TL;DR: Shadow AI now accounts for 89% of generative AI use in enterprises, with unsanctioned tools creating data leakage, compliance, and intellectual property risks as employees route sensitive work through unmanaged apps, according to JumpCloud. Blocking access alone does not solve the governance problem because discovery, policy, and approved alternatives must replace ad hoc prohibition.
At a glance
What this is: This is an analysis of Shadow AI governance gaps, with the key finding that unsanctioned enterprise GenAI use is widespread and creates data, compliance, and IP risk.
Why it matters: It matters because identity, access, and governance teams need visibility and controls around unsanctioned AI use before sensitive data and approved workflows are bypassed.
By the numbers:
- 89% of generative AI use in enterprises today happens as Shadow AI, according to JumpCloud.
Context
Shadow AI is the use of generative AI tools and apps without IT oversight or approval. In enterprise terms, that makes the problem an identity and governance issue, not just an acceptable-use issue, because workers are moving sensitive work into ungoverned external services.
The core failure is that blocking tools alone does not create control. Once unsanctioned GenAI becomes part of day-to-day work, IT needs discovery, policy, monitoring, and approved alternatives to regain visibility and steer usage into governable channels.
Key questions
Q: What breaks when employees use shadow AI for work tasks?
A: Shadow AI breaks identity visibility and lifecycle control. Employees can create or use AI accounts, connect them to work data, and move sensitive information outside approved governance. That leaves security teams unable to reliably inventory the identity, review its access, or revoke delegated permissions when the business need ends.
Q: Why do unsanctioned AI tools create compliance risk for IAM teams?
A: They move employee data into third-party systems that may sit outside approved access, logging, and retention controls. IAM teams are affected because identity determines who can submit data, from which device, and under what policy. When those conditions are unclear, compliance, auditability, and accountability all weaken at the same time.
Q: How do you know if shadow AI governance is actually working?
A: You know it is working when you can see where AI is used, what data it touches, what actions it can take, and whether those actions are blocked or approved in real time. If usage is still being discovered through incidents or audits, governance is lagging behind adoption.
Q: Should organisations block AI tools or enable them safely?
A: Organisations should enable AI safely rather than rely on blanket blocking. Bans often push employees toward personal accounts and unmonitored tools, which reduces visibility and increases risk. A safer model combines approved AI paths, data classification, monitoring, and clear enforcement for prohibited content.
Technical breakdown
How shadow AI enters enterprise workflows
Shadow AI usually appears through ordinary business behaviour, not malicious intent. Employees adopt external GenAI tools to speed up writing, research, design, or support tasks, then paste in data that was never meant to leave governed systems. The control problem is that these tools sit outside identity management, so IT cannot reliably see which account, workflow, or data set is being used. That makes the issue less about banning a category and more about regaining observable access paths across browsers, SaaS sessions, and cloud activity.
Practical implication: teams need discovery that can identify unsanctioned GenAI use across user workflows, not just block a shortlist of domains.
Why data exposure and IP leakage are governance failures
When employees place source code, customer data, or proprietary material into external AI tools, the organisation loses control over where that information is processed, retained, or reused. That matters for both confidentiality and legal exposure, because the governance boundary shifts from internal policy to a third-party service agreement and its data handling terms. The article’s examples show that the risk is not hypothetical: a single prompt can move regulated or valuable information outside enterprise oversight in seconds.
Practical implication: governance teams should classify which data types are never permitted in external GenAI prompts and enforce that policy consistently.
Why blocking alone fails for shadow AI
A block-first model assumes that if a tool is denied, the behaviour disappears. In practice, users route around controls when a tool solves a business problem they value. That is why the article argues for a three-phase response: discovery to surface usage, governance to set rules, and approved alternatives to make compliant use realistic. This is the same pattern identity teams see in other shadow IT problems. When the sanctioned path is slower than the unsanctioned one, prohibition simply pushes the risk into blind spots.
Practical implication: replace blanket prohibition with discovery-backed governance and sanctioned AI options that employees will actually use.
Threat narrative
Attacker objective: The objective is not necessarily a direct attacker action, but the consequence is uncontrolled disclosure of enterprise data and intellectual property to outside services.
- Entry occurs when employees adopt unsanctioned GenAI tools through normal work channels rather than approved IT pathways.
- Sensitive prompts expose proprietary data, code, or regulated information to an external service outside enterprise oversight.
- Impact follows as data leakage, regulatory exposure, and loss of intellectual property control spread across business workflows.
Breaches seen in the wild
- OmniGPT breach claim 2025: A hacker claims to have leaked 34 million OmniGPT AI chat messages holding users' API keys and credentials; OmniGPT has not confirmed it.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Shadow AI is an identity governance problem before it is an AI problem. The central issue is that users are making trust decisions outside approved governance channels, which means the organisation cannot reliably see, classify, or constrain where sensitive work goes. Once that happens, the control failure is not just policy noncompliance, it is the absence of a governable identity boundary around AI use. Practitioners should treat shadow AI as unmanaged access to external processing.
Discovery is the prerequisite control because you cannot govern what you cannot see. Network monitoring, CASBs, browser telemetry, and log review are all visibility mechanisms, but they serve the same larger purpose: turning hidden AI usage into something that can be assigned policy and ownership. Without discovery, acceptable-use rules remain aspirational, and every downstream control is operating blind. The practitioner conclusion is straightforward: detection must precede restriction.
Blocking shadow AI does not solve the enterprise productivity pressure that created it. Employees adopt unsanctioned tools because they remove friction, not because they are trying to bypass governance. That means the durable answer is a governed adoption path with clear usage boundaries, acceptable data classes, and sanctioned alternatives. The implication for identity and access teams is that control design has to compete with convenience, or it will be bypassed.
AI governance now sits inside the same lifecycle discipline used for human and non-human access. The article’s recommendations map cleanly to policy definition, monitoring, and access control, which are familiar IAM and governance primitives. What changes is the subject being governed: prompts, sessions, and external AI services become part of the access surface. Practitioners should fold AI usage into the same governance model they already use for high-risk SaaS and third-party access.
Shadow AI creates an enterprise-wide trust debt that compounds over time. The longer unsanctioned use continues, the more data, workflows, and business decisions are routed through channels IT does not control. That accumulation makes the governance gap harder to close later because the organisation must inventory behaviour before it can remediate it. The practitioner conclusion is to treat unmanaged AI use as an accumulating exposure, not a one-off policy exception.
From our research library:
- Generative AI use specifically increased from 33% in 2023 to 79% in 2025, according to McKinsey’s Global Surveys on the State of AI.
What this signals
Shadow AI turns GenAI adoption into an identity and governance problem. As employees embed external AI services into everyday work, the control point shifts from the application layer to the usage layer. IT teams need discovery and policy enforcement that can follow people, sessions, and SaaS behaviour instead of assuming approved tools are the only path.
Approved alternatives matter because prohibition alone creates blind spots. When users have a productivity need and no sanctioned route, they will create one. The practical response is to define allowed data classes, make compliant workflows easier than shadow usage, and monitor for drift as new AI tools enter the environment.
For practitioners
- Build shadow AI discovery into routine monitoring Trace unexpected traffic to known GenAI endpoints, review SaaS login activity, and inspect browser-based usage patterns so unsanctioned tools become visible in normal operations.
- Define acceptable AI use by data class Set explicit rules for which data types may never be placed into external AI tools, including code, customer information, and proprietary content.
- Create sanctioned alternatives for common workflows Offer approved GenAI options for content drafting, support, and knowledge work so employees have a compliant path that is easier to use than shadow tools.
- Monitor activity logs for unsanctioned AI usage Review logs for ChatGPT, DALL-E, and similar services, then correlate usage with departments, projects, and sensitive workflow locations.
- Update governance policy as AI tools change Reassess acceptable use, access controls, and employee guidance as new GenAI services appear and existing ones add new data-handling behaviours.
Key takeaways
- Shadow AI is not just an acceptable-use issue. It is a governance gap that allows enterprise data and intellectual property to move into unmanaged external services.
- The article’s core evidence is that 89% of generative AI use in enterprises happens through Shadow AI, which makes visibility the first control problem.
- Discovery, policy, monitoring, and approved alternatives are the controls that change the outcome. Blocking alone leaves the underlying business demand untouched.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack surface, NIST AI RMF and NIST CSF 2.0 set the technical controls, and ISO/IEC 42001:2023 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI09 — Human-Agent Trust Exploitation | Shadow AI use hinges on workers trusting external AI services with sensitive prompts. |
| Recommendation — Reduce trust exploitation by restricting what users can place into external AI sessions. | ||
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Employees are using external AI services as unsanctioned non-human identities. |
| Recommendation — Treat shadow AI as unmanaged NHI use and inventory where human users invoke it. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is fundamentally about establishing accountable AI governance. |
| Recommendation — Define AI governance ownership, policy, and accountability before scaling enterprise use. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Approval and authorization boundaries are the control gap behind shadow AI use. |
| Recommendation — Align AI access paths to authorised entitlements and remove unsanctioned routes. | ||
| ISO/IEC 42001:2023 | A.4 — Organisational context | Shadow AI governance fits AI management system scope and oversight. |
| Recommendation — Embed shadow AI into the AI management system scope and governance review cycle. | ||
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Acceptable Use Policy: An acceptable use policy defines which data, tools, workflows, and actions are permitted for an identity or system. For AI governance, it becomes the boundary that turns vague intent into enforceable scope, which auditors and security teams can test against actual runtime behaviour.
- Discovery Controls: Discovery controls are the monitoring mechanisms used to reveal previously hidden systems, sessions, or services. In shadow AI programs, they include logs, browser telemetry, network analysis, and CASB signals that expose unapproved AI usage.
- Governed AI Adoption: Governed AI adoption is the practice of enabling AI use through approved tools, policy boundaries, and monitoring rather than blanket prohibition. It aims to preserve productivity while keeping data handling, access, and accountability inside the organisation's control plane.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org