Shadow AI is any AI tool your staff use for work without the company approving it. Usually nobody is acting in bad faith. People paste a contract, a donor list, or a client email into a free chatbot because it helps them finish faster, and the data leaves your control without anyone signing off.
Why shadow AI leaks more than shadow IT
Shadow IT has been around for decades, from personal file-sharing accounts to unapproved apps. This newer version is different, because the tool’s whole purpose is to take in your content.
Employees do not just store a file there. They paste the most sensitive paragraph, because that is the part they need help with.
Consumer AI tools also come with their own terms. Some let the provider keep prompts, and some use them to improve future models. Settings vary by product and change often.
Business versions of the same tools typically offer stronger data commitments. However, staff using personal accounts do not get those protections, even when they use the same brand.
What the breach data shows
IBM’s Cost of a Data Breach Report, released in July 2025, was the first edition to study unapproved AI use directly. One in five organizations in that study reported a breach due to shadow AI. In addition, organizations with high levels of shadow AI saw $670,000 more in breach costs than peers with little or none.
The same report found that 63% of breached organizations had no AI governance policy or were still developing one. That gap shows up in smaller companies too, because AI use grew faster than anyone wrote rules for it.
How to find what is already in use
You cannot manage what you have not found, so start by asking. A short, no-blame survey about which AI tools people use, and for what, often reveals more than any scan. Most people are glad to share a tool that helps them.
Next, check the technical signals. DNS filtering and web logs show which AI sites company devices visit. Microsoft Entra ID shows which third-party apps users have connected to their mailbox or files.
Browser extensions deserve their own look. Some AI add-ons can read every page a user opens, including your line-of-business apps.
Then review expense reports and card statements. Individual AI subscriptions often appear as small monthly charges that nobody questions.
Why banning AI does not work
Blocking every AI site feels decisive. In practice, it pushes use onto personal phones and home computers, where you have no visibility at all. As a result, the data still leaves, and you simply stop seeing it.
In my experience, staff follow rules that give them a reasonable way to get the work done. So the goal is to offer an approved tool that is good enough, then block the risky alternatives. People rarely go around a tool that already works for them.
Write an AI use policy people will follow
A policy does not need to be long. One or two pages that people actually read beat a thick document nobody opens. Cover these points:
- Which AI tools are approved, and which accounts to use (company accounts, never personal ones).
- Which data never goes into any AI tool: client records, health information, passwords, financial account details, and anything under a confidentiality agreement.
- Who approves a new AI tool, and how quickly a request should get an answer.
- Rules for AI browser extensions and meeting note-takers that join calls.
- How staff should check AI output before it goes to a client, donor, or regulator.
- Who to tell, without penalty, if someone pasted something they should not have.
Then train on it. A 15-minute walkthrough with examples from your own work does more than a signed acknowledgment form.
The fast approval path matters most. If a request sits for a month, staff will quietly use the tool anyway.
Technical controls that back up the policy
Policy sets the expectation, and controls catch the mistakes. First, stop users from granting third-party apps access to company data without admin approval. That single setting in Microsoft Entra ID blocks many AI apps from connecting to mailboxes and OneDrive.
Next, use DNS filtering to block unapproved AI sites on managed devices while allowing the approved one. Data loss prevention rules can also flag or block sensitive data, such as Social Security numbers, before it leaves.
For deeper reading, CISA and partner agencies published AI data security best practices in May 2025. It is written for technical teams, but the principles apply to any organization that handles sensitive data.
When someone already pasted sensitive data
Sooner or later, someone will tell you they put client data into a personal AI account. How you respond decides whether the next person speaks up at all. So thank them first, then act quickly.
Start by writing down what was shared, which tool received it, and when. Next, have the employee delete the conversation and check the account’s data settings, since many tools let users turn off training on their chats. Then decide whether the data triggers any contract, regulatory, or insurance notice obligations.
That last question belongs with leadership and, when needed, legal counsel. It should not be left to the employee or to IT alone.
How WEBIT approaches this
We baseline every client to the CIS Controls, and software inventory is part of that baseline. Security Essentials on every managed device includes DNS filtering and application allowlisting, so unapproved tools are visible and controllable. For clients who want more, our Shadow AI protection add-on focuses on AI-specific discovery and control.
We pair those controls with a practical policy and an approved tool, because blocking alone fails. Our cybersecurity team helps leadership decide which data can go where, and our AI and automation team helps staff get value from the approved tools.
Key takeaways
- Shadow AI is usually well-meaning staff trying to work faster, not bad actors.
- IBM’s 2025 breach research tied heavy use of unapproved AI to $670,000 in added breach costs.
- Ask staff first, then confirm with DNS logs, connected-app reviews, and expense reports.
- Give people an approved tool and a short policy before you block anything.
Related from WEBIT: free Security Scorecard.
Not sure which AI tools your staff already use? Talk to an owner.





