What is Shadow AI? (And why it looks a lot like Shadow IT from ten years ago)
Shadow AI is the use of AI tools and services by employees without the organization’s approval, knowledge or control. It’s the modern equivalent of Shadow IT, when departments procured their own SaaS tools without going through technology, but with a critical difference: AI processes data, generates content and makes decisions. The risks are exponentially higher. It includes practices such as:- Pegar datos confidenciales de clientes, ventas o finanzas en chatbots públicos como ChatGPT, Gemini o Claude.
- Usare strumenti di IA generativa non approvati per creare contenuti marketing, proposte commerciali o report interni.
- Installing AI-powered browser extensions that access corporate email, calendars or documents.
- Using AI code assistants without security review policies.
- Automating tasks with tools like Zapier + AI with no control over what data flows or where.
Key fact: 38% of employees have shared sensitive data with unapproved AI tools, and 27% of prompts sent to AI tools contain confidential or proprietary company information.
The real scale of the problem: numbers that should alarm you
If you think this doesn’t apply to you, review these 2025–2026 data points:- 93% of employees share confidential data through unauthorized AI tools. This isn’t a fringe percentage: it’s virtually your entire workforce.
- 60% of employees knowingly accept security risks to meet deadlines faster using unauthorized AI. Perceived productivity beats caution.
- 35% would keep using Shadow AI even if explicitly banned. Prohibition without alternatives doesn’t work.
- Companies with 1,000+ employees manage an average of 250+ unauthorized AI tools. Two hundred and fifty. Without control, audit or governance.
- Organizations upload 8.2 GB of data per month to unauthorized AI applications. That’s information leaving your security perimeter every day.
Five concrete risks of Shadow AI
1. Confidential data leakage
When an employee pastes client data, pricing, margins or strategies into a public chatbot, that data can be used to train future models, stored on servers outside your jurisdiction, or accessed by third parties. This directly violates GDPR and, depending on the data type, may constitute a serious infringement under the AI Act.2. Loss of control over decisions
If a team makes business decisions based on unverified AI outputs (pricing recommendations, customer segmentations, risk assessments) you’re operating without traceability. You don’t know which model was used, with what data, under what policy. If something goes wrong, you can’t audit or explain the decision. And explainability is an AI Act requirement for high-risk systems.3. Reputational and brand risk
AI-generated content without human review can contain hallucinations (fabricated data presented as fact), biases or false claims. If that content reaches clients, media or social networks under your company’s name, the reputational damage is immediate.4. Direct financial cost
Security breaches linked to Shadow AI cost an average of $4.63 million ; $670,000 more than breaches in environments with low Shadow AI exposure. This isn’t a theoretical risk: it’s a quantified cost.5. Cascading regulatory non-compliance
Shadow AI puts you at risk of simultaneously breaching GDPR (unauthorized data transfer), AI Act (AI use without governance or evidence), NIS2 (security chain gap) and potentially the DMA/DSA if you operate in digital markets. AI Act penalties can reach €35 million or 7% of global turnover.From the master’s program: AI governance is not a brake, it’s an accelerator. Without governance, AI becomes a bottleneck and a risk. The AI Steering Committee must detect and correct any unregistered AI as one of its priority anti-patterns.
Test: do you have Shadow AI in your company?
Answer these questions. If you tick three or more, you have an active Shadow AI problem:- Does any team use ChatGPT, Gemini, Claude or other generative AI with personal accounts for work tasks?
- Are there AI-powered browser extensions installed on corporate devices without IT approval?
- Is content (emails, proposals, reports) being generated with AI tools that aren’t on the approved software list?
- Are there automations connecting corporate data with external AI services without security controls?
- Does the company lack a written AI usage policy that employees know about?
- Do you not monitor in real-time which AI tools employees are using?
- Have employees not received training on what data they can and cannot share with AI tools?
Reality: Only 28% of organizations monitor AI usage in real-time, and 83% lack basic controls to prevent data exposure to AI tools. If you’re not watching, assume Shadow AI is happening.
From prohibition to channeling: the approach that works
The instinctive reaction is to ban. But the data proves that prohibition doesn’t work: 35% of employees would keep using unauthorized AI even with an explicit ban. The reason is simple: AI tools make them more productive, and if the company doesn’t offer an alternative, they’ll find their own. The effective approach is not to ban but to regularize and channel. And this is where the AI Steering Committee governance model makes all the sense in the world.The Shadow AI regularization protocol
When unauthorized AI usage is detected, the AI committee has two decision paths:- Regularize if the case is recoverable: Register the tool or use case in the Gates system, starting with Gate 0 (registration, value hypothesis, risk assessment) and advancing to Gate 1 (controlled pilot with evidence). The goal is to move from opaque to governed, preserving the value the team was already generating.
- Immediate cessation if risk is unacceptable: Si el caso implica datos personales sensibles (PII), riesgos de seguridad graves, sesgo no controlado o incumplimiento normativo directo, se ordena el cese inmediato, se evalúa el daño potencial y se activa el protocolo de incidentes.
Key: The protocol doesn’t punish innovation—it organizes it. Regularization wraps Shadow AI in the same framework of evidence and controls as any other AI project, without destroying the team’s innovative energy.
How to build an AI policy that prevents Shadow AI
An effective AI policy, what the operating model calls an AI Policy Liteis the document that establishes what can be done with AI, under what conditions, who decides in case of uncertainty and what evidence is required. It must be clear, accessible and realistic.The five principles of a good policy
- Proportionality to risk: Not everything requires the same level of control. A customer-service chatbot using public data doesn’t need the same governance as a credit-scoring model. Classify uses by risk level (minimal, limited, high) following the AI Act framework.
- Single accountability and traceability: Every AI use has an owner (Product Owner) and leaves a record of who authorized it, what model is used, with what data and under what conditions.
- Source anchoring (grounding): Any AI that generates content or makes decisions must be anchored to verified, documented sources. Without grounding, there’s no reliability.
- Continuous observability: Approving an AI use once isn’t enough. You must continuously monitor: output quality, data drift, incidents and real adoption.
- Reversibility and Kill Switch: Every AI deployment must be reversible. If something fails, you need to be able to roll back to the previous state without data or service loss.
What the policy should include in practical terms
- List of approved AI tools and their conditions of use.
- List of data that can never be shared with AI tools (PII, non-aggregated financial data, trade secrets, proprietary code).
- Procedure for requesting approval of a new AI tool or use case.
- Responsible person and channel for reporting unauthorized uses without punishment.
- Review and update frequency for the policy.
- Mandatory training for all employees who use AI tools.
The AI Steering Committee’s role in fighting Shadow AI
The AI Steering Committee is the body that turns principles and risks into evidence-based decisions. Regarding Shadow AI, its specific functions are:- Detection and registration: Maintain an up-to-date inventory of all AI tools and uses in the organization, actively detecting unregistered ones.
- Assessment and decision: Apply the regularization protocol (regularize or cease) for each detected case.
- Exception management: Define an agile channel so teams can propose new AI uses quickly, preventing bureaucracy from pushing them underground.
- Anti-pattern monitoring: Watch for early warning signs like unversioned changes, symbolic HITL (human review that’s merely a formality), ignored drift and vanity metrics.
- Vendor due diligence: Before using an external AI provider (LLM models, APIs), require a factsheet/model card, DPA prohibiting retraining with company data, reversibility clauses and continuity SLAs. Without these documents, the risk is unacceptable.
30-day action plan to control Shadow AI
You don’t need a six-month project to start. In 30 days you can lay the foundations:Week 1: Diagnosis
- Launch a rapid audit of AI tools in use (anonymous survey + network traffic review).
- Identify the three or four most critical uses by data volume or sensitivity.
Week 2: Policy and classification
- Draft your AI Policy Lite with the five principles and approved tool list.
- Classify detected uses by risk level (minimal, limited, high).
Week 3: Regularization
- Apply the protocol: regularize recoverable cases (Gate 0 + Gate 1) and order cessation for unacceptable-risk cases.
- Assign an owner (Product Owner) for each regularized case.
Week 4: Training and communication
- Train all teams on the policy: what they can use, what they can’t, and how to propose new uses.
- Activate continuous monitoring and establish a monthly AI inventory review.
The bottom line: Shadow AI can’t be eliminated—it must be governed
Shadow AI is inevitable. Your employees are using AI because it makes them more productive, and that’s a good thing. What’s not good is them doing it without control, policy or traceability. The solution isn’t banning it’s building a governance framework that channels innovation: a clear policy, a regularization protocol with Gates, an AI Steering Committee that decides with evidence, and a culture where proposing a new AI use is easy and safe. Because the companies that win in the AI era won’t be the ones that ban the most, but the ones that govern best..Suspect Shadow AI is already operating in your company? At Impulsa3 we help you diagnose, regularize and build an AI policy that protects your business without stifling innovation.
Sources and references
- Reco – State of Shadow AI Report (2025)
- Gartner - AI governance and Shadow AI predictions (2026–2030)
- Kiteworks - Employees Sharing Confidential Data with Unauthorized AI Tools
- CIO Dive / EY – Shadow AI governance in enterprises (2026)
- IBM – Cost of a Data Breach Report (coste de brechas vinculadas a Shadow AI)
- Instituto Europeo de Posgrado - AI Transformation Master’s: Governance and Operating Model
- AI Act (European Artificial Intelligence Regulation)
- NIST AI Risk Management Framework (AI 100-1)
Lo que hemos aprendido en Impulsa3 sobre el Shadow AI
En Impulsa3 hemos comprobado que el uso espontáneo de IA crece cuando la empresa no ofrece contexto, método y acompañamiento. Por eso I3OS no se planteó como una colección de cuentas o robots individuales, sino como un sistema común con Projects de cliente, skills reutilizables, conectores y responsables. La experiencia práctica ha sido pasar de preguntar quién está usando IA a construir las condiciones para que el uso aporte valor y pueda revisarse. Es una forma más realista de convertir un riesgo difuso en una capacidad organizada.
Esta política se puede convertir en un sistema de decisión mediante un comité de IA.