Shadow AI

Shadow AI is the use of AI tools, models or AI-powered integrations inside an organization without IT or security team approval.

Shadow AI is the use of artificial intelligence tools, models or AI-powered integrations inside an organization without the knowledge, approval or oversight of the IT or security team. It is the AI-specific successor to shadow IT, and it spreads faster because most AI tools are free, browser-based and one OAuth click away from company data.

Key facts

Shadow AI vs. shadow IT

Shadow ITShadow AI
What it isAny unsanctioned software, hardware or serviceUnsanctioned AI tools, models and AI integrations
Typical examplesDropbox, Trello, WhatsApp, personal devicesChatGPT, AI notetakers, AI email assistants, browser copilots
Main riskUnmanaged data storage and accessCompany data used as model input, sometimes retained or used for training
How data leavesFiles uploaded or sharedPrompts, pasted content and OAuth-granted mailbox or drive access
Regulatory exposureGDPR, industry rulesGDPR plus the EU AI Act's requirements on AI use and oversight
Detection difficultyModerate: network and expense signals existHigh: most tools are free, browser-based and leave no procurement trail

Real examples of shadow AI

Generative AI chatbots

Employees paste customer lists, contracts, source code or financial data into ChatGPT, Claude, Gemini or free lookalike tools to summarize, translate or debug. If the tool retains inputs or uses them for training, that data has left your control permanently.

AI meeting notetakers

Bots from transcription services join video calls after a single employee connects a calendar. Every participant's words are recorded and processed by a third party nobody vetted.

AI email assistants connected via OAuth

Writing assistants, schedulers and "inbox copilots" ask for Google Workspace or Microsoft 365 permissions. One click can grant a third-party AI full read access to an entire mailbox, including confidential threads, invoices and password reset emails. This is the least visible and highest-risk category, because the access persists silently even after the employee stops using the tool.

AI browser extensions

Extensions that summarize pages or draft replies can read everything rendered in the browser, including internal web apps and webmail.

Embedded AI features

Approved SaaS tools quietly ship new AI features that send data to subprocessors the original security review never covered.

Autonomous AI agents

Employees experiment with agents that browse, click and act on their behalf using their real credentials and sessions, creating actions no policy anticipated.

Why employees use shadow AI

Shadow AI is rarely malicious. Employees adopt AI tools because they work: drafts get written faster, meetings summarize themselves, code gets reviewed instantly. When the sanctioned toolset offers no AI capability, or approval takes weeks, employees route around it. Any response that relies on banning AI outright tends to push usage further underground rather than reduce it.

The risks of shadow AI

Data leakage into models

Sensitive input can be retained by the provider, exposed through provider breaches, or in some cases used to train future models. Unlike a misplaced file, data absorbed by a model cannot be recalled.

Persistent OAuth access

AI tools granted mailbox, drive or calendar scopes keep that access until it is explicitly revoked. Abandoned grants accumulate into an invisible attack surface, and a breach at any of those AI vendors becomes a breach of your data.

Compliance exposure

GDPR obligations follow personal data into whatever AI tool an employee chose. The EU AI Act adds requirements on transparency and human oversight for AI use in areas like HR and finance. Regulators will not accept "we did not know the tool was in use" as a defense.

New attack paths

Attackers register lookalike AI apps and use OAuth consent phishing to trick employees into granting mailbox access, a technique increasingly seen alongside business email compromise and credential phishing. Malicious or compromised AI browser extensions carry the same risk.

No audit trail

When work happens inside unsanctioned AI tools, security teams cannot investigate incidents, respond to data subject requests or prove compliance.

How to detect shadow AI in Google Workspace and Microsoft 365

Most shadow AI touches the corporate email or identity layer, which makes it detectable:

  1. Audit OAuth grants. In Google Admin (Security > API controls > App access control) or Microsoft Entra (Enterprise applications), list every third-party app with granted scopes. Sort by mail, drive and calendar scopes. Flag AI tools nobody approved.
  2. Search inbound welcome emails. New signups leave a trail: welcome and verification emails from AI services arriving in employee inboxes reveal adoption within minutes of it happening.
  3. Review calendar and meeting logs for recurring third-party notetaker bots.
  4. Check the browser extension inventory via your managed browser policy, if you have one.
  5. Repeat continuously. A quarterly audit misses tools adopted and abandoned between audits. The OAuth grant, however, stays.

Reduce the risk without banning AI

An outright ban fails in practice. Instead: publish a short, clear AI usage policy that names approved tools and forbidden data types. Provide a sanctioned AI option so employees do not need workarounds. Require review before any tool receives OAuth scopes on company accounts. Revoke unused grants on a schedule. Train employees on what must never be pasted into a public model.

How Sentaro sees shadow AI

Because nearly every AI tool announces itself in email (welcome messages, verification links, billing receipts) and the riskiest ones connect through OAuth, the mailbox is where shadow AI becomes visible first. Sentaro's App and Domain Intelligence layers monitor exactly these signals in Google Workspace and Microsoft 365: new AI service signups, new OAuth grants and consent phishing attempts disguised as AI apps, so security teams see AI adoption as it happens instead of months later.

Frequently asked questions

Is using ChatGPT at work shadow AI?

Only if it is used without IT approval. If your organization has sanctioned ChatGPT (for example through an enterprise agreement with data controls), it is approved AI. The same tool pasted company data into from a personal account without approval is shadow AI.

What is the difference between shadow AI and shadow IT?

Shadow IT covers any unsanctioned technology. Shadow AI is the subset involving AI tools and integrations. It carries additional risks because AI tools ingest data as prompts, may retain or train on that data, and often gain broad access through OAuth permissions.

Is shadow AI illegal?

Using an unsanctioned AI tool is not illegal in itself, but it can put the organization in breach of GDPR, the EU AI Act, industry regulations or customer contracts if personal or confidential data is processed without proper controls.

How common is shadow AI?

Very. Over a third of employees admit to sharing sensitive work information with AI tools without permission, and adoption keeps rising because most tools are free and require no installation.

How do I detect shadow AI in my organization?

Start where the evidence is: audit third-party OAuth grants in Google Workspace or Microsoft 365, monitor inbound welcome emails from AI services, and review meeting logs for notetaker bots. Continuous monitoring of the email and identity layer catches new tools within minutes of signup.

Should companies ban AI tools completely?

Bans push usage underground where it cannot be monitored. A better approach is a clear AI policy, sanctioned alternatives, mandatory review before OAuth access is granted, and continuous detection of new AI signups.

See every AI integration touching your inbox

Sentaro deploys on Google Workspace and Microsoft 365 in minutes and shows you every app, AI tool and OAuth grant in your email environment.

Get a demo