Back to the glossary
    Security conceptsCybersecurity glossary

    Shadow AI

    Use of AI tools without company approval: sensitive data pasted into chatbots and decisions based on outputs nobody validates.

    Full definition

    Shadow AI is the use of artificial intelligence tools without company approval or oversight: the employee pasting proprietary code into a public chatbot to debug it, the team summarizing confidential contracts with a free tool, the analysis run on customer data in a service without a contract.

    It is the natural evolution of shadow IT with one aggravating factor: beyond account and access risk, there is the destination of the data. Information pasted into a public AI tool leaves the company's control, may be stored outside any policy and, depending on the service, used to train models.

    Banning AI does not work: the productivity it offers guarantees usage continues in silence. The effective response combines approved alternatives with contractual guarantees, clear policies on what data may leave, and training specific to these risks.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.