Shadow AI: The Risk You Cannot See

An employee pastes a contract into a public assistant to summarize it. A colleague uses an AI app on a personal phone to review a photo of an invoice. A business team activates a generative feature inside software the company already licenses. At home, someone works within earshot of an always-available digital assistant. None of those uses necessarily appears in the corporate AI inventory.
The organization may have an AI policy, a governance committee, and a list of approved tools and still be blind to a material part of its exposure. That is the core problem with shadow AI: it is not only unauthorized or ungoverned use. It is the gap between the AI the organization believes it uses and the AI that is actually touching its data, processes, and decisions.
For internal audit, that distinction changes the assurance question. It is not enough to review the AI inventory. Auditors should assess whether the process feeding that inventory is capable of finding uses that are not there yet.
Shadow AI is broader than a prohibited tool
Shadow AI is often pictured as employees using public generative AI tools without approval. That is useful shorthand, but it is too narrow. The problem can emerge through an unapproved tool, a personal account, a device or environment outside corporate controls, or an AI capability that appeared inside software that had already been approved.
That is why “unapproved” and “unknown” are not synonyms. Management may know about an experiment and tolerate it temporarily; a legitimate use may also never reach the registration process. COSO describes shadow AI as unauthorized or ungoverned AI outside formal oversight and, in its 2026 guidance, highlights the low barrier to entry of generative AI.
The first audit question therefore should not be, “Are employees using prohibited tools?” A better question is: “How reasonable is management's belief that it knows the universe of AI use?”
This also separates shadow AI from shadow IT. Both can arise outside approved technology processes, but AI adds questions about what information enters the model, what content it produces, what decisions it influences, which provider processes the data, and how much human judgment is delegated.
The perimeter no longer ends at the corporate laptop
An employee may use an approved service through a personal account, losing enterprise configurations, logging, retention controls, or contractual protections. They may move information into an AI app on a personal smartphone, photograph a document, or use AI capabilities embedded in the mobile operating system, browser, or productivity apps.
Remote work adds another layer. Home digital assistants, personal transcription tools, and meeting services can process audio, conversations, or documents without belonging to the managed environment. Working from home is not inherently shadow AI; the issue is whether the AI use sits outside the visibility and controls the organization intended to apply.
A subtler problem is AI feature creep. Software may have been approved years ago as a conventional application and later gain summarization, text generation, transcription, semantic search, or agent capabilities. The contract remains known; the AI capability may not be.
The same logic extends to suppliers. A recruitment, customer-service, translation, or document-processing provider may embed AI without the organization interacting directly with a model. Outsourcing the technology does not outsource the exposure.
An inventory works only if it can approximate reality
ISO/IEC 42001:2023 structures AI management around context, accountability, risk, controls, resources, suppliers, operations, monitoring, and improvement. It does not prescribe a single inventory format. The audit implication is more useful: management needs enough visibility to assess risk, assign accountability, and justify control decisions.
A technology-maintained register does not, by itself, demonstrate that visibility. If it depends entirely on voluntary reporting of formal projects, it will overrepresent what is already visible and governed. A useful inventory should identify, at minimum, the use, purpose, owner, data, provider or model, affected process, and criticality; for shadow AI, account type, device or environment, and relevant integrations also matter.
Completeness requires combining signals:
| Discovery source | What it can reveal | Internal audit red flag |
|---|---|---|
| Procurement, expenses, and contracts | Subscriptions and services purchased by business units. | AI capabilities missing from the inventory. |
| Identity, access, and telemetry | SaaS, extensions, and services used from the corporate environment. | Repeated use with no known owner or approval. |
| Surveys, interviews, and declarations | Personal accounts, mobile use, experiments, and embedded features. | AI is part of the work but is not registered. |
| Process walkthroughs | Tasks and decisions where AI is already part of the real workflow. | The process depends on AI although official procedures do not mention it. |
| Third-party management | AI embedded by suppliers. | The business cannot explain relevant models, data, or subprocessors. |
An AI inventory is not credible because it contains many rows. It is credible when the discovery process can reasonably explain what may still sit outside it.
Information can leave through more routes than it appears
“Putting data into AI” no longer means only pasting text into a chatbot. It can include prompts, attachments, screenshots, photographs, source code, contracts, financial information, ERP or CRM extracts, meeting audio, transcripts, audit documents, or metadata.
COSO recommends acceptable-use policies, restricted data categories, training, logging, and monitoring. For shadow AI, the practical question is whether a person knows what may be entered, has an approved alternative, and encounters meaningful friction when leaving the controlled environment.
Internal audit can test whether information classification has been translated into AI-use rules; whether employees distinguish enterprise from personal accounts; whether BYOD and remote-work policies address AI; whether contracts and configurations reflect data-handling expectations; and whether incidents or exceptions lead to control changes.
Shadow AI can signal a governance problem, not just misconduct
Treating every shadow AI case as an employee-discipline issue can hide the root cause. If approved tools are difficult to obtain, approvals take weeks, policies are ambiguous, or no useful alternative exists, the organization itself creates incentives for work to move outside the formal perimeter.
A mature audit finding may therefore be less “Employees are violating policy” and more “The governance model is not responding to how work is actually being done.” The response should be proportionate: block some uses, migrate others to enterprise services, register low-risk cases, or create fast routes for controlled experimentation. Governance that is too restrictive can push activity further into the shadows.
What internal audit should test
The IIA's Artificial Intelligence Auditing Framework encourages internal audit to understand how the organization uses AI and assess governance, risk, and controls. The Global Internal Audit Standards place that work within a risk-based assurance model.
A five-step model turns the concept into practical audit work:
- Discover. Look for public tools, personal accounts, mobile devices, remote-work environments, extensions, embedded features, decentralized purchases, and third parties.
- Reconcile. Compare those signals with the formal inventory and investigate differences.
- Classify. Document owner, purpose, data, criticality, process, provider, account type, and dependencies.
- Govern. Evaluate rules, approvals, technical controls, training, and treatment decisions in proportion to risk.
- Monitor. Review how new uses, vendor changes, newly activated features, and repeat exceptions are detected.
Evidence may include AI and SaaS inventories, SSO data, corporate spending, extension lists, process questionnaires, supplier contracts, exception logs, BYOD policies, and enterprise configurations for generative AI services.
The next version of the problem is already emerging: shadow agents. An assistant produces an answer; an agent may connect to email, files, calendars, enterprise systems, or APIs and take actions. When that capability falls outside formal governance, the question is no longer only what information the AI could see, but what it could do on the user's behalf.
The full sequence is visibility → accountability → risk assessment → control → monitoring. Discovering shadow AI does not solve the problem; it makes governance possible. In an environment where AI can arrive as an application, personal account, embedded feature, home device, or third-party service, visibility is not administrative housekeeping. It is the first condition for regaining control.