Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance / Shadow AI

Shadow AI: unauthorized AI use is a control failure with a long history, wearing a new name.

Shadow AI is the use of artificial intelligence tools, accounts, and features inside an organization without its knowledge, approval, or governance. It is the current form of a problem security frameworks have addressed for decades: unauthorized use of organizational systems and information. Treating it that way matters, because it means the organization already has the disciplines needed to find it and govern it. This page explains how shadow AI enters organizations, what risk it actually creates, how it is detected, and why prohibition alone fails.

The Pattern

What shadow AI looks like in practice

  • Personal accounts on consumer AI chatbots used for work
  • Free-tier AI services adopted by a team, not the organization
  • AI browser extensions installed without review
  • AI features switched on inside approved software by the vendor
  • Company data pasted into tools the organization has never examined
  • No inventory entry, no policy decision, no record
How It Enters

Shadow AI arrives through people and through products.

The employee path is the familiar one. A person under deadline discovers that a consumer AI chatbot drafts, summarizes, translates, or codes faster than they can, signs up with a personal account, and starts using it for work. Nothing about this is malicious. It is the same dynamic that produced shadow IT a decade earlier: the sanctioned tools are slower than the unsanctioned ones, and the work has to get done. The organization's data begins flowing to a service it has never evaluated, under consumer terms it has never read, through an account it cannot see, suspend, or audit.

The product path is quieter and now arguably larger. Vendors are adding AI features to software organizations already run: the office suite gains an assistant, the CRM gains generative drafting, the meeting platform gains transcription and summarization, often enabled by default in a routine update. No employee decided anything, and no procurement review occurred, because nothing was procured. The organization's AI footprint grew through a version number. This embedded path is why an AI use inventory built from a purchasing list is always wrong, and why the inventory work described on the AI governance overview starts from the environment rather than the contracts.

Both paths share the defining feature: the use exists, and the governance does not. There is no inventory entry, no policy decision about whether the use is acceptable, no examination of where the data goes, and no record that any of these questions were ever asked.

What Is Actually at Risk

Four consequences, in descending order of visibility.

Shadow AI commentary tends to stop at data leakage. The fuller picture includes what the leakage does to the organization's obligations and its compliance record, which is where the durable damage occurs.

01

Data leaves the governed boundary

Content pasted into an unapproved tool leaves the environment the organization controls and enters one it has never examined. Depending on the service and account tier, that content may be retained, reviewed, or used to train models under terms no one at the organization has read. Proprietary designs, customer information, personnel matters, and pricing all travel this path.

02

Regulated data carries its obligations with it

Controlled Unclassified Information, personal information, and data held under contractual confidentiality do not shed their obligations when they enter a chatbot. For a defense contractor, CUI reaching an unapproved AI service is a safeguarding failure under NIST SP 800-171 and DFARS 252.204-7012, with the tool and its vendor suddenly relevant to the assessment boundary. The same structure applies to any regulated data class the organization holds.

03

The compliance record quietly becomes inaccurate

The organization's representations, an SPRS score, a System Security Plan, cyber insurance application answers, customer security questionnaires, all describe a boundary and a set of controls. Shadow AI redraws the boundary without updating the record. The representation was accurate when made and is inaccurate now, which is the exact failure mode that turns a compliance gap into a liability question.

04

Decisions inherit ungoverned outputs

Work produced with unapproved AI enters documents, code, analyses, and customer communications with no human oversight requirement attached, no accuracy check defined, and no record of AI involvement. When an error surfaces later, the organization cannot reconstruct how the content was produced, because officially it was never produced that way at all.

The control lineage here is direct. NIST SP 800-171 requirement 3.14.7 obligates organizations to identify unauthorized use of organizational systems, and this practice has published control-level analysis of that requirement in its CMMC controls library. Shadow AI is that requirement's newest subject, not a new discipline. An organization that can detect unauthorized software use can detect unauthorized AI use with the same machinery.
Detection

Finding shadow AI with disciplines the organization already has.

01 Network and DNS records

Traffic to AI service domains is visible in web filtering, DNS, and firewall logs the organization already keeps. The question is rarely whether the evidence exists; it is whether anyone has been asked to look for this category of destination.

02 Identity and SaaS discovery

OAuth grants, single sign-on logs, and SaaS discovery tooling reveal AI services connected to organizational accounts, and browser extension inventories reveal AI tools riding inside the browser. Each finding is an inventory entry waiting to be made.

03 Vendor change review

Embedded AI arrives in release notes and administrative consoles. A standing review of vendor AI feature announcements, and of the admin settings that enable them, catches the product path that network monitoring alone misses.

04 Asking people directly

Interviews and anonymous surveys surface more shadow AI than any log, because people will describe what they use when the question is framed as inventory rather than enforcement. This is the same finding that onsite assessment work produces across every framework this practice supports: the people who run the operation know how it actually runs.

Detection without a destination creates a standoff: the organization learns what people use and has nothing to offer them instead. That is why detection and policy ship together.
The Response

Why prohibition alone fails, and what works instead.

A blanket ban is the instinctive response and the weakest one. Shadow AI exists precisely where rules and reality have diverged; adding a stricter rule widens the divergence and pushes the use further from view, onto personal devices and home networks where no organizational control reaches. The employees most likely to comply with a ban are the ones who were least likely to create risk, and the productivity motive that created the behavior remains fully intact.

The durable response has three parts, and they arrive together. First, an AI use policy that makes real decisions: which uses are permitted, which are prohibited, which require approval, and what data may never enter an AI tool under any tier of approval. Second, an approved path, meaning sanctioned tools under organizational accounts and terms, so that the benefit employees were seeking exists inside the boundary rather than outside it. Third, monitoring that treats remaining unauthorized use as the detectable control failure it is, feeding the same inventory and the same records that the rest of the AI governance program maintains. The NIST AI RMF locates this work in its Govern function, and ISO/IEC 42001 addresses it through its policy, resource, and responsible use objectives, so the shadow AI response is not a side project: it is the entry point into the governance program itself.

Common Questions

Shadow AI, answered briefly.

What is shadow AI?

Shadow AI is the use of AI tools, accounts, or features inside an organization without its knowledge, approval, or governance: personal chatbot accounts used for work, unapproved AI extensions and free-tier services, and AI features vendors enable inside software already in service.

Is shadow AI different from shadow IT?

It is the same organizational pattern with a sharper edge. Shadow IT moved work into unapproved applications; shadow AI additionally moves the organization's information into systems that may retain it, learn from it, and generate output from it, which raises the stakes for regulated data and for the accuracy of the organization's compliance record.

Should we just ban AI tools?

Prohibition alone pushes the behavior out of sight without removing the motive. The response that holds is a policy with real decisions in it, an approved path that delivers the benefit inside the boundary, and monitoring for what remains. The AI use policy page describes what those decisions look like.

Why does this matter for a defense contractor specifically?

Because CUI reaching an unapproved AI service is a safeguarding failure under NIST SP 800-171 and DFARS 252.204-7012, and because requirement 3.14.7 already obligates the contractor to identify unauthorized use of its systems. Shadow AI sits squarely inside obligations the contractor has certified against, which makes it a compliance accuracy problem and not merely a productivity debate.

Get In Touch

Discuss Your Organization's AI Boundary

Inquiries may involve establishing an AI use inventory, examining where shadow AI intersects regulated data and existing compliance representations, or building the policy and approved path that bring the use inside governance. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

Whether the question is what AI is actually in use across your organization, what that use means for the representations you have already made, or how to bring it under a working policy, the first conversation carries no commitment and no pitch.

Discuss an Assessment →