TL;DR: Shadow IT now spans unsanctioned SaaS apps, unmanaged devices, shared files, and browser-based AI tools, with BetterCloud reporting an average of 106 SaaS applications per organisation and 59% of IT teams still concerned about unsanctioned services, according to Safetica and cited research. The governance lesson is straightforward: discovery, data classification, and exposure-based control matter more than blanket bans when users adopt tools faster than approved processes can absorb them.
At a glance
What this is: Shadow IT is expanding across SaaS, AI assistants, devices, and browser extensions, and the article argues that visibility and exposure scoring are the only practical way to manage it.
Why it matters: For IAM, NHI, and broader security teams, the same unmanaged adoption patterns that drive Shadow IT also create account sprawl, offboarding gaps, and unaudited data movement across identity-bound workflows.
By the numbers:
- The average organisation is actually running 106 SaaS applications, which widens the gap between approved inventory and real usage.
- 59% of IT teams remain somewhat or very concerned about unsanctioned tools, showing the issue is already a mainstream operational problem.
- 39.2% of respondents named detection of unauthorized applications and unsanctioned cloud services among their top hybrid and multicloud security challenges.
- 63% of organisations had no AI governance policy or were still developing one, according to IBM's 2025 breach research.
👉 Read Safetica's analysis of Shadow IT and Shadow AI exposure patterns
Context
Shadow IT is what happens when people adopt software, devices, or file-sharing paths outside approved governance because the sanctioned route is too slow or too restrictive. The primary security issue is not the tool itself, but the fact that identity, data, and access controls never fully see the asset, which creates blind spots for inventory, offboarding, and audit.
This matters across IAM, NHI, and human identity programmes because unsanctioned tools often inherit trusted work identities, personal accounts, or browser sessions rather than explicit governance. Once data moves through those channels, the organisation loses ownership, revocation becomes difficult, and the exposure often sits outside normal control review until after the fact.
The article's starting position is typical of mid-sized organisations: a small team trying to govern a fast-moving SaaS and AI sprawl with limited visibility. That is the norm, not the exception.
Key questions
Q: What breaks when shadow IT sits outside identity governance controls?
A: Access reviews, offboarding, and privileged approval workflows lose reliability when shadow IT is outside the system of record. The main failure is not the existence of extra tools, but the inability to inventory, classify, and revoke the identities and entitlements tied to them. That leaves unmanaged access in place even when governance activity appears to be working.
Q: Why do SaaS app integrations create extra risk for IAM teams?
A: SaaS integrations create extra risk because they extend trust beyond the original user session through tokens, API keys, and delegated permissions. Once an integration is active, it can move data and trigger actions even when no one is directly using the app, which makes lifecycle control essential.
Q: What do security teams get wrong about Shadow AI?
A: They often treat Shadow AI as an approval problem for software, when it is usually also an identity problem. The hidden risk can be an undocumented token, an over-permissioned service account, or an autonomous agent with unreviewed reach. Inventory the identity layer before you decide the tool is the issue.
Q: Who is accountable when access to regulated data is mishandled?
A: Accountability usually sits with the covered entity or service provider that owns the data environment, but business associates can also carry direct obligations under HIPAA. In practice, the IAM team, compliance function, and system owner must share responsibility for proving that access was authorized, reviewed, and revoked. The framework, contract, and technical record all have to agree.
Technical breakdown
Why Shadow IT escapes inventory and access review
Shadow IT evades conventional inventory because adoption now happens through self-service sign-up flows, not procurement or software deployment. A work email is enough to create a SaaS account, and browser-based tools require no install at all. That means the organisation may have no asset record, no owner, and no access lifecycle tied to the service. From an identity perspective, the account is often the only durable control point, yet it exists outside central governance. If the team cannot see the tool, it cannot map data exposure, revoke access on offboarding, or evaluate whether the account belongs to a person, a department, or a personal device.
Practical implication: build discovery that inventories services, accounts, and file movement together, not separately.
Why browser-based AI tools change the data loss problem
Generative AI use is a new form of Shadow IT because the user interface looks like ordinary browsing while the risk behaves like unsanctioned data transfer. Users paste drafts, support transcripts, code, and contracts into a session that may retain prompts or reuse inputs in model training. Unlike file sharing, there is often no clear export event and no standard retention control visible to security teams. The security question is therefore not just which AI tools are allowed, but which identities can place regulated or confidential content into them, and under what policy. That intersects directly with identity governance because the employee credential is the entry point, even when the application is outside the approved stack.
Practical implication: classify AI tools by data sensitivity and identity context before you decide whether to allow or block them.
How browser extensions expand privileged access inside the session
Browser extensions are often overlooked because they look small and disposable, yet many request permission to read and modify every page a user visits. That creates a privileged execution layer inside the browser session, where contracts, source code, and internal portals may already be open. In governance terms, extensions behave like lightweight third-party agents embedded in the user workflow. They are difficult to audit, can persist beyond their original purpose, and may access content the security team assumes is only visible to the user. The risk is not simply malicious code, but overbroad consent granted once and forgotten. This is a control problem as much as a threat problem.
Practical implication: review extension permissions as you would third-party access and remove broad page-level read/write rights where possible.
Threat narrative
Attacker objective: The attacker or risk event seeks unaudited access to sensitive business data through identities and tools that the organisation does not govern.
- Entry begins when a user adopts an unsanctioned SaaS app, personal file-sharing account, or browser-based AI tool with a work identity and no procurement trail.
- Escalation occurs when approved data, contracts, code, or client files are uploaded into an account or extension that security teams do not manage.
- Impact follows when sensitive data leaves the governed tenant, remains in an unowned account after offboarding, or becomes subject to retention and reuse outside recovery options.
NHI Mgmt Group analysis
Shadow IT is fundamentally an identity and data governance failure, not a software-compliance issue. The article correctly shows that the risk begins when approved identity pathways are used to reach unapproved services or personal accounts. In practice, that means the control gap sits between access ownership, data classification, and offboarding. Teams should treat unaudited tool adoption as a governance event, not a simple policy violation.
Shadow AI introduces a new version of the visibility gap because the session, not the install, is the control surface. Users can place regulated content into a browser-based assistant without any deployment marker in the endpoint stack. That creates an identity-bound data path that traditional inventory methods miss. The named concept here is session-level data drift: sensitive content leaving governed systems through ordinary authenticated use and ending up in unmanaged retention or training contexts. Practitioners need controls that follow the session and the data, not just the application list.
Browser extensions are a privileged identity problem hiding inside a user productivity problem. Extensions that can read and modify every page effectively gain broad delegated access within the browser session. That is especially relevant where files, customer records, or source code are already open in the same context. For IAM and security teams, the lesson is to govern extension permissions as third-party access, because the effective blast radius is defined by what the extension can see, not by its file size.
Exposure-based governance is the only scalable response for small security teams. The article is right to reject blanket bans as the primary control. A lean team needs to prioritise based on which tools touch sensitive data, which identities created the accounts, and which services are still active after offboarding. That is consistent with NIST-CSF access and governance thinking and aligns with identity lifecycle control discipline. The practitioner conclusion is to reduce blind spots first, then narrow the sanctioned stack where the exposure is real.
Shadow IT will increasingly overlap with NHI governance as teams adopt machines, assistants, and integrations that behave like accounts. Even when the article focuses on human users, the pattern is the same one that drives NHI sprawl: convenience creates unsupervised credentials and unattended data paths. That makes account ownership, revocation, and usage review the common control plane across human and non-human identity programmes. Practitioners should unify discovery and lifecycle governance before the same blind spot spreads into service accounts and AI workflows.
What this signals
Session-level data drift: as more work moves into browser tabs and generative assistants, the security problem becomes tracing what authenticated users place into unmanaged services. That pushes teams toward controls that classify content at the point of use and correlate it with identity, rather than relying on static application allowlists.
For identity programmes, the immediate signal is that Shadow IT and Shadow AI both expose the limits of inventory-only governance. Teams should expect more workflow-driven exceptions, more unowned accounts, and more pressure to unify access review with data classification and offboarding. The stronger the visibility into identities and the data they move, the smaller the blast radius becomes.
Security leaders should align discovery, exposure scoring, and exception handling with NIST SP 800-53 Rev 5 Security and Privacy Controls to make the issue operational, not anecdotal. A small team cannot stop every workaround, but it can force the riskiest ones into a managed queue before they become permanent dependencies.
For practitioners
- Implement continuous discovery across SaaS, devices, and browser activity Use automated discovery to surface web apps, installed software, unmanaged devices, and file-sharing paths, then reconcile them against approved inventories and owners. Prioritise tools that touch sensitive content rather than simply counting unknown applications.
- Classify data before you classify the tool Map which files, transcripts, and source code move through each unsanctioned service, then assign risk based on regulated or business-critical data exposure. An unknown app with no sensitive data is lower priority than a known app receiving contract uploads every day.
- Treat Shadow AI as a separate control domain Create a specific review path for generative AI tools that considers prompt retention, training reuse, and who is allowed to paste confidential content. Tie that path to identity ownership so users know which accounts and content types are in scope.
- Review browser extensions like third-party access Audit extension permissions for page-level read and write access, remove utilities that do not have a clear business need, and review newly installed extensions after browser updates. Pay attention to extensions that can access internal portals, webmail, and document repositories.
- Close the offboarding gap for unsanctioned accounts Add a step to offboarding and joiner-mover-leaver workflows that looks for SaaS accounts created outside procurement and personal file-sharing accounts used for work. Revoke or transfer ownership before the former employee retains the only active control over the data.
Key takeaways
- Shadow IT becomes a governance failure when identities can create accounts and move data outside the approved stack without visibility.
- The article's core evidence is that 106 SaaS apps and 59% IT concern describe a real operating condition, not a niche exception.
- The most effective response is exposure-based control, built on discovery, classification, ownership, and offboarding rather than blanket prohibition.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Shadow IT creates unmanaged access paths that map to access governance gaps. |
| NIST SP 800-53 Rev 5 | AC-6 | Excessive or unowned access is the core governance issue in shadow tool adoption. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policy is central when employees bypass approved software paths. |
| NIST AI RMF | GOVERN | Shadow AI governance requires clear ownership and accountability for AI use. |
Apply AC-6 to limit access rights in discovered tools and remove permissions tied to orphaned use.
Key terms
- Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Exposure-Based Control: Exposure-based control is a governance approach that prioritises tools and accounts according to the data they touch and the access they hold. It is more practical than blanket bans because it focuses remediation on services with real sensitivity, real ownership gaps, and real downstream risk.
- Session-Level Data Drift: Session-level data drift is the movement of sensitive information out of governed systems through an authenticated browser or application session into unmanaged services. It matters because the risk can occur without a traditional file transfer event, making it harder for inventory and logging tools to detect.
What's in the full article
Safetica's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step discovery workflow for identifying unsanctioned SaaS apps, devices, and shared files across a lean environment
- Practical guidance on separating personal activity from business exposure while preserving privacy controls
- Details on how the platform scores tools by the classified data they touch and narrows enforcement to the riskiest services
- Examples of how Shadow AI fits into the same governance model as SaaS sprawl and file-sharing drift
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, secrets management, and workload identity. It helps security and identity practitioners build the control discipline needed for sprawl, delegated access, and unmanaged credentials.
Published by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org