What Is Shadow AI, and How Is It Different From Shadow IT?
10 September 2026 | David and Goliath
Quick answer
Shadow AI is AI capability in use inside an organisation that IT has not reviewed or approved. It differs from shadow IT in three ways that change how you find it: it usually arrives with no purchase and no account to audit, it hides inside software the organisation already licensed, and the risk runs on the way in rather than on the way out, because the exposure happens when someone types company data into a prompt.
- Shadow IT leaves a paper trail. Shadow AI often leaves none
- AI arrives inside SaaS you already pay for, so procurement review misses it
- The risk is the input, not the storage, which inverts the usual DLP question
- Banning tools moves usage to personal devices where you can see nothing
Mentioned: David and Goliath, shadow AI, shadow IT, data loss prevention, Akamai Workforce Protector
Shadow AI gets treated as shadow IT with a fashionable prefix, and that framing quietly produces the wrong response. The playbook that worked for unsanctioned SaaS, find the invoices, consolidate the vendors, block the rest, fails against a problem with no invoices and nothing central to block. The differences are worth being precise about, because each one breaks a different assumption.
What is shadow AI?
Shadow AI is AI capability being used inside an organisation that IT has not reviewed or approved. That covers a chatbot someone opened in a tab, an AI feature switched on inside a tool you already pay for, and an AI assistant a developer added to their code editor.
The defining characteristic is not that the tool is unknown. It is that nobody has assessed what company information reaches it, under whose account, and what happens to that information afterwards.
How is shadow AI different from shadow IT?
Shadow IT is unsanctioned software. Shadow AI is unsanctioned capability, and that distinction changes where you have to look. Three differences matter in practice.
- No purchase trail. Most shadow IT was bought by someone with a card, which leaves an invoice, a vendor record and usually an account to audit. The majority of AI use has a free tier, so there is nothing in the finance system to find.
- It arrives inside things you already own. Your existing vendors ship AI features into products under contracts signed before those features existed. Nothing triggers a procurement review, because nothing was procured.
- The risk direction is inverted. With shadow IT you worry about company data sitting in an unvetted system. With shadow AI the exposure happens at the moment of input, when someone pastes a customer list or a contract clause into a prompt.
Why does a procurement audit not find shadow AI?
A procurement audit finds things that were bought, and most AI use is not bought by the person using it. It is signed up for, in seconds, with an email address.
The account used is frequently a personal one, which removes the last trace an audit could follow. Akamai measured 47.11% of enterprise AI conversations running through personal identities rather than corporate managed accounts (Source: Akamai, State of the Internet: Enterprise AI Usage Risk Report 2026, August 2026). That figure is regularly quoted backwards, so it is worth stating carefully. It is not that half of staff use AI on their work email. It is that close to half of the AI activity is happening under identities your systems have no relationship with.
Where does shadow AI actually hide?
It hides in four places, and only the first is the one people picture.
- Direct tools in a browser tab. A chatbot, signed into with a personal email, in a normal browsing session.
- Features inside licensed SaaS. AI assistants and summarisers switched on by the vendor inside products your organisation already uses daily.
- Installed web apps. Progressive web apps, browser based applications that install to the desktop and open in their own window, which look like native software to the user.
- Browser extensions. Akamai found that almost 75% of AI browser extensions demand high or critical permissions (Source: Akamai research, 5 August 2026), a level that typically allows an extension to read and change the content of pages the user visits.
The extension category is the one most reviews skip and the one with the most privilege. The same research reported that 16.3% of AI browser extensions contain known CVEs, publicly catalogued security vulnerabilities (Source: Akamai research, 5 August 2026).
Is shadow AI actually a problem, or is it just people working faster?
Mostly it is people working faster, and treating it as pure risk is how governance programmes lose the organisation. Staff adopt these tools because they remove real friction, and the ones doing it are usually the people you least want to obstruct.
The problem is narrower than the panic and wider than the sceptics allow. A small proportion of that activity involves regulated or confidential information going somewhere nobody assessed, under an account nobody controls, and you currently cannot tell which proportion. The task is separating those cases out, not stopping the behaviour.
Why does blocking AI tools make shadow AI worse?
Blocking pushes usage onto devices and networks you cannot observe at all. The work does not stop, because the deadline did not move. It relocates to a personal phone or a home laptop, where there is no logging, no data loss prevention and no possibility of an audit trail.
You also lose the one thing worth having, which is knowledge of what is happening. An organisation with a blanket ban and no visibility is in a worse position than one that permits a sanctioned tool and can see how it is used.
How do you find shadow AI without banning anything?
You observe the browser, because that is where all four hiding places are visible at once and where personal accounts are distinguishable from corporate ones. Forrester found more than 70% of corporate work now happens inside a browser (Source: Forrester, Digital Workplace and Employee Technology Survey 2025), which is why every other vantage point sees only part of it.
Run that observation read only for a fortnight first. You want a ranked list of what is genuinely in use, by how many people, through which accounts, holding which permissions. Policy written before that list exists usually bans the tools nobody uses and misses the ones everybody does.
What tool gives that visibility?
One that runs inside the browser rather than in front of it. Akamai Workforce Protector is the platform we deploy, through an extension covering Chrome, Edge, Firefox and Safari, with an optional endpoint agent when coverage needs to extend to desktop AI applications and AI enabled IDEs.
The behaviour worth knowing about is what it does once discovery is finished. Rather than hard blocking a person mid task, it can redirect them to the sanctioned equivalent, which moves usage into the light instead of underground. That is the difference between a control staff route around and one they stop noticing.
How does David and Goliath approach this?
We run the discovery, then help you decide what to sanction rather than what to ban. In our experience the output splits three ways: a majority of usage that is fine and should be made official, a middle group that needs a guardrail rather than a prohibition, and a small number of genuine problems worth acting on this week.
The mechanics of running that discovery are in how to find out what AI tools your staff are actually using, and if you already own Chrome Enterprise Premium or Microsoft Purview, start with does Chrome Enterprise Premium cover Safari to see what your licences already handle.
Keep reading
Related guides and next steps
solution
AI Governance
The governance framework every deployment runs through, including what staff type into AI tools.
solution
Resources
resource
How Do I Find Out What AI Tools My Staff Are Actually Using?
Network logs and SSO reports miss most AI usage. What actually surfaces it, why the browser is the only place it is all visible, and what to do first.
resource
Does Chrome Enterprise Premium Cover Safari?
No. Chrome Enterprise Premium is capable, and it governs Chrome only. What that leaves uncovered, and how to work out whether the gap matters to you.
resource
Can Microsoft Purview See AI Usage on a Mac?
Partly. Endpoint DLP does cover macOS, the browser extension does not, and three of the five site level actions are Edge only. What that means in practice.
resource
How Do I Stop Staff Pasting Customer Data Into ChatGPT?
Blocking the domain moves the behaviour to a phone. What actually works is controlling the paste itself, and the difference is where the control sits.
Ready to move from reading to shipping?
Ten business days. Four modules. One agent live by the end.