AI Shadow IT in the Enterprise: How to Detect It and What to Do Next

AI shadow IT is not the exception, It is the norm. In most medium-sized and large organisations, employees across almost every department are already using AI tools that the IT team does not know about.

Some have downloaded them independently, others are browser extensions, many are AI features embedded in SaaS platforms the organisation already pays for, but which were never assessed before being activated.

The problem is not that people are using AI, the problem is that this use has never gone through any evaluation process. No one knows what data these tools process, what contractual terms apply, or what risks they introduce.

Why AI Shadow IT Is Different

Shadow IT is not new. Unauthorised cloud storage services or SaaS applications purchased without IT approval have existed for years.

What makes AI different is the speed and scale. Free AI tools can be accessed from any web browser within seconds. No installation. No corporate procurement process. No approval.

The journey from “I saw this tool on LinkedIn” to “I’m using it with customer data” can take just a few minutes. Most users have little understanding of what happens to the information they enter or how that information may be processed.

The potential impact is also very different. An unauthorised note-taking application usually presents relatively limited risk. An AI tool that processes customer data, summarises confidential contracts or supports recruitment decisions presents a completely different level of organisational risk.

How to Detect It Without Creating Conflict

The simplest and least intrusive approach is also the most effective: ask.

An anonymous survey asking employees three simple questions: 

  • Which AI tools do you use?
  • What do you use them for?
  • How often do you use them?

These questions can provide an accurate picture of AI adoption within just a few days.

Anonymity reduces self-censorship and usually produces more reliable information than technical monitoring alone.

The way the survey is presented matters as much as the survey itself. It should not be introduced as a compliance audit or the first step towards banning AI tools. Instead, explain its real purpose: to understand how people actually work so the organisation can provide appropriate tools with appropriate safeguards.

Two Additional Ways to Detect AI Shadow IT

Network traffic analysis can reveal regular connections to external AI services such as OpenAI, Anthropic, Google AI or Hugging Face.

This is a useful way to validate patterns of use, but it should not be the starting point. Before carrying out this type of monitoring, organisations should ensure that it is consistent with their legal obligations and internal privacy policies.

Reviewing existing SaaS platforms is often even more revealing. Many services already used by organisations—including Salesforce, HubSpot, Notion, Slack and Microsoft 365—have introduced AI capabilities over the past two years. These features are often enabled by default without anyone formally assessing them. Reviewing contracts and platform configurations frequently uncovers AI systems that are already in use but have never been recognised as such.

What Should You Do With What You Find?

The first step is not to prohibit. It is to provide a safe alternative.

Banning tools that employees genuinely find useful without offering approved alternatives simply drives their use underground, reducing visibility rather than reducing risk. The objective is to govern AI use—not eliminate it.

The second step is to establish a fast approval process.

Employees often use unauthorised tools because requesting approval is slow or impossible. A lightweight approval process—with a simple request form, a documented assessment and a decision within 48 to 72 hours—removes much of the incentive for Shadow IT. When approval is straightforward, most employees are willing to ask first.

The third step is to maintain a clear catalogue of approved AI tools together with their permitted uses.

This is generally far more effective than restrictive policies alone. When employees have trusted alternatives, they have far less reason to seek unapproved solutions.

Explain Why—Not Just What

Policies that people understand are followed far more consistently than policies that are simply imposed.

Explain why a tool has not been approved.

Explain what data it processes.

Explain the risks involved.

Explain why the provider cannot offer the contractual or technical safeguards the organisation requires.

That creates far greater respect for the policy than simply publishing a list of prohibited tools.

Ultimately, AI Shadow IT is not solved through tighter control, It is managed through better judgement.

Teams that understand what is at stake make better decisions than teams that only know what is forbidden.

Frequently Asked Questions

What is AI Shadow IT?

AI Shadow IT refers to the use of AI tools by employees without the knowledge or approval of the organisation’s IT or management teams.

It includes free generative AI tools, browser extensions, mobile applications and AI features built into SaaS platforms that have never been formally evaluated.

How can we audit which AI tools our employees are using?

The most effective starting point is an anonymous employee survey.

This can be complemented by network traffic analysis and a review of existing SaaS platforms.

The objective is not to monitor or punish employees, but to understand how AI is actually being used so it can be governed appropriately.

Should we ban AI Shadow IT?

In most cases, no.

Simply banning tools without offering suitable alternatives rarely works. Employees are likely to continue using them, but with less transparency.

A more effective approach is to establish a clear approval process, maintain a catalogue of approved AI tools with defined conditions of use, and explain why those conditions exist.

Raquel López Hernández, fundadora de Ethiceye y consultora en IA responsable

Raquel López Hernández

Raquel López Hernández is the founder of Ethiceye, a consultant and trainer specialising in responsible AI, AI governance and AI literacy. With a long career in education, she collaborates with the European Commission’s European Digital Education Hub on initiatives relating to AI literacy and ethics.

She has trained teachers from across Europe at the Europass Teacher Academy (Florence) and supports schools and organisations in developing frameworks, policies and strategies to integrate AI in line with their own criteria.

Contact with Raquel López
Privacy Summary

This website uses cookies so that we can offer you the best possible user experience. The information from the cookies is stored in your browser and performs functions such as recognising you when you return to our website or helping our team to understand which sections of the website you find most interesting and useful. You can see our Privacy Policy.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

Analytics

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.