AI Governance

Shadow AI

The use of unauthorized or unvetted AI tools by employees within an organization, without IT or security team knowledge or approval. Similar to shadow IT but specific to AI tools.

Why It Matters

Shadow AI creates compliance, security, and data privacy risks. Employees using ChatGPT with confidential data is the most common form.

Example

Employees pasting proprietary code, customer data, or financial projections into ChatGPT for quick analysis — without realizing the data may be used for training.

Think of it like...

Like employees using personal email for work — convenient, but creates security and compliance risks that the organization cannot manage or even see.

Related Terms