Judging AI governance

What is shadow AI, and how do you detect it?

Short answerShadow AI is the use of AI tools, accounts, features, or agents for company work outside the organization’s approved path. Find it by combining network or CASB discovery, managed-browser signals, endpoint visibility, and gateway records, then give employees an approved tool, a clear policy, and a control at the point of use.

Shadow AI includes a personal chatbot account used for a customer email, an AI feature inside an approved application that nobody reviewed, a model API called with a personal key, and a coding agent used on company source code outside the approved path. The defining issue is missing organizational approval and control, regardless of whether the tool is free, paid, installed, or reached in a browser.

Why shadow AI happens

People choose a tool that solves an immediate problem. Shadow AI grows when the approved route is unclear, slow, or absent, when policy names risks without naming an approved tool, and when an AI feature appears inside software the company already uses. Personal accounts and personal API keys make that route easy to take.

Coding agents belong in the same inventory as browser chat. A developer can run an assistant from an editor or terminal and send source code, configuration, logs, and command output to a model provider. The secure Claude Code guide shows the request path for one coding tool.

The risks of shadow AI

  • Customer, employee, financial, legal, health, or company data can leave through a personal account with terms and settings the company has not approved.
  • A coding agent can receive source code, logs, configuration, credentials, or command output outside the approved route.
  • The company can lose the request record needed to investigate an exposure, verify which account was used, or show which control ran.
  • AI output can reach a customer, codebase, document, or decision without the review required by company policy.
  • A team can depend on a tool, connector, or model before security, legal, procurement, and the business owner have evaluated it.

Review Is ChatGPT safe for work? for plan-specific training, retention, and encryption details. Use the PII redaction guide to define and test the data boundary before an LLM call.

How companies detect shadow AI

Start with an inventory question: which AI destinations, applications, accounts, and model APIs are used for company work? Each detection category sees a different part of the path. Compare findings with the approved-tool list before treating an observed connection as a policy breach.

  • Network or CASB. Shows connections to cataloged cloud and generative AI applications in observed company traffic, with app and usage signals available to the deployed system. Coverage: the network, proxy, log source, and application catalog. Personal devices and traffic outside those sources require another signal.
  • Managed browser extension. Shows browser requests within the extension’s declared permissions and host access. Coverage: enrolled browsers, granted permissions, allowed hosts, and the browser APIs used. Desktop applications and terminal tools require another path.
  • Endpoint. Shows application use and network events observed on managed devices, including traffic created outside a browser. Coverage: enrolled devices and the events the endpoint product collects. Personal and unmanaged devices sit outside that view.
  • AI gateway. Shows requests that applications, coding agents, or browser traffic route through the gateway, plus the policy result and request record the gateway produces. Coverage: configured routes. Pair gateway records with discovery signals to find AI traffic that uses another route.

Microsoft documents network and CASB discovery for generative AI applications, including catalog-based application identification and usage review. Its endpoint integration supplies device network events and application usage. Chrome documents that an extension can observe and analyze requests only where its permissions and host access apply. SUPERWISE documents browser-extension, environment-variable, CLI proxy, and gateway routes for traffic configured to use Sentinel. Sources were read on 2026-10-07.

What to do after detection

  1. Confirm the business task, tool, account type, people, data, and route involved.
  2. Classify the finding against the company’s approved-tool and restricted-data rules.
  3. Give employees an approved tool that meets the business need and is practical to reach during work.
  4. Publish an AI acceptable use policy that names approved tools, restricted data, review, reporting, and an owner.
  5. Put a control in the browser, endpoint, network, or gateway path selected for the risk, and record what that control covers.
  6. Test the approved route with synthetic data, review the resulting record, and repeat the inventory on a defined schedule.

The existing answer to Should a company ban AI at work? explains why an approved path matters. The AI glossary defines the gateway, guardrail, policy, and runtime terms used here.

Where Sentinel fits

SUPERWISE® Sentinel replaces emails, phone numbers, account numbers, and API keys with placeholders before a prompt leaves the PC, and logs every request routed through it. It does not redact names or passwords. Use discovery signals to identify other routes, then connect approved browser, application, and coding-agent traffic to the governed path.

Frequently asked questions

What is shadow AI?
Shadow AI is the use of AI tools, accounts, features, or agents for company work outside the organization’s approved path, review, and controls.
What are examples of shadow AI?
Examples include a personal chatbot account used for company work, an unreviewed AI feature inside a business application, a model API called with a personal key, and an unapproved coding agent used on company source code.
How do companies detect shadow AI?
Companies combine network or CASB discovery, managed-browser signals, endpoint visibility, and AI gateway records. They compare the observed tools and routes with the approved inventory and investigate coverage gaps.
How do you prevent shadow AI?
Give employees an approved tool that meets the business need, publish a clear AI use policy, put a control in the relevant request path, and review discovery and gateway records on a defined schedule.

Sources

  1. Microsoft Learn, Manage generative AI apps for your organization. Read 2026-10-07.
  2. Microsoft Learn, Investigate apps discovered by Microsoft Defender for Endpoint. Read 2026-10-07.
  3. Chrome for Developers, chrome.webRequest API. Read 2026-10-07.
  4. SUPERWISE docs, Connect your applications. Read 2026-10-07.
  5. SUPERWISE docs, Gateway reference. Read 2026-10-07.

Reviewed