Shadow AI
Use of AI tools without company approval: sensitive data pasted into chatbots and decisions based on outputs nobody validates.
Full definition
Shadow AI is the use of artificial intelligence tools without company approval or oversight: the employee pasting proprietary code into a public chatbot to debug it, the team summarizing confidential contracts with a free tool, the analysis run on customer data in a service without a contract.
It is the natural evolution of shadow IT with one aggravating factor: beyond account and access risk, there is the destination of the data. Information pasted into a public AI tool leaves the company's control, may be stored outside any policy and, depending on the service, used to train models.
Banning AI does not work: the productivity it offers guarantees usage continues in silence. The effective response combines approved alternatives with contractual guarantees, clear policies on what data may leave, and training specific to these risks.
Related terms
Shadow IT
Tools and services employees use without IT approval. Every invisible account is risk that nobody is watching.
Data leak
Exposure of sensitive information with no attack involved: a misconfigured database, an overshared file, an email to the wrong recipient.
Security awareness
Programs that teach employees to recognize and report threats. Completing courses does not equal changed behavior: that is validated with a retest.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.