Every organization now runs two AI programs: the one it chose, and the one its staff chose for it. The second one is shadow AI, and this page defines it precisely enough to act on.
Shadow AI is the use of AI tools, features or services inside an organization without the knowledge, approval or oversight of whoever is accountable for technology and data decisions.
Working definition used throughout this site. The operative words are "without oversight", not "forbidden": most shadow AI violates no explicit rule, because no rule exists yet.The pattern is inherited: staff adopt tools faster than organizations approve them. Three things changed when the tools became AI.
Shadow IT spread tool by tool over years. A useful AI tool spreads through a team in days, because trying it costs one browser tab and zero dollars.
A rogue Dropbox stored your files; the deal was legible. Many AI tools are paid in prompts: our analysis counts 700+ tools that train on customer data by default, and 85.5% whose public terms say nothing about training either way.
Shadow IT was separate apps you could name. Shadow AI is also a setting inside apps you already sanctioned: the assistant tab that appeared in your CRM one Tuesday.
The full playbook comparison, what carries over from shadow IT management and what breaks, has its own page: shadow AI vs shadow IT.
Nobody plans a shadow AI problem. Four structural gaps produce it automatically.
Every shadow AI finding in an audit entered through one of three doors. Each door has a distinct signature in network logs.
Staff use consumer AI under private logins: the personal chatbot subscription, the transcription app on a private phone, the image tool from a side project.
Riskiest door, because consumer tiers carry the weakest terms and the organization has zero contractual standing.
Log signature: consumer domains under corporate network identities, evenings and deadline spikes included.
Teams adopt the free plan of a business tool: the summarizer, the meeting bot, the code assistant, intending to "upgrade if it sticks".
Free tiers are where training-by-default clauses concentrate, and the upgrade that would fix the terms rarely happens.
Log signature: steady team-shaped clusters of use on one tool, often via app and API subdomains.
AI arrives inside software already approved: the CRM's assistant, the design suite's generator, the video platform's summary bot.
Nobody chose it, so nobody reviewed it. Procurement's original assessment predates the feature entirely.
Log signature: ai., copilot. and assistant. subdomains of vendors on your own approved list.
Door 3 is the one surveys never find, because users honestly do not consider it "using an AI tool". Log evidence does not depend on anyone's framing: the methodology page explains why.
From our register and terms research, the measurable backdrop that makes shadow AI a standing condition rather than a passing story.
A sanctioned list can hold twenty tools. The market holds tens of thousands. The gap between those numbers is the space shadow AI lives in.
When most terms answer nothing, "check the terms" fails as staff-level advice. Verdict-tracking at register scale is the workable substitute.
Tools launch, rebrand and change terms continuously. A quarterly-updated list mislabels the present; more numbers live on the statistics page.
Compressed from patterns we see across audits: the arc from discovery to policy, in five stages.
Someone under pressure finds a tool that helps. It works, so they keep it, telling nobody because nobody asked.
Word of mouth spreads it sideways. Usage becomes a team habit with shared prompts and pasted templates.
Deliverables now depend on the tool. Client data, code or internal documents flow through it routinely.
An audit, an invoice, a client questionnaire or an incident surfaces the tool. This is where organizations either measure or moralize.
The tool gets an enterprise tier and joins the approved list, gets conditions, or gets blocked with an alternative offered. All three are fine; not deciding is what is not fine.
The audit is built for the discovery moment: it finds every tool at whatever lifecycle stage, with the risk context to triage them. The sequencing after discovery is covered in detect before you block.
Definitions earn their keep at the edges. Six cases that come up in every workshop:
| Case | Shadow AI? | Why |
|---|---|---|
| Personal chatbot account used for work drafts | Yes | Work content under terms the organization never saw. Door 1, classic. |
| Approved CRM's new AI assistant, in use | Yes, until reviewed | The feature postdates the approval. Oversight has not caught up with the ingredient list. |
| Sanctioned enterprise chatbot with no-training terms | No | Approved, contracted, listed. This is the goal state, not the problem. |
| Developer testing a model API on a side project, own hardware, own data | No, until work data enters | Personal experimentation is not the organization's exposure. The boundary is the data, not the curiosity. |
| Blocked tool still being reached via attempts | Yes, demand-shaped | Blocked demand predicts workarounds. It belongs in the same review as allowed usage. |
| AI feature bundled in the OS or browser | Yes, at inventory level | You may not control it, but a governance inventory that omits it is incomplete. |
Definitions orient; logs decide. The sample report shows the document that turns this page's taxonomy into your network's actual list.
The definition becomes actionable the moment it has a count attached. Three steps, no new infrastructure:
Your DNS filter, proxy or firewall recorded every AI hostname reached. The four-step walkthrough covers each source.
Totals by category, risk-flag counts and the top tools, free. That is the definition of this page, quantified for your network.
Every tool named with dated training verdicts, per-user breakdowns and a sanctioned split, from $99. The three doors become three worklists.
Uploads are read once and discarded; reports live 90 days in your account, deletable earlier.
Usually there is no rule to be against. Shadow AI is defined by missing oversight, not by broken policy, which is why the first response is measurement rather than discipline.
No. It is unpriced risk mixed with genuine productivity. Audits routinely convert shadow discoveries into the sanctioned toolset the organization should have bought earlier.
Same adoption pattern, three new properties: vertical adoption speed, data-as-payment terms, and embedding inside already-approved software. The comparison page goes deep.
Whoever is accountable for data and technology decisions generally, typically the CISO or IT leadership, with legal and department heads owning their slices. Ownerless is the failure mode.
No, and chasing zero is expensive theater. The achievable state is a measured, shrinking unsanctioned share with the risky tail blocked.
Run a log-based audit. A free preview of one month of DNS or proxy logs answers the question the definition raises.
One log export tells you which doors are open in your organization and what walked through them.
Run the free audit