Skip to content
Go to homepageDrova logo

Shadow AI: the risk your register does not know it has

Your people already use AI at work. Most registers have no entry for it. The fix is a line in the register, not a ban.

Shadow AI is the use of AI tools at work without approval, oversight or knowledge. It does not look like an incident. It looks like work getting done, which is exactly why it stays invisible.

Simple feature visual

TL;DR

  • Shadow AI is AI used at work without the organisation's approval, oversight or knowledge: a personal chatbot account, a free transcription app, an AI feature switched on inside software you already own.
  • It is already the norm, not the exception. Microsoft and LinkedIn's 2024 Work Trend Index found 78% of AI users bring their own AI tools to work, and 75% of knowledge workers now use AI at work.
  • It is not a junior problem. UpGuard's research found executives report the highest rates of regular shadow AI use, and security leaders are more likely than the average employee to use unapproved tools.
  • Bans do not remove it, they relocate it to personal phones and home laptops, where you lose the one thing you had: visibility.
  • Treat it as an operational risk with an owner, a score and safeguards, and make the sanctioned path easier than the shadow one.

What is shadow AI?

Shadow AI is the use of AI tools at work without the organisation's approval, oversight or knowledge. An employee runs company information through a personal chatbot account, a free transcription app, or an AI feature switched on by default inside software you already pay for. The work gets done. The business never sees where the information went.

Somewhere in your business this morning, someone pasted a customer email into a chatbot to draft the reply. It was faster. The reply was good. Nobody wrote it down anywhere, because there is nowhere to write it down. That is the shape of this risk: it does not announce itself as an incident, it presents as productivity.

The scale is not marginal. Microsoft and LinkedIn's 2024 Work Trend Index found that 75% of knowledge workers were already using AI at work, and that 78% of those users bring their own AI tools with them. Whatever your official position on AI is, your actual position is that your people are already using it.

Part of our series on the real risks of AI for a business: familiar risks, with the likelihood turned up.

Where shadow AI actually shows up

Personal accounts

Company or customer information pasted into a chatbot signed in under someone's own email. Nothing about it is logged on your side. This is the branch our data leakage page covers in depth.

Free point tools

A transcription app for the client call, a summariser for the contract, an image tool for the deck. Each one is a supplier you never assessed, holding data you never approved.

Features you already own

The AI toggle switched on inside a tool you licensed years ago. Nobody adopted anything, so nobody reviewed anything, and the terms changed underneath you.

Output nobody checked

The quieter half. Work drafted by AI and shipped without verification, which is how fabricated detail reaches customers, auditors and boards.

The tempting fix

Why bans fail

The comfortable version of this story is that shadow AI is a graduate problem: a well-meaning junior, a free account, a lesson learned. The research does not support it. UpGuard's study, reported by Cybersecurity Dive, found that while mid-level managers and junior staff showed the highest overall shadow AI use, executives reported the highest rates of regular use, and security leaders were more likely than the average employee to use unapproved tools, and far more likely to do so routinely.

That detail kills the easy fix. You cannot train your way out of behaviour your leadership is modelling.

And a ban does not stop shadow AI either. It relocates it. The pasting continues on personal phones and home laptops, and the one thing a ban reliably removes is your visibility of it. You trade a risk you could see for the same risk with the lights off. The pressure that created the behaviour has not moved: the tool works, the day is full, and the approved alternative either does not exist or takes weeks to request.

What good looks like

What the register entry looks like

If shadow AI went into your risk register tomorrow, the entry would be unremarkable. That is the point.

The risk: company or customer information leaves the business through unsanctioned AI tools, and decisions get made on unverified AI output. What is driving it: AI is in every tool your people touch, the sanctioned alternatives lag the free ones, and usage is invisible by default. What it threatens: client confidentiality, data protection obligations, and the accuracy of what goes in front of customers, auditors and the board. The safeguards: an AI policy people can actually follow, a sanctioned tool that is genuinely good, an owner, and a review rhythm that keeps pace with how fast this moves.

Nothing exotic. The only unusual thing about shadow AI as a risk is that most registers still do not carry it, because it arrived faster than the annual review cycle. The structure every entry needs is on the risk register page, and the assessment page covers how to work out your own score for it.

One cultural safeguard matters more than any tooling decision: nobody should be punished for asking whether they may use something. The moment the question carries a cost, the usage does not stop, it just stops being visible.

Shadow AI FAQs

What is shadow AI?

The use of AI tools at work without the organisation's approval, oversight or knowledge: personal chatbot accounts, free point tools, or AI features switched on inside software you already own. It is the AI equivalent of shadow IT, and it is usually driven by productivity rather than bad intent.

How common is shadow AI?

Common enough to be the default. Microsoft and LinkedIn's 2024 Work Trend Index found 75% of knowledge workers already using AI at work and 78% of those users bringing their own tools. If your business has not approved anything, that does not mean nothing is being used.

Is shadow AI a security risk or a business risk?

Both, and treating it purely as a security issue misses most of it. Data leakage is the visible edge. The quieter costs are decisions made on unverified AI output and obligations breached without anyone noticing, which is why it belongs on the business risk register rather than only the IT one.

Should we ban AI tools at work?

Bans mostly relocate the behaviour to personal devices, where you lose visibility entirely. A usable policy, a sanctioned tool that is genuinely good, and a register entry with a named owner outperform a ban in practice.

Who should own shadow AI risk?

Whoever owns operational risk, with IT as a contributor rather than the owner. If it sits only with IT it gets managed as a tooling question, and the business impact goes unowned.

How do we find out what is already being used?

Ask, without penalty, and look at what the finance and expense records already show. A short amnesty tends to surface more than a monitoring programme, because the people using these tools are not hiding maliciously, they are solving a problem you have not solved for them.

The AI Disruption Index scores the risks AI is driving against your objectives, with a safeguard drafted for each one. Free, in about ten minutes.

Shadow AI is just one risk. See everything AI is driving.

AI risk series

Explore related topics

The real risks of AI for a business

The series hub: what counts as an AI risk, the four families, and where to start.

AI data leakage: what your people paste into AI

The fastest breach is a paste: the four ways out, and the rules that keep the tools without the leak.

The AI policy your business actually needs

The full template, free on the page, and how to make it yours.

The AI risk register

What every entry carries, with worked examples.

How to run an AI risk assessment

Three ways to do it, compared, and the five steps.

Guardrails, safeguards, controls: what AI actually needs

Three words untangled, and the four families of AI-era safeguards.

AI governance, in plain English

The four working parts, who owns what, and when a framework earns its keep.

AI in risk management: what it can genuinely do

The four jobs AI does well, and the three things it must never own.

AI hallucinations at work: examples and what they cost

Three documented cases with price tags, and the verification safeguards that catch fabrication before it ships.

AI phishing: the email with perfect grammar

Why the spot-the-typo era is over, and the safeguards that work without spotting the fake.

AI scams targeting businesses

Old cons, industrialised: the four branches, the tells that remain, and what to do if you're hit.

Fraud no longer needs a forger

Deepfakes, voice clones, invoice fraud, and the safeguards that still hold.

AI cyber attacks: when the attack is automated

Familiar attacks at a new tempo: the real uplift, the hype, and the fundamentals that still hold.

Prompt injection: the attack your register hasn't heard of

Instructions hidden in ordinary content, and the safeguards that limit the damage.

What is AI disruption?

A plain definition: the change is in your risks and plans, not just your tools.

See your own AI risk picture

The risks AI is driving against your objectives, scored for your business.