Threats & Failure Modes
Shadow AI
Shadow AI is employees using AI tools their organization hasn't approved or can't see — personal ChatGPT accounts, browser extensions, meeting bots — creating data-leakage and compliance risk outside IT's controls.
Shadow AI is the use of AI tools inside an organization without IT's approval, visibility, or controls: an associate drafting in a personal ChatGPT account, a manager's Otter bot joining client calls, a developer pasting code into a chatbot on their phone. It is the AI-era successor to shadow IT, but riskier — the data doesn't just sit in an unapproved app, it is submitted to a third party whose terms may allow retention and model training.
Blocking rarely works; employees switch to personal devices and the organization loses visibility entirely. The workable pattern is discovery plus prompt-level control: know which AI destinations are in use, redact sensitive data before it leaves, and keep a record.
Where this shows up
Related terms
See it in your own organization.
Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.