Shadow AI: What it is, Why it’s a Risk, and How to Detect it

Your employees are using AI tools right now. The question is whether you know which tools they’re using, what data they’re putting into them, and what’s happening to that data once it leaves your network.

According to Microsoft’s research, 71% of UK employees have used unapproved consumer AI tools at work, with more than half doing this every week. And when a data breach is linked to shadow AI, the average additional cost is $670,000 above the cost of a standard breach.

Shadow AI isn’t about malicious employees trying to bypass your controls. It’s about people using tools that make them more productive, without understanding the compliance and security risk they’re creating in the process. Client contracts pasted into ChatGPT. Customer records uploaded to an AI summarisation tool. Internal financial data run through an unapproved model that retains everything it processes. In each case, your data has left your control, your GDPR obligations may have been breached, and you have no audit trail.

The visibility gap can be closed.

In this guide, we’ll cover what shadow AI is, why it creates real UK GDPR and security risks for UK-based organisations, where it hides in your environment, and how to build the detection and monitoring capability to start closing the gap using tools you almost certainly already have.

Key Takeaways

  • Shadow AI is the use of AI tools by employees without IT or security team knowledge or approval.
  • 71% of UK employees use unapproved AI tools at work; shadow AI breaches cost an average of $670,000 more than standard data breaches.
  • The risk isn’t limited to public LLMs like ChatGPT; AI features embedded in productivity tools create the same exposure.
  • A CASB, DLP, IAM, and SIEM form the four pillars of effective shadow AI detection.
  • Shadow AI is a direct GDPR risk: any AI tool processing personal data without a lawful basis creates regulatory exposure.
  • Start with discovery to understand what’s in use before any controls can be effective.

What is Shadow AI?

Shadow AI is the use of artificial intelligence tools by employees without the knowledge, approval, or oversight of IT and security teams. It’s the AI equivalent of shadow IT, but with a significantly higher risk profile. AI tools actively process, analyse, and often permanently retain the information inputted.

An employee using an unapproved AI tool creates an unmanaged data processing relationship with an external model that you don’t control.

How Shadow AI Differs from Shadow IT

Shadow AI creates additional data sovereignty gaps. For instance, when an employee pastes a client contract into ChatGPT, the risk is that the data may now be part of a training dataset accessible globally. Shadow AI involves unmanaged data flows to external models, which significantly increases compliance exposure and business risk.

Where Shadow AI Hides in Your Organisation

One of the most challenging aspects of shadow AI is its breadth; it appears across multiple layers of your organisation’s technology environment.

Public LLMs and Browser-Based AI Tools

The direct use of public large language models like ChatGPT and browser extensions that integrate AI capabilities creates significant exposure, especially when accessed through personal accounts not associated with your organisation.

AI Features Embedded in Sanctioned SaaS Tools

Sanctioned tools like CRM platforms may contain AI features enabled by default without IT knowledge. Employees may be using these approved tools without any assessment of the data processing implications.

Personal Devices and BYOD

Employees using personal devices present additional challenges. Data extracted from business systems can be processed through AI tools on a personal device, creating further compliance risks.

Why Shadow AI is a UK GDPR and Security Risk

Understanding the risks created by shadow AI is crucial. Shadow AI generates two main types of exposure: regulatory and security.

The GDPR Dimension

Under UK GDPR, any processing of personal data must meet specific requirements. When data is submitted to unapproved AI tools, those conditions are rarely met, exposing organisations to compliance risks.

The Security Risk Dimension

Shadow AI poses significant security risks, including data leakage through unvetted models. Browser-based AI tools can create data exfiltration channels that slip under perimeter defenses, leading to unauthorized access to sensitive information.

How to Detect Shadow AI in Your Organisation

Detection is essential for addressing shadow AI. A framework with four capability pillars can help.

Cloud Access Security Broker (CASB)

A CASB catalogues cloud application usage and risk-scores applications in the environment, including AI tools.

Data Loss Prevention (DLP)

DLP policies help monitor and control data sent to external services, enabling alerts when sensitive data is submitted to AI tools.

Identity and Access Management (IAM)

IAM detects sign-ins to unapproved services, providing logs of external service authentications using corporate credentials.

SIEM and SOC Analytics

SIEM platforms can be configured with custom rules to monitor AI usage patterns, detecting anomalies through DNS requests and OAuth events.

Building a Three-Phase Shadow AI Detection Programme

A phased approach helps build shadow AI visibility iteratively; each phase adds value while laying the groundwork for the next.

Phase 1: Discover

Enable cloud app discovery and query your identity provider to identify AI service usage.

Phase 2: Assess Risk

Risk-score identified tools and map data flows to understand the context and compliance of usage.

Phase 3: Control

Implement Conditional Access policies and alerting for new AI app registrations to manage risk.

Why Blocking Everything Doesn’t Work

Blocking all AI tools tends to push usage underground and does not eliminate risk. Understanding what tools are being used and providing compliant alternatives is a more effective strategy.

What to Do This Week: Immediate Actions for UK Security Leaders

Actions that can be taken quickly include enabling cloud app discovery, querying OAuth grants, and creating DLP alert rules. None require significant investment.

Final Thoughts: You Can’t Protect What You Can’t See

Shadow AI is invisible to many organizations, exposing them to significant regulatory and financial risks. Building visibility is crucial for mitigating these risks effectively.

Frequently Asked Questions: Shadow AI

What is shadow AI?

Shadow AI refers to the use of AI tools by employees without oversight, creating unmanaged data processing relationships.

How is shadow AI different from shadow IT?

Shadow AI involves data processing and retention risks that are more severe than simply storing files in unapproved services.

Is shadow AI a GDPR risk for UK businesses?

Yes, shadow AI often processes personal data without compliance with GDPR requirements.

What tools can detect shadow AI in my organisation?

Core tools include CASB, DLP, IAM, and SIEM to monitor AI usage patterns and compliance.

Should I block all AI tools to prevent shadow AI?

Blocking often drives usage underground; understanding and managing tools is more effective.

What is a CASB and how does it help with shadow AI detection?

CASB provides visibility into cloud application usage, helping to manage and assess risk from AI tools.

Is DeepSeek safe to use in a UK organisation?

DeepSeek poses specific data sovereignty concerns and is considered high-risk for sensitive data processing.