TL;DR: Shadow AI is creating invisible governance and data-exfiltration risk as employees adopt unsanctioned AI tools faster than security teams can inventory or control them, according to SailPoint. The core failure is not adoption itself but the assumption that identity and access programmes can govern tools they cannot see.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “We are Customer Zero: How SailPoint secured its own shadow AI”.
Key questions
Q: What breaks when employees use shadow AI for work tasks?
A: Shadow AI breaks identity visibility and lifecycle control.
Q: Why does unsanctioned AI use create such a high data security risk for organisations?
A: Shadow AI increases risk because employees often paste sensitive content into tools that may retain prompts, train on submitted data, or expose inputs to third parties.
Q: How do you know if shadow AI governance is actually working?
A: You know it is working when you can see where AI is used, what data it touches, what actions it can take, and whether those actions are blocked or approved in real time.
Practitioner guidance
- Build a shadow AI discovery baseline Map browser-level AI usage across managed endpoints, then compare it against sanctioned application inventories and access records to find gaps in what the organisation can actually govern.
- Define an AI onboarding gate Require review of data handling, retention, and ownership before any AI tool is treated as approved for corporate use, so governance starts before adoption spreads.
- Route risky AI usage into governance workflows Feed observed unsanctioned AI activity into identity and security operations so policy decisions, app restrictions, and user guidance happen from the same evidence set.
Bottom line: Shadow AI creates risk because unsanctioned AI tools sit outside the inventory, policy, and review processes that identity programmes depend on.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow AI is primarily a visibility failure, not an AI adoption problem. The organisation may still have identity processes, but they are being applied to an incomplete application estate. Once workers move data into tools the security team cannot enumerate, governance becomes reactive instead of authoritative. The practitioner implication is that AI usage discovery must sit ahead of policy enforcement.
A few things that frame the scale:
- Organisations with high levels of shadow AI faced an average of $670,000 in additional breach costs compared with those with little or none, according to IBM's 2025 Cost of a Data Breach Report.
A question worth separating out:
Q: What should IAM and SOC teams do with browser-level AI usage signals?
A: Use them as shared governance evidence, not just alert data. Identity teams can map usage to sanctioned inventory while security operations can assess exposure, but both teams need the same signal set if they want to close the gap between approved access and actual behaviour.
👉 Read our full editorial: Shadow AI visibility gaps are widening enterprise identity risk