AI Governance

Shadow AI: What It Is, What It Costs, and How Enterprises Govern It

An inventory of AI applications is no longer an inventory of enterprise AI use. And a sanctioned AI tool is not the same as governed AI execution.

Definition

What is shadow AI?

Shadow AI is the use, development or deployment of artificial intelligence for organizational work outside sufficient organizational approval, visibility or governance. It can include employees using personal AI accounts, but the category now extends beyond unauthorized chatbots to AI coding assistants, model APIs, locally hosted models, agents, MCP servers and AI-enabled workflows operating outside established controls.

Microsoft’s current definition explicitly encompasses AI-powered tools and agents used without IT awareness or approval, including unauthorized coding assistants, local agents, MCP servers and agentic command-line tools. Netskope’s 2026 research similarly reports that shadow-AI discovery has expanded beyond personal AI applications to agents, MCP servers and local AI infrastructure.

Shadow AI is not limited to whether procurement approved a particular vendor. The governance question can involve the AI asset, the account being used, the data entering it, its integrations and permissions, or the business workflow being executed.

The Evidence

Shadow AI at a glance

Six figures from 2026 research, each shown with the population it was measured against.

30%

used only personal AI applications

Netskope AI Report 2026 (observed enterprise AI users; another 14% used both managed and personal)

43%

reported security incidents involving shadow AI

IBM Cost of a Data Breach 2026 (602 breached organizations; up from 20% in the prior study)

$5.39M

average cost of a breach involving shadow AI

IBM 2026, among breached organizations studied, vs. a $4.99M global average that year

39.7%

of AI interactions involved sensitive data

Cyberhaven 2026 AI Adoption & Risk Report (telemetry across 222 companies)

38%

have a formal, comprehensive AI policy

ISACA 2026 AI Pulse Poll (3,400+ digital-trust professionals; 90% believed employees were using AI)

26%

say leadership is clearly aligned on AI

Microsoft 2026 Work Trend Index (20,000 AI-using knowledge workers across 10 markets)

Taxonomy

The five forms of shadow AI

Not every instance looks like an employee with a personal chatbot tab open.

1.Unsanctioned AI tools
An employee uses an AI application the organization has not approved or does not know about — commonly a consumer generative-AI service used to summarize internal material.
2.Sanctioned tool, unsanctioned account
The enterprise permits the product, but an employee uses a personal account for organizational work. The application is approved while the activity sits outside enterprise identity, retention and data controls.
3.Unregistered AI infrastructure
Model APIs, local models, coding assistants, agent frameworks and MCP servers enter through technical teams without ever reaching the organization's inventory and governance processes.
4.Unregistered agents and workflows
Someone assembles an agent or AI-enabled workflow connecting models, data and enterprise tools without registration, review or a named owner.
5.Sanctioned AI with poorly governed execution
The approved system is not itself shadow AI, but the execution practices inside it can be invisible: business-critical prompts privately maintained, inconsistently changed, unowned and impossible to reconstruct.

That last case is why enterprises should distinguish AI asset visibility from AI execution visibility. Using an approved AI system does not automatically make the system itself shadow AI — but the execution practices inside it can still be invisible.

Surface Area

What counts as shadow AI today?

Shadow AI now has a much broader technical surface than consumer chatbots alone.

Examples of shadow AI and why each can fall outside enterprise governance
ExampleWhy it can become shadow AI
Personal ChatGPT, Claude, Gemini or other AI accountOrganizational work occurs outside enterprise account controls
Unapproved AI SaaS applicationSecurity and IT may lack visibility into the application and its data practices
AI coding assistantProprietary code or technical context can enter an unmanaged AI workflow
Model APIDevelopers can embed AI into applications without normal AI governance
Local LLMModels can operate on endpoints outside centralized inventory and oversight
AI agentAn agent can access data, invoke tools and execute actions
MCP serverIt can connect AI systems with enterprise tools and resources outside established controls
Agentic CLIAI capabilities can enter developer workflows through endpoint tools
Embedded AI featureA sanctioned SaaS vendor can introduce AI functionality into an already-approved application
Unregistered internal AI workflowThe individual components may be approved while the combined business process remains insufficiently governed

The unit of governance is shifting from “which AI websites are employees visiting?” toward “which AI systems, connections and execution practices are participating in enterprise work?”

Methodology

How common is shadow AI?

There is no single percentage. Different studies measure different populations, so here they are side by side with what each one actually covers.

Shadow AI measures compared by source, method, finding and limitation
MeasureSourceMethod / populationFindingImportant limitation
Personal vs. managed AI useNetskope AI Report 2026Platform telemetry, Jun. 2025 – Jul. 202630% personal-only; 14% personal + managedMeasures users in Netskope's observed environment, not all employees globally
Sensitive data in AI interactionsCyberhaven 2026 AI Adoption & Risk ReportTelemetry across 222 companies39.7% of AI interactions involved sensitive dataDoes not establish that every interaction caused a harmful disclosure
Shadow-AI security incidentsIBM Cost of a Data Breach 2026602 breached organizations43%, up from 20% in the prior studyBreached organizations are not representative of all organizations
Formal comprehensive AI policyISACA 2026 AI Pulse Poll3,400+ digital-trust professionals38%Policy existence does not establish policy effectiveness
AI leadership alignmentMicrosoft 2026 Work Trend Index20,000 AI-using knowledge workers across 10 markets26% report clear, consistent leadership alignmentMeasures employee perceptions of organizational alignment

Survey evidence tells us what employees and organizations report. Telemetry tells us what participating security platforms observe. Breach research tells us what appears among organizations that have already experienced a breach. Three different questions, three different populations. What they agree on: AI adoption is occurring outside fully managed enterprise paths at meaningful scale.

Cost

What does shadow AI cost?

$5.39M

Average breach involving shadow AI

Among the 602 breached organizations in IBM’s 2026 study

$4.99M

Global average breach cost

Across all breaches in the same 2026 study

The costs breach accounting does not capture

Financial loss is one dimension. Poorly governed AI also creates operational costs that never appear in an incident ledger:

  • Work that cannot be reproduced
  • Outputs whose provenance cannot be established
  • Duplicated prompts and workflows
  • Inconsistent processes across teams
  • AI-assisted decisions that cannot be reconstructed
  • Dependencies on privately maintained instructions
  • Outdated workflows that continue to be reused
  • Governance work performed retrospectively rather than by design

These issues connect shadow AI to a broader problem: AI Execution Debt.

Root Cause

Why do employees use shadow AI?

Shadow AI is often framed primarily as an employee-compliance problem. That explanation is incomplete.

Employees route around the sanctioned path when the sanctioned path does not adequately serve the task they need to complete. That failure takes several forms:

  • The organization has not provided an approved AI option
  • The approved option lacks required capabilities
  • Obtaining access takes too long
  • Employees do not know which tools are permitted
  • Governance guidance is unclear
  • The sanctioned workflow creates excessive friction
  • Employees learned effective practices outside the formal AI environment

The organizational context supports this reading. ISACA’s 2026 poll found widespread perceived AI use but only 38% of respondents reporting a formal, comprehensive organizational AI policy. Microsoft’s 2026 Work Trend Index found only 26% of surveyed AI users saying leadership was clearly and consistently aligned on AI.

AI adoption happens at individual-user speed while enterprise governance operates at organizational speed.

A governance strategy has to address that mismatch rather than assuming policy publication alone will remove it.

PromptFluent Framework

The Shadow AI Demand Model

Treat an instance of unsanctioned AI use as information about the organization, not only as a policy violation. This is a PromptFluent framework, not an industry standard.

1

A real task exists

Someone believes AI can help perform actual work. That represents demand.

2

The sanctioned path failed somewhere

Availability — no approved solution exists. Capability — the approved solution cannot do the task. Speed — access takes too long. Awareness — a solution exists but the employee does not know about it.

3

The governance layer did not capture the work

The organization loses both risk visibility and useful information about where AI demand exists.

Instead of asking only “who used an unauthorized tool?” also ask:

“What were they trying to accomplish, and why did the governed path fail to serve that task?”

Shadow-AI discovery then becomes both a risk signal and a demand signal for enterprise AI.

Comparison

Shadow AI vs. shadow IT

Shadow AI evolved from shadow IT, but AI changes both the risk surface and the unit of governance.

Shadow IT compared with shadow AI
Shadow ITShadow AI
Unauthorized software or cloud serviceUnmanaged AI apps, models, agents, APIs and execution
Often creates a procurement, identity or access footprintCan begin with a free account, API key, local model or embedded capability
Primary governance object is often the applicationGovernance can extend to model, account, data, prompt, agent, workflow and action
Software generally executes predefined functionalityGenerative AI produces probabilistic outputs
Application discovery can reveal much of the problemDiscovering the AI application may not reveal what work is occurring inside it
Primarily human-operatedAgents can increasingly execute multi-step actions
Access can often be revokedInformation already disclosed to an external system cannot simply be “unsubmitted”

The most important distinction is not that shadow AI is entirely different from shadow IT. It is that AI makes application-level visibility insufficient for some governance questions.

Adjacent Problem

Shadow AI vs. AI agent sprawl

Shadow AI

AI operating outside sufficient organizational visibility, approval or governance.

AI agent sprawl

Proliferation of agents without adequate coordination, lifecycle management, ownership or rationalization.

An agent can therefore be:

  • Sanctioned and well governed
  • Sanctioned but part of an agent-sprawl problem
  • Unauthorized, and therefore shadow AI
  • Both unauthorized and part of agent sprawl

The distinction matters because remediation differs. Shadow AI requires discovery, assessment and governance. Agent sprawl additionally requires lifecycle management, ownership, architecture and rationalization.

Risk

What are the biggest shadow AI risks?

1.Sensitive-data disclosure
Cyberhaven's 2026 telemetry across 222 companies found 39.7% of AI interactions involved sensitive data — intellectual property, source code, regulated information, customer data, contracts, financials, internal strategy, credentials.
2.Loss of visibility and auditability
ISACA's 2026 European research found that among 681 digital-trust professionals, only 11% were completely confident their organization could investigate and explain a serious AI incident, and 59% did not know how quickly it could halt an AI system mid-incident.
3.Security exposure
An agent can access tools. An MCP server can connect models with external resources. A coding assistant operates in development contexts. Local models and agentic CLIs run on endpoints. The surface expands as AI becomes more connected.
4.Compliance and regulatory exposure
“Shadow AI is illegal” is an inaccurate generalization — requirements depend on jurisdiction, sector and use case. The defensible point is that unmanaged AI makes it harder to demonstrate compliance where documentation, oversight or record-keeping obligations exist.
5.Non-reproducible work
An AI-generated result can become operationally important even when nobody can later determine which prompt produced it, which model ran, what context was supplied, which workflow version executed, or what validation occurred.
6.Inconsistent AI execution
Two employees can perform the same task with different models, prompts, context, workflows and validation. Both may produce acceptable results. The enterprise may still have no way to determine which process is current, approved or reproducible.

The governance question is not merely which AI tool the employee used. It is:

What information entered the AI workflow, under what policy, for what purpose, and what happened next?

Detection

How do organizations detect shadow AI?

Shadow-AI discovery is primarily a security and observability function.

Network and proxy telemetry

CASB, SASE and secure web gateways can identify traffic to AI services and, depending on implementation, enforce policy.

Endpoint and browser telemetry

Endpoint agents and browser controls provide visibility into AI applications and data movement.

Identity signals

SSO and directory data distinguish organization-managed accounts from personal ones and reveal AI operating outside enterprise identity.

AI asset discovery

Modern discovery needs to cover applications, APIs, agents, local AI infrastructure and MCP servers — not SaaS applications alone.

Procurement and expense signals

Individual subscriptions and unapproved vendor spend remain useful shadow-IT indicators.

Employee disclosure

Telemetry shows that something happened. Employees can explain what task they were performing and why the sanctioned path did not serve it.

PromptFluent is not a network-level shadow-AI discovery, CASB, DLP or endpoint-security product. Those technologies address an important problem: finding and controlling AI activity occurring outside approved enterprise boundaries.

Strategy

Is blocking AI the solution to shadow AI?

Not by itself.

Blocking a high-risk application can be appropriate when its use creates unacceptable security, privacy or compliance risk. But blocking addresses access to a tool. It does not eliminate the business task that caused someone to seek the tool.

The prohibition-only cycle

  1. business demand
  2. unavailable sanctioned path
  3. unauthorized workaround
  4. detection
  5. blocking
  6. unresolved business demand

The stronger governance objective is to reduce both the risk and the incentive to leave the sanctioned environment. That means combining controls with viable approved alternatives.

Framework

How can enterprises govern shadow AI?

A mature approach can be organized around six capabilities. Treat them as a sequence, not a menu.

01

Discover

Identify the AI actually participating in enterprise work: applications, personal vs. enterprise accounts, model APIs, local models, coding assistants, agents, MCP servers, AI-enabled integrations and emerging execution surfaces.

02

Inventory

Maintain an authoritative inventory of sanctioned AI assets and accountable owners. It should answer more than “which vendor did we buy” — which systems are approved, who owns them, what they may do, and which enterprise resources they can reach.

03

Classify

Risk is contextual. Classify by data sensitivity, business purpose, model or provider, autonomy, external connectivity, decision impact, regulatory relevance, human oversight and the consequences of failure.

04

Govern

Define what is permitted, prohibited, conditional, subject to approval, subject to human review, and subject to additional monitoring or records. Policy establishes authority — but policy alone is not execution.

05

Provide a better sanctioned path

Give employees capabilities that solve the tasks creating demand: approved tools, reusable instructions, governed prompts, approved workflows, clear ownership and guidance without unnecessary friction. The goal is not making unauthorized AI harder to use. It is making governed AI easier to use correctly.

06

Monitor execution

For repeatable, consequential or regulated AI-assisted work: which prompts and instructions were used, which workflow ran, which model or version participated, who owned and approved it, what changed, and what execution evidence exists.

Why detection alone is not enough

Detection answers where unmanaged AI is occurring. It does not answer why the employee left the governed path, or how the underlying work should be performed going forward. A useful remediation loop:

  1. Discover
  2. Understand the task
  3. Classify the risk
  4. Provide a governed path
  5. Monitor execution
  6. Use residual shadow AI as feedback

This turns shadow-AI discovery from a recurring enforcement exercise into an input to enterprise AI operating design.

Maturity

From shadow AI to governed AI execution

A second-order problem appears once enterprises succeed at moving employees onto approved AI platforms. The platform is sanctioned. The execution layer may still be poorly governed.

  1. Stage 1

    Shadow AI

    What AI activity don't we adequately see or govern?

  2. Stage 2

    Visible AI

    What AI is actually being used?

  3. Stage 3

    Sanctioned AI

    Which AI systems and uses have we approved?

  4. Stage 4

    Governed AI

    What policies, ownership and controls apply?

  5. Stage 5

    Governed AI Execution

    Can we manage and understand how AI-mediated work is actually executed?

A sanctioned tool is not the same as governed execution.

This is the distinction most shadow-AI programs eventually encounter.

Where PromptFluent Fits

Discovery is a security problem. Execution is ours.

PromptFluent addresses the execution layer enterprises confront as they bring AI into governed use. It is an enterprise AI execution infrastructure and governance platform, and a system of record for prompts, workflows, governance and execution intelligence — so important AI practices stop living in personal documents, ad hoc prompt collections and disconnected workflows.

Shadow AI and AI Execution Debt

An enterprise can substantially reduce shadow AI by standardizing on sanctioned platforms and still accumulate AI Execution Debt if the prompts and workflows operating inside those platforms remain fragmented or poorly governed.

Shadow AI and Prompt Debt

An organization could have zero unauthorized AI applications and still have hundreds of employees independently maintaining competing prompts for the same processes. That is not necessarily shadow AI. It is still Prompt Debt.

The strategic objective is larger than eliminating unauthorized AI: move from invisible AI use toward visible, governable and measurable AI execution.

FAQ

Shadow AI FAQs

What is a simple definition of shadow AI?

Shadow AI is AI used, built or deployed for organizational work outside sufficient organizational approval, visibility or governance. It can include personal AI accounts, unauthorized applications, APIs, local models, coding assistants, agents, MCP servers and unregistered AI workflows.

Is using ChatGPT at work shadow AI?

Not automatically. Using an organization-approved enterprise ChatGPT environment in accordance with applicable controls is not inherently shadow AI. Using a personal account for company work can constitute shadow AI when that activity occurs outside the organization's approved and governed path. The same principle applies to Claude, Gemini and other AI systems.

Are AI agents shadow AI?

Not inherently. An inventoried, approved and governed AI agent is not shadow AI simply because it is autonomous. An agent created, connected or deployed outside applicable organizational controls can become shadow AI.

Can an approved AI tool still create governance problems?

Yes. Tool approval does not mean that every prompt, workflow, agent or AI-assisted process operating through that tool is consistently governed. This is why enterprises increasingly need to distinguish AI asset governance from AI execution governance.

What is the difference between shadow AI and shadow IT?

Shadow IT concerns technology adopted outside established IT controls. Shadow AI is closely related but introduces additional governance questions around models, prompts, context, outputs, agents and AI-mediated actions. Discovering an application may be sufficient to identify much of a shadow-IT problem. With AI, discovering the application may still leave the organization unable to explain what AI-mediated work occurred inside it.

What percentage of employees use shadow AI?

There is no single defensible universal percentage, because studies measure different populations and behaviors. Netskope's 2026 telemetry found 30% of observed enterprise AI users using only personal AI applications and another 14% using both managed and personal applications. Other surveys measure policy violations, organizational governance or breach involvement rather than the same behavior, so the figures are not interchangeable.

What does shadow AI cost?

IBM's 2026 breach research found that among the 602 breached organizations studied, breaches involving shadow AI averaged $5.39 million, compared with a $4.99 million global average across all breaches in that year's study. It describes the breaches in that study, not an expected loss for every organization.

Is shadow AI illegal?

Not inherently. Legal and regulatory consequences depend on what AI is used for, which information is processed, contractual obligations, jurisdiction, industry and applicable AI or data-protection requirements. Shadow AI can nevertheless make compliance harder because the organization may lack visibility, records, controls or accountable ownership.

How do you detect shadow AI?

Organizations can use network and proxy telemetry, CASB and SASE controls, endpoint and browser monitoring, identity signals, AI asset discovery, procurement data and employee disclosure. Modern discovery increasingly needs to cover agents, APIs, MCP servers and local AI infrastructure as well as browser-based AI applications.

Does an AI acceptable-use policy stop shadow AI?

Not by itself. Policies establish organizational rules and authority, but they do not automatically provide an approved alternative, detect violations or enforce controls at the point of use. Effective governance combines policy with discovery, usable sanctioned capabilities, technical controls, ownership and monitoring.

Should companies block unauthorized AI?

They should block AI use where the risk justifies it, but blocking should not be the entire shadow-AI strategy. The business task that caused the employee to seek AI still exists. Enterprises should pair appropriate restrictions with governed alternatives that adequately serve legitimate work.

Who owns shadow-AI governance?

Responsibility commonly spans security, IT, privacy, legal and compliance, AI governance, and the business functions performing the work. The important requirement is explicit accountability rather than assuming shadow AI belongs exclusively to one function.

How does PromptFluent help enterprises govern shadow AI?

PromptFluent addresses the AI execution governance layer. Security and discovery technologies can identify unauthorized AI applications and other unmanaged AI assets. PromptFluent helps enterprises manage the prompts, workflows, governance practices and execution intelligence involved in putting AI to work. That makes PromptFluent complementary to shadow-AI discovery rather than a replacement for it.

Does PromptFluent detect unauthorized AI applications?

PromptFluent is not a network or endpoint shadow-AI discovery product. Security technologies are better suited to discovering traffic, applications, accounts, agents and data movement outside the PromptFluent environment. PromptFluent addresses what happens as enterprises establish a governed execution path for AI work.

How does prompt governance relate to shadow AI?

Business-critical prompts can remain fragmented and poorly governed even inside sanctioned AI platforms. Prompt governance brings management discipline to those instructions by treating them as enterprise assets rather than disposable text. This addresses a governance problem that can persist after unauthorized tools have been eliminated.

How does AI workflow governance relate to shadow AI?

AI-supported work increasingly combines prompts, models, context, human decisions, tools and multiple execution steps. When those workflows develop independently, organizations can lose visibility into how AI-assisted work is being performed even when individual technologies are approved. AI workflow governance extends governance from the AI asset into the business process.

Can PromptFluent help move an organization from shadow AI to governed AI?

PromptFluent can support the governed execution portion of that transition. A useful progression is: Shadow AI, Visible AI, Sanctioned AI, Governed AI, Governed AI Execution. Security and discovery technologies help expose unmanaged AI. Enterprise governance determines what should be permitted. PromptFluent addresses the infrastructure and governance needed for the prompts and workflows through which sanctioned AI is executed.

Glossary

Shadow AI glossary

Shadow AI
AI use, development or deployment for organizational work outside sufficient organizational approval, visibility or governance.
Shadow IT
Technology adopted or used outside established IT approval and management processes.
Sanctioned AI
AI systems or uses that an organization has formally permitted under applicable policies and controls.
AI agent
An AI-enabled system capable of pursuing objectives and performing actions using models, tools or external systems.
MCP server
Infrastructure implementing the Model Context Protocol to make tools, resources or capabilities available to compatible AI applications.
AI agent sprawl
Proliferation of AI agents without sufficient coordination, ownership, lifecycle management or rationalization.
Prompt governance
Organizational management and governance of prompts as reusable AI execution assets.
AI workflow governance
Governance of the multi-step processes through which AI participates in organizational work.
AI execution governance
Governance of how AI-mediated work is actually executed, including prompts, workflows, models, versions, ownership, approvals and execution evidence.
Prompt Debt
Accumulated organizational consequences of fragmented, inconsistent, outdated or poorly governed prompt practices.
AI Execution Debt
Accumulated unmanaged, inconsistent, fragmented, outdated, poorly governed or unmeasured AI execution practices.
Shadow AI Demand Model
PromptFluent's framework for interpreting shadow-AI activity as evidence of a real business task, a failure in the sanctioned path and a gap in organizational visibility.

More definitions in the PromptFluent glossary.

Sources

Every figure on this page, and where it came from

Last evidence verification:

  1. 1

    Microsoft Understand Shadow AI in the Microsoft 365 admin center

    Microsoft Learn, 2026. Current definition and examples covering AI-powered tools and agents, unauthorized coding assistants, local agents, MCP servers and agentic CLIs.

  2. 2

    Netskope Threat Labs Netskope AI Report 2026

    Platform telemetry covering June 2025 – July 2026. Supports the 30% personal-only and 14% mixed managed-and-personal figures, and the expansion of discovery toward agents, MCP servers and local AI infrastructure.

  3. 3

    IBM / Ponemon Institute Cost of a Data Breach Report 2026

    Published July 29, 2026. Research covering 602 breached organizations. Supports the $4.99 million global average breach cost and the 2026 shadow-AI breach findings.

  4. 4

    Cyberhaven Labs 2026 AI Adoption & Risk Report

    Telemetry across 222 companies. Supports the finding that 39.7% of observed AI interactions involved sensitive data, and documents expanding use of agents and coding assistants.

  5. 5

    ISACA 2026 AI Pulse Poll

    Published May 5, 2026. More than 3,400 digital-trust professionals. Supports the findings that 90% believe employees are using AI and 38% report a formal, comprehensive AI policy.

  6. 6

    ISACA Adopted, Not Governed: AI Blind Spot at the Heart of Enterprise Risk

    Published March 23, 2026. Survey of 681 European digital-trust professionals. Supports the 59% incident-halting uncertainty and 11% complete-confidence findings.

  7. 7

    Microsoft 2026 Work Trend Index: Agents, Human Agency, and the Opportunity for Every Organization

    Published May 5, 2026. Survey of 20,000 AI-using knowledge workers across 10 markets. Supports the 26% leadership-alignment finding.

Assess your AI execution governance

Shadow-AI discovery tells you where AI has escaped the governed path. The next question is whether the governed path itself can support repeatable, accountable enterprise AI execution.

Related: AI Governance Hub · AI Governance Framework · Prompt Governance · Prompt Debt