Trusted Pen Testing, Industry Certified.
Microsoft Certified Expert badge with three white stars on a blue shield.
Kaseya Platinum Partner badge

What is shadow AI?

Shadow AI is the use of artificial intelligence tools for work without the approval or oversight of the organisation's IT or security function. In practice it means consumer chatbots, browser extensions, meeting notetakers, AI features inside other applications, and increasingly AI agents and MCP connectors, often accessed with personal accounts, used to do ordinary work faster.

It is the AI version of shadow IT, but it behaves differently. Shadow IT is usually an unapproved application holding data. Shadow AI is data leaving the organisation inside a prompt, an upload or an integration, where it may be retained, reviewed by the provider, or used to train a model. Nothing has to be installed and no policy has to be knowingly broken for it to happen.
Power Automate workflow automation feature cards
What is shadow
AI discovery
?
Shadow AI discovery is the process of identifying every AI tool in use across an organisation, including tools nobody approved, and establishing what data has been put into them. It answers two questions: which tools, and what went in.

Discovery is not detection. Detection products alert you when someone uses a tool. Discovery establishes the whole picture first, including what has already happened, which is what you need before writing a policy.

Discovery is not governance. Discovery is a point in time. Governance is the ongoing control that follows: an approved toolset, policy, and guidance for staff at the moment they act.

It does not require a ban. The usual output is a shortlist of tools that can be approved safely, a smaller list that cannot, and the evidence for both.
How common shadow AI is in UK businesses
Four figures, each with its publisher, date and sample size stated. Worth stating why that matters: a widely repeated claim that "72% of employees use unsanctioned AI tools" is attributed across several vendor pages to Salesforce, but the figure in Salesforce's own research is 55%, from fieldwork in October 2023.
71
%
of UK employees have used unapproved consumer AI tools at work and 51% continue to do so every week.
Microsoft UK, 13 October 2025. Censuswide survey of 2,003 UK employees.
Office at night overlaid with digital padlock icons
22
%
used consumer AI for finance-related work, yet only 32% were concerned about the company data they entered.
Microsoft UK, 13 October 2025. Same survey of 2,003 UK employees.
52
%
of people using AI at work are reluctant to admit using it for their most important tasks.
Microsoft and LinkedIn, Work Trend Index 2024. 31,000 knowledge workers across 31 markets.
Abstract dark blue 3D puzzle pieces
40
%
of organisations worldwide are forecast to suffer a security or compliance incident from unauthorised AI use by 2030.
Gartner press release, 19 November 2025. A forecast, not a measurement.
The 52% is why an internal survey under-reports. If half of AI users will not name their most important uses, asking the question produces a tidy answer and an incomplete picture. That is the argument for discovery over a questionnaire.
What are the risks
of shadow AI
?
Four distinct risks, which matter because they need different fixes. Data exposure is a security problem, regulatory exposure is a governance problem, unreliable output is a quality problem, and the missing audit trail is what makes the other three hard to prove either way.
Consumer chatbots
Staff drafting client work in tools nobody approved
Which AI tools is your team using that you have never signed off?
Data in prompts
Client files and payroll sheets pasted in to summarise
What has already gone into a chatbot, and is it retained?
Personal accounts
Work done on personal logins, outside your tenant and invisible to it.
Business outcome
Increase adoption while reducing risk.
Connected apps
AI add-ins holding standing permissions on your Microsoft 365 data.
Leaver accounts
People who left, still holding AI accounts with your data in them
Free tiers
Consumer plans whose terms may permit training on what you type.
Blue digital particle waves representing monitored data
Meeting notetakers
Bots transcribing client calls and storing the recordings elsewhere.
Leaver accounts
Are any of your staff logins already circulating from an old breach?
Browser extensions
AI extensions that can read every page a member of staff opens.
Agents and MCP
AI agents and MCP connectors acting on your systems on someone's behalf.
How shadow AI
is detected
Entering personal data into a consumer AI tool is a processing decision, whether or not anyone signed anything. Three consequences before treating this as an IT problem rather than a board one.
Shadow AI and UK GDPR
Entering personal data into a consumer AI tool is a processing decision, whether or not anyone signed anything. Three consequences before treating this as an IT problem rather than a board one.
Power Automate workflow automation feature cards
Why blocking AI tools
does not work
The instinct is to block the domains and move on. It fails for a reason the research states plainly: staff are not using these tools to be difficult, and removing them does not remove the need they meet.

In Microsoft's UK survey, 41% of employees using unapproved AI said they did so because the tool was already familiar from personal life, and 28% said their employer provided no approved alternative. Blocking addresses neither. The work moves to a personal phone or a home laptop, where there is no logging, no data loss prevention and no way to answer a client asking where their information went.

The organisations that get this under control tend to do the same three things. They discover what is actually in use before deciding anything. They approve a small number of tools quickly, so there is a sanctioned route that is genuinely easier than the workaround. Then they write the policy, naming what must never be entered into any tool, and train against it rather than announcing it.
the works
How shadow AI
discovery works
Four steps, in order. The sequence matters: a policy written before the facts are known tends to prohibit the tools people depend on most, which is how shadow AI ends up on personal devices.
why
why choose intouch tech
98
%
UK organisations
1000
+
UK organisations
12
+
Years in business
99.99
%
Uptime SLA
ISO 27001
And 9001
24
/
7
SOC monitoring
CE PLUS
Certified

What is shadow AI?

Shadow AI is the use of AI tools for work without the approval or oversight of the organisation's IT or security function. It usually means consumer chatbots, browser extensions, meeting notetakers or AI features inside other apps, often on personal accounts.

What is shadow AI discovery?

Shadow AI discovery is the process of identifying every AI tool in use across an organisation, including unapproved ones, and establishing what data has been entered into them. It answers which tools are in use and what went into them, before any decision about blocking or approving.

How is shadow AI different from shadow IT?

Shadow IT is usually an unapproved application holding data. Shadow AI is data leaving the organisation inside a prompt, an upload or an integration, where it may be retained or used for training. Shadow AI needs nothing installed, so it rarely appears in expenses or software inventories.

How do you detect shadow AI?

From five signal sources your systems already produce: identity and sign-in logs, OAuth apps holding permissions on Microsoft 365, network and DNS traffic to AI domains, browser extension inventories, and data loss prevention alerts. Microsoft documents the network-level approach for shadow AI discovery in Entra Global Secure Access.

What are the main risks of shadow AI?

Four: data exposure when company or client information is entered into unassessed tools, regulatory exposure because you remain the controller for that processing, unreliable output reaching clients unchecked, and the absence of an audit trail, which makes the first three difficult to prove either way.

Can we just ban AI tools instead?

Blocking rarely works. In Microsoft's UK research, 41% used unapproved AI because it was familiar from personal life and 28% because no approved alternative existed. A ban removes neither reason, and the work moves to personal devices where nothing is logged.

What if sensitive data has already been entered?

Establish what went where, whether the tool retains or trains on it, and what remains within your control: deleting conversations and accounts, revoking app permissions, and deciding whether anything meets the threshold for reporting to the ICO.

Does shadow AI breach UK GDPR?

Not automatically, but it makes compliance difficult to evidence. If personal data has been entered into a tool your organisation never assessed, you remain the controller for that processing, and the ICO expects you to know where AI is used and on what lawful basis.

Is shadow AI a risk for smaller businesses?

More so, not less. Smaller teams adopt tools quickly because there is no procurement process in the way. Microsoft and LinkedIn's Work Trend Index 2024 found 78% of AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies.

What does shadow AI discovery cost?

Discovery is included in the free Intouch Tech cyber review, which covers AI use alongside the rest of your security posture. Ongoing AI governance, which keeps the visibility in place rather than taking a snapshot, starts at £12.50 per user per month.

Trusted UK IT Team

Lets Start A Conversation

Tell us what you need, from AI governance and cyber security to managed IT, Microsoft 365, phones and connectivity. You'll deal with one accountable UK team that's looked after growing businesses since 2012, and leave with clear next steps.

0333 370 7000

Mon-Fri 8am-5pm · 24/7 for managed clients

[email protected]

Response within 1 business day, guaranteed

United Kingdom

UK-based team, since 2012

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.