Shadow AI
Shadow AI is the use of AI tools and services by employees without the knowledge, approval, or governance of IT and security teams. It is the AI-era extension of shadow IT: unauthorized technology adoption that creates unmanaged risk.
Why It Matters
Shadow AI is not driven by malice. Employees adopt AI tools because they make work faster. A developer connects Cursor to their company's codebase. A marketer uses ChatGPT with customer data. A sales rep connects an AI agent to the CRM. Each individual is solving a real problem.
The governance gap is collective. Each shadow AI deployment creates an unmonitored access path between an AI system and company data. The organization has no audit trail, no policy enforcement, and no visibility into what data the AI is accessing or what actions it is taking.
For many organizations, shadow AI is the primary driver of AI agent governance adoption. The threat model is internal (employees setting up agents without permission), not external (attackers breaching the network).