Shadow AI Governance
AI can enter through employee tools, vendor features, or browser scripts. Use discovery checks that cover all three routes.
By Cody Maxwell · AI Governance Institute · Published September 2026 · Reviewed monthly
What is shadow AI?
Shadow AI is organizational AI use that IT, Legal, or Risk has not approved and may not know about. Employees can adopt consumer chatbots or add AI browser extensions to their workflows. Vendors can introduce AI features into approved software, including Microsoft 365 Copilot or Salesforce Einstein. A vendor’s web application can also run AI scripts directly in a user’s browser, outside internal network systems. These channels need different checks. Employees following existing approval rules can encounter AI through software the organization already trusts.
How AI bypasses existing checks
Software installations, budget requests, and access requests can reveal shadow IT. Browser-based AI tools may need neither installation nor administrator rights. Vendors can enable AI features in production software without customer action or a new purchase. Procurement reviews may therefore miss the change. The PRC-014 shadow AI control addresses AI introduced through this existing software supply chain.
Risks to review
An unknown AI system cannot be classified, monitored, or included in incident planning. Missing inventory entries leave data governance and response teams without a complete picture. Consumer tools may lack the contractual protections your enterprise agreements require. Check retention, training use, and deletion terms before staff enter sensitive information. Embedded vendor features also need review. A new AI feature processing personal data may change the adequacy of an older vendor agreement. Assess the processing roles and applicable GDPR or CCPA requirements, even when the vendor relationship appears unchanged.
How to find shadow AI
Review vendor contracts and feature announcements for AI added to productivity, communication, and CRM tools. Request AI feature disclosures during annual vendor reviews. Survey employees about undisclosed tools, offering amnesty and a clear approval route. This encourages disclosure during discovery. Ask IT to inventory browser extensions and flag broad site-data or clipboard permissions. Content-security-policy and web-application-firewall logs can reveal scripts loading from AI-associated domains. Run these checks together because each finds systems the others miss. The AI system inventory and risk classification playbook describes the discovery process.
Assess the tools you discover
A blanket ban can drive continued use out of sight because many tools need no IT involvement. Apply risk classification to each discovery using data sensitivity, decision impact, and regulatory exposure. Give useful tools an approval route that employees can follow quickly. The PRC-014 control includes allowlists and blocklists for AI-capable browser extensions. Review vendor data-processing terms when you find an embedded AI feature. Repeat scans on a schedule as vendors release further changes.
The regulatory angle
Lack of internal approval does not exempt a system from applicable law. Personal data processing can trigger GDPR or California Consumer Privacy Act (CCPA) duties even when Legal never approved the tool. EU AI Act classifications depend on the system’s use and other statutory criteria. A personal account does not remove obligations that apply to a high-risk use. Financial model risk and clinical oversight requirements also need assessment when staff adopt AI informally.
Related guides
Find your shadow AI exposure
Use the self-assessment to identify unmanaged AI use and plan the reviews your team needs.
Start the self-assessment