Skip to content
Sections
All notes

All notes · Foundations

What Shadow AI Actually Is

A working definition, the shapes it takes, and why it is better understood as information than as misconduct.

Foundations · Explainer

Shadow AI is the use of AI tools the organisation has not provided, approved or in many cases heard of. It is widespread, it is mostly done by conscientious people, and the framing you choose determines what you learn from it.

The recommendations in “What Shadow AI Actually Is” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating the full article can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.

For an independent benchmark, compare the local approach with ICO guidance on AI and data protection; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

The shapes it takes

A personal account on a consumer AI service, used for work.

An AI feature switched on inside a tool you did approve, which nobody evaluated separately.

A browser extension that sends page content somewhere.

An AI coding assistant on a personal licence.

And an agent or automation somebody built, which calls a model you have no relationship with.

The second and fifth are the ones most organisations have not thought about.

Why the term is unhelpful on its own

"Shadow" implies concealment, and most of this is not concealed — it is simply unasked about.

People use a tool, it helps, and no process exists to declare it.

Treating that as misconduct produces a compliance exercise and a quieter shadow, which is the central failure mode this collection is about.

The better framing

Shadow AI is a measurement of the gap between what people need and what they were given.

Every instance tells you: this task was hard enough that somebody went looking, and the approved route did not cover it.

That is information about your tooling, not about the person.

What is genuinely risky

Confidential or regulated data entered into a service whose terms permit retention or training.

Output used without checking, where accuracy matters.

Code produced with unclear provenance.

Automations running unattended against a service nobody assessed.

Each has its own note. None of them is "people used AI".

What is not risky and gets treated as though it is

Drafting an internal email.

Summarising a public document.

Explaining an error message.

Rewriting something for clarity.

A policy that treats these the same as pasting a client contract will be ignored in full, which is how organisations lose the ability to control the cases that matter.

What this collection covers

Finding what is actually in use, without starting a hunt.

Sorting the risk by how real it is.

What can be monitored and where that becomes monitoring people.

Writing rules people will follow, and providing something good enough that they want to.

What to check

Can you name the AI tools in use in your organisation?

Do you know which AI features are switched on inside tools you already approved?

Is there a route for somebody to declare a tool they find useful?

And does your policy distinguish drafting an email from pasting a contract?

The point

Shadow AI is better read as a measurement of the gap between what people need and what they were given than as misconduct..

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.