Shadow AI: The Board's Guide to Governing It
Shadow AI is the use of artificial intelligence tools, such as public chatbots, AI note-takers, browser extensions and self-built agents, outside an organisation's approved systems and governance. It is the AI form of shadow IT, with one important difference: the risk travels in what people type and what they connect, not just in what they install.
In September 2026 the UK's National Cyber Security Centre published guidance on the hidden risks of shadow AI, citing research that 71% of employees have used AI tools their employer has not approved. A separate survey of more than 1,000 UK senior decision-makers, reported the same week, found that 88% believe external AI tools are being used inside their organisation and 51% fear staff are feeding sensitive company data into them. More than a quarter of those leaders, all directly involved in AI decisions, had not heard the term shadow AI before they were asked.
That combination is the real finding for boards. Adoption is ahead of visibility, and visibility is ahead of governance. This guide sets out what shadow AI is, why banning it fails, what it exposes the business to, and how to bring it into the open without losing the productivity that drove people to it in the first place.
What is shadow AI?
Shadow AI covers any AI capability used for work that the organisation has not assessed, approved or recorded. In practice it rarely looks like a security incident. It looks like people getting their jobs done faster:
- A commercial manager pasting a customer contract into a public chatbot to summarise the termination clauses.
- An AI note-taker joining a leadership call because one attendee connected it to their calendar.
- A finance analyst running an ERP export through a browser extension to build a variance commentary.
- A developer using an unapproved coding assistant on proprietary source code.
- A team building its own agent and connecting it to a shared mailbox or a customer database.
None of these people think they are taking a risk. Most think they are being efficient, and they are right. That is what makes shadow AI a governance problem rather than a discipline problem.
How shadow AI differs from shadow IT
Boards have managed shadow IT for twenty years, so it is tempting to treat this as more of the same. Three differences make it harder.
The data leaves in the prompt. Shadow IT usually meant an unapproved application that could be found on an asset register or a firewall log. Shadow AI needs nothing installed. Confidential information leaves the business the moment it is pasted into a text box, and depending on the service's privacy settings it may be stored, retained or used to improve the model.
The output flows into decisions. An unapproved file-sharing tool stored data. An unapproved AI tool produces analysis, summaries and figures that end up in customer emails, board papers and investment cases, with no record of where they came from or whether anyone checked them.
Agents act with borrowed authority. The NCSC highlights the step from chat tools to AI agents as the more serious risk. An agent works with the access of whoever set it up. If it is poorly governed and then compromised, an attacker inherits that access, whether that is a finance system or a customer database.
Shadow AI is a signal, not a disciplinary issue
People turn to unapproved tools because the approved route does not meet their need, is too slow, or does not exist. The NCSC's own advice is to understand why staff are using these tools before deciding what to do about them.
Read that way, a map of shadow AI is also a map of demand. It shows which processes your people already believe are ready for AI, which teams are most motivated to change how they work, and where the approved toolset is falling short. Few organisations get that insight so cheaply. The mistake is to treat it purely as a threat and waste it.
Why banning AI does not work
The instinctive board response is to block public AI services and issue a policy. It rarely holds. Staff move to personal phones and home laptops, the organisation loses what little visibility it had, and the most capable people, who are usually the heaviest users, conclude that leadership does not understand how work is now done.
There are broadly three options, and only one of them ends well.
| Approach | What it looks like | What usually happens |
|---|---|---|
| Block | Public AI services blocked at the network edge, a prohibition in the acceptable use policy. | Use moves to personal devices. Visibility falls to zero. Risk is hidden, not removed. |
| Approve case by case | Staff request individual tools, IT or security assesses each one. | A growing queue, slow decisions, and shadow use continues while people wait. |
| Govern | An approved, usable toolset, rules set by data sensitivity, a register of use cases and a named owner. | Use moves into the open, risk becomes measurable, and productivity gains are kept. |
Governing is more work than blocking in the first month and far less work in every month after. It is also the only option that gives the board something it can actually oversee.
The risks boards actually carry
Data protection. Personal data entered into a consumer AI service is being processed outside your agreed contracts and controls. Under UK GDPR the organisation remains accountable for that processing, whether or not it knew it was happening.
Confidentiality and intellectual property. Customer contracts, pricing models, deal documents and source code are exactly the material people find most useful to put into AI tools, and exactly the material the business can least afford to lose control of.
Decision quality. AI output is fluent whether it is right or wrong. When unverified output reaches a board pack or a customer, the error carries the organisation's name. We cover why this gets worse at scale in our piece on data readiness for AI.
Agent access. Self-built agents connected to mailboxes, drives and business systems extend the attack surface in ways endpoint controls will not catch, because the agent is using legitimate credentials.
Regulation. For organisations operating in or selling into the EU, uncatalogued AI use makes it very hard to show which obligations apply. Our guide to EU AI Act conformity assessment sets out where those obligations bite.
Transaction exposure. Buyers' technology due diligence increasingly asks how AI is used and governed. Unrecorded AI use, or company data sitting in services nobody can account for, becomes a finding, and findings become price chips. It belongs on the same list as the other issues covered in technology exit readiness.
How to find shadow AI in your organisation
You cannot govern what you cannot see, but discovery does not need a large programme. Five sources will give most organisations a reliable picture within a fortnight.
- Ask first, without blame. A short, anonymous survey framed as an amnesty: which tools do you use, for what, and with what kind of data. People will tell you if they believe the purpose is to provide better tools rather than to discipline them.
- Follow the money. Expense claims and company card statements show AI subscriptions that individuals or teams have bought for themselves.
- Check identity and network data. Cloud application discovery, sign-ins to third-party services using corporate accounts, and permissions granted to external apps all reveal tools in active use.
- Look at meetings and browsers. AI note-taker bots joining calendars and AI browser extensions on managed devices are two of the most common and least visible routes.
- Map each use to its data. For every tool found, record which class of data it touches. A tool drafting marketing copy from public information is a very different risk from one summarising HR cases.
From shadow to sanctioned: a governance model that works
The aim is not a thicker policy. It is a small number of controls that make the safe route the easy route. Our AI governance framework sets this out in full; the essentials are these.
Provide an approved route people will actually use
If the sanctioned tool is slower or weaker than the one on someone's phone, shadow use continues. Select approved tools against the real demand the discovery exercise surfaced, and make them available quickly, even on an interim basis.
Set rules by data, not by tool
Tools change monthly; data classifications do not. A simple rule set works best: public information can go into approved general tools, internal information only into enterprise-licensed tools with data protection terms in place, and confidential or personal data only into specifically approved use cases.
Keep a use-case register with a named owner
Every approved AI use case should have a business owner, a record of the data it uses and a statement of how its output is checked. This is also the evidence a regulator, auditor or buyer will ask for.
Bring agents under identity controls
Treat agents as identities in their own right: least-privilege access, logging of what they do, and a named human accountable for each one. The NCSC's warning on agents inheriting privileges is the part of this issue most likely to become an incident.
Report it to the board
Four measures are enough to start: approved use cases in operation, the share of staff with access to an approved tool, the trend in shadow use from repeat discovery, and incidents or near misses. For boards still building their understanding of the technology itself, our guide to agentic AI versus generative AI is a useful companion.
Making it stick: governance is a change programme
Most AI policies fail for the same reason most transformation programmes do: they are written, launched and left. Behaviour does not change because a document exists. It changes when managers understand the rules, when the approved tools are better than the workarounds, and when someone keeps checking.
That is why we treat shadow AI as a change challenge first and a technology challenge second. Our Embedded Change Model™ places senior practitioners alongside your management team to build the governance, the habits and the internal capability together, so that it holds after we step away rather than decaying into another unread policy.
A note for private equity sponsors
For a sponsor, shadow AI sits on both sides of the investment case. The value creation plan may be counting on AI-driven productivity, yet unmanaged use across the portfolio is a diligence liability waiting for exit. A quick discovery exercise at each portfolio company, repeated before a sale process, turns an unknown into a governed asset with evidence behind it.
Where to start: a 30-day plan
- Week one: run the amnesty survey and pull spend, identity and network data.
- Week two: map each use to its data class and rank the top risks.
- Week three: approve interim tools for the highest-demand uses and publish the data rules.
- Week four: stand up the use-case register, name an accountable executive and take the first report to the board.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools for work outside an organisation's approved systems, processes and governance. It includes public chatbots, AI note-takers, browser extensions, coding assistants and self-built agents that the organisation has not assessed or recorded.
How is shadow AI different from shadow IT?
Shadow AI is a form of shadow IT, but it is harder to detect and control. Data leaves the business through what people type rather than what they install, AI output flows directly into decisions without any record of its source, and AI agents can act with the access rights of the person who set them up.
What are the main risks of shadow AI?
The main risks are exposure of personal and confidential data, loss of control over intellectual property, unverified AI output influencing decisions, compromised agents inheriting access to business systems, regulatory non-compliance and findings in a buyer's due diligence.
How can organisations reduce shadow AI without banning AI?
Find out what is being used and why, provide approved tools that meet the real need, set rules based on data sensitivity rather than individual tools, keep a register of approved use cases with named owners, and report progress to the board. Making the safe route the easy route is more effective than prohibition.
Should we block ChatGPT and other public AI tools?
Blocking alone usually pushes use onto personal devices, where the organisation has no visibility at all. It can make sense for specific high-risk data or roles, but it should sit alongside an approved alternative, not replace one.
Who should own AI governance at board level?
A named executive should be accountable for AI governance, with the board receiving regular reporting. The day-to-day controls can sit with technology, security and data protection teams, but ownership of the risk and the benefit belongs with the business.
Talk to us
Intology is independent. We do not sell AI licences, implement vendor platforms or take commission, so our view on which tools to approve, which to block and how to govern the rest is not an argument for a product. If shadow AI is already in your business, or you want to know before a buyer does, arrange a confidential conversation with a senior consultant.