If your organization has sanctioned ChatGPT (for example through an enterprise agreement with data controls), it is approved AI. The same tool pasted company data into from a personal account without approval is shadow AI.",{"q":137,"a":138},"What is the difference between shadow AI and shadow IT?","Shadow IT covers any unsanctioned technology. Shadow AI is the subset involving AI tools and integrations. It carries additional risks because AI tools ingest data as prompts, may retain or train on that data, and often gain broad access through OAuth permissions.",{"q":140,"a":141},"Is shadow AI illegal?","Using an unsanctioned AI tool is not illegal in itself, but it can put the organization in breach of GDPR, the EU AI Act, industry regulations or customer contracts if personal or confidential data is processed without proper controls.",{"q":143,"a":144},"How common is shadow AI?","Very. Over a third of employees admit to sharing sensitive work information with AI tools without permission, and adoption keeps rising because most tools are free and require no installation.",{"q":146,"a":147},"How do I detect shadow AI in my organization?","Start where the evidence is: audit third-party OAuth grants in Google Workspace or Microsoft 365, monitor inbound welcome emails from AI services, and review meeting logs for notetaker bots. Continuous monitoring of the email and identity layer catches new tools within minutes of signup.",{"q":149,"a":150},"Should companies ban AI tools completely?","Bans push usage underground where it cannot be monitored. A better approach is a clear AI policy, sanctioned alternatives, mandatory review before OAuth access is granted, and continuous detection of new AI signups.","2026-09-08",[153,154,155,156,157,158,159,160,161],"account-takeover","business-email-compromise","consent-phishing","eu-ai-act","gdpr","integrated-cloud-email-security","phishing","shadow-it","vendor-email-compromise",[156,160,157,163,164,165,166,167],"ai-jailbreaking","iso-42001","agentic-ai-security","ai-native","prompt-injection",1789658069711]