🚀 أصبحت CloudSek أول شركة للأمن السيبراني من أصل هندي تتلقى استثمارات منها
اقرأ المزيد
Shadow AI is the use of AI tools, models, agents, or AI features inside an organization without the approval, visibility, or controls of its IT and security teams. It covers an employee pasting a contract into a personal chatbot account, a developer connecting an AI API into a product without review, and a team running a self-hosted model server that nobody added to the asset inventory.
Not every case of shadow AI starts with a person choosing a new tool, because vendors and cloud platforms switch AI capabilities on by default. CloudSEK found that enabling the Gemini API on a Google Cloud project silently grants Gemini access to every existing API key on that project, with no warning or confirmation. Scanning the top 10,000 Android apps, CloudSEK researchers identified 32 hardcoded Google API keys across 22 apps with more than 500 million combined downloads, keys that now open AI endpoints their owners never decided to expose.
Shadow AI takes several distinct forms, and each one leaves a different trace for security teams to find.

Employees who sign in to ChatGPT, Gemini, Claude, or similar assistants with personal accounts, a pattern called bring your own AI (BYOAI), move company data into services governed by consumer terms instead of an enterprise contract. Prompts, uploaded files, and chat history sit outside the organization's retention, audit, and deletion controls.
Collaboration suites, CRMs, note-taking apps, and design tools now ship AI assistants that vendors switch on through routine updates. The application stays approved, yet a new AI feature starts reading documents, meetings, or customer records without a separate risk review. The Gemini API key finding follows the same pattern at the cloud platform level.
AI writing, summarizing, and meeting extensions request browser permissions that let them read page content on the sites where they run, including webmail, CRMs, and internal portals. An extension with broad host permissions sends whatever it reads to its own backend, and many organizations have no inventory of which extensions employees installed.
Developers adopt coding assistants and AI agents that read repositories, run terminal commands, and call internal APIs. Agents connected through OAuth grants or personal access tokens act with the permissions of the person who connected them, so an unreviewed agent inherits access that security teams never approved for an AI system.
Engineering teams stand up model servers such as Ollama, vLLM, and LLM proxy gateways, plus Model Context Protocol (MCP) servers that connect AI agents to internal tools and data. Ollama's API ships without built-in authentication, so a server bound to a public interface answers anyone who finds it. These assets form the infrastructure side of shadow AI and expand the organization's AI attack surface in ways endpoint and SaaS monitoring never see.
Product teams add OpenAI, Anthropic, Gemini, or open-model APIs to applications and scripts, then store the keys in code, CI pipelines, or mobile apps. A leaked AI API key exposes usage billing, stored files, and any data sent through that account.
Shadow AI is a subset of shadow IT, which covers any software, hardware, or cloud service used without IT approval. The two differ in how data moves, where the tools hide, and what the tools do on their own.
One in five organizations reported a breach due to shadow AI in IBM's 2025 breach research, and organizations with high levels of shadow AI saw average breach costs $670,000 higher than those with low or no shadow AI. Shadow AI incidents compromised personally identifiable information in 65% of cases and intellectual property in 40%, against global averages of 53% and 33%. Among organizations that reported an AI-related breach, 97% lacked proper AI access controls, and 63% of breached organizations had no AI governance policy or were still developing one.
Enterprise controls are closing part of the personal-account gap, according to Netskope's 2026 threat report, which found that the share of AI users on personal AI apps fell from 78% to 47% over the past year, while organization-managed accounts climbed from 25% to 62%. The same report counts an average of 223 generative AI data policy violations per month in a typical organization, and Netskope now tracks more than 1,600 generative AI apps.
Shadow AI risk runs in two directions: data flows out to AI services the organization never assessed, and new AI assets open paths into the organization that no one is watching.
Employees paste source code, contracts, customer records, and meeting notes into AI tools to get better answers, and that data leaves the organization's control the moment it is submitted. Samsung saw this within weeks of allowing ChatGPT in its semiconductor division on March 11, 2023: The Register reported three incidents involving source code from a semiconductor database program, code for identifying defective equipment, and a recorded meeting submitted to generate minutes. Samsung responded by capping uploads at 1,024 bytes per question and later restricted generative AI tools on company devices.
AI tools run on keys and tokens, and those secrets end up in repositories, notebooks, mobile apps, and chat prompts. A single exposed key gives an attacker the account's quota, stored files, and conversation history—the same exposure pattern behind many other data leak incidents.
Model servers, vector databases, and MCP servers deployed for quick experiments rarely get authentication, network restrictions, or patching. An internet-facing MCP server exposes the tools an agent uses, such as file readers, HTTP fetchers, and database connectors, and any of those tools becomes an initial access attack vector once an outsider can call it. The MCP security risks in this layer grow with every new agent integration.
AI agents granted OAuth access to mailboxes, drives, and ticketing systems read untrusted content as part of their job. Instructions hidden in an email, web page, or document trigger prompt injection, and an agent with write access then forwards data or changes records on the attacker's behalf.
Unvetted AI tools pull in model files, plugins, SDKs, and proxy libraries from third parties, each with its own vulnerabilities and maintainers. A compromised package in that chain reaches every environment that installed it, the core concern of AI supply chain security.
Every major AI governance framework assumes an organization knows exactly which AI systems it runs and who owns them. The NIST AI Risk Management Framework starts with its Govern and Map functions, and ISO/IEC 42001 requires a managed inventory of AI systems within an AI management system. Under the EU AI Act, Article 4 on AI literacy has applied since February 2, 2025, requiring providers and deployers to support AI literacy among staff who operate and use AI systems. Undocumented AI use sits outside all of these programs, and personal data sent to an unassessed provider creates exposure under GDPR, HIPAA, and PCI DSS.
Detecting shadow AI requires combining several data sources, because each one sees a different form and misses the others.
Security teams get the fastest baseline by pulling 90 days of DNS and proxy logs against a maintained list of AI domains, then comparing the results with the approved AI tool list and the SaaS OAuth grant inventory. A short, non-punitive employee survey fills the remaining gaps, because people disclose tools they believe help them work when disclosure carries no penalty. CloudSEK's guide to SaaS security covers the OAuth grant reviews that surface AI agents inside collaboration suites.
Blanket bans push AI use onto personal devices, so effective programs make the approved path faster than the unapproved one and put technical controls behind it:
An unauthenticated MCP server shows how shadow AI infrastructure turns into an attack path. In a June 2026 case study, CloudSEK's AIVigil found a publicly accessible MCP server attached to a Spring Boot application that powered voice and messaging features on a customer-facing communications platform. The server let anyone enumerate and run its tools without authentication. AIVigil confirmed that an audio proxy tool accepted arbitrary URLs, which reached the AWS instance metadata service and returned live IAM role credentials, and that a file-reading path exposed plaintext database credentials.
AIVigil continuously discovers AI-enabled applications, model-serving APIs, MCP servers, and AI infrastructure such as vector databases and AI pipelines, then assesses them for access control gaps, misconfigurations, prompt injection vulnerabilities, and data exposure. This coverage complements SSE and DLP controls that monitor employee prompts by identifying AI assets that teams may have deployed and forgotten, before attackers can exploit them as initial access vectors.
It depends on approval. Using ChatGPT through an enterprise account the company sanctioned is managed AI, while using a personal account for work data is shadow AI.
No, not by itself. Shadow AI becomes a legal problem when the data involved is regulated, such as personal data under GDPR or health records under HIPAA.
No. New AI tools and features appear faster than any review process, so organizations reduce shadow AI through continuous discovery and fast approvals.
It varies by organization. The CISO leads detection and controls, while the CIO, legal, privacy, and an AI governance committee own policy and tool approval.
No. Blocking AI domains on corporate networks pushes employees toward personal devices and mobile apps, and it misses AI features inside approved software.
Yes, under some consumer terms. Several consumer AI services train on chats unless users opt out, while major providers' enterprise agreements exclude customer data from training.
Passwords, API keys, customer personal data, health records, payment data, unreleased financial results, and proprietary source code should stay out of any AI tool not approved for that data tier.
Yes. Small businesses rely heavily on free AI tools and personal accounts, and they rarely have DLP or SaaS monitoring to see what data leaves through them.
