Shadow IT
Shadow IT is the use of information technology systems, devices, software, applications, and services without explicit approval from the IT department. It includes unauthorized SaaS subscriptions, personal devices connected to corporate networks, and unsanctioned cloud services.
Why It Matters
Shadow IT has been a security concern since employees first started signing up for SaaS tools with their corporate email. Browser extensions, freemium SaaS apps, and personal cloud storage are common vectors.
Shadow AI and shadow MCP are the current evolution of shadow IT. The underlying pattern is the same: employees adopt tools that make them productive, without going through procurement or security review. What changes is the blast radius: a shadow SaaS app holds data; a shadow AI agent actively accesses and manipulates data across multiple systems.
Governance approaches that make approved tools easier to use than unauthorized alternatives are more effective than detection-and-block strategies. If the sanctioned path is frictionless, shadow IT loses its appeal.