Threats & Failure Modes

Shadow AI

Shadow AI is employees using AI tools their organization hasn't approved or can't see — personal ChatGPT accounts, browser extensions, meeting bots — creating data-leakage and compliance risk outside IT's controls.

Shadow AI is the use of AI tools inside an organization without IT's approval, visibility, or controls: an associate drafting in a personal ChatGPT account, a manager's Otter bot joining client calls, a developer pasting code into a chatbot on their phone. It is the AI-era successor to shadow IT, but riskier — the data doesn't just sit in an unapproved app, it is submitted to a third party whose terms may allow retention and model training.

Blocking rarely works; employees switch to personal devices and the organization loses visibility entirely. The workable pattern is discovery plus prompt-level control: know which AI destinations are in use, redact sensitive data before it leaves, and keep a record.

Where this shows up

Related terms

See it in your own organization.

Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.

Get a demo