TL;DR: Shadow AI is spreading as employees use unsanctioned AI tools and paste sensitive data into them, with 61% of organisations reporting unmonitored AI use and 60% of IT professionals saying AI is outpacing their protection, according to JumpCloud. The security problem is not just tool sprawl but the collapse of identity, policy, and data-handling control at the point of use.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Shadow AI Is the New Shadow IT: What CIOs Must Do Now”.
By the numbers:
- 61% of organisations report encountering unsanctioned or unmonitored use of AI tools.
- 60% of IT professionals agree that AI is outpacing their organisation’s ability to protect against threats.
Key questions
Q: How should security teams govern shadow AI without slowing adoption?
A: Start with continuous discovery, then classify tools by data access, system connectivity, and provider trust.
Q: Why does shadow AI create risk even when employees are trying to be productive?
A: Because the risk is not intent, it is uncontrolled data movement.
Q: What are the signs that an AI system is being used outside the controls expected by the EU AI Act?
A: Warning signs include poor data quality, limited explanation of model decisions, weak records of system activity, and missing human review for decisions that affect individuals.
Practitioner guidance
- Map sanctioned and unsanctioned AI use Build an inventory of AI services being used by employees, including browser-based tools, consumer accounts, and embedded AI features in other apps.
- Enforce prompt data restrictions Define which data types can never be entered into external AI tools, especially PII, financial records, customer data, and proprietary code.
- Centralise identity enforcement for AI access Tie AI access decisions to verified identities, approved accounts, and consistent logging across human users and non-human identities.
Bottom line: Shadow AI is not just unsanctioned software use. It is a governance failure that lets sensitive data move outside approved identity and access boundaries.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow AI is an IAM visibility failure before it is an AI adoption issue. The organisation may still authenticate users correctly, but it cannot govern the destination once employees shift work into unsanctioned AI services. That means the real break occurs between identity assurance and application visibility, where approved access no longer predicts actual data movement. Practitioners should read this as a governance gap in the access layer, not a tooling gap in isolation.
A few things that frame the scale:
- 63% of organisations surveyed lacked AI governance policies to manage AI or prevent shadow AI, according to IBM's 2025 Cost of a Data Breach Report.
A question worth separating out:
Q: When should teams prioritise governance and process discipline over adding more AI tooling?
A: Teams should prioritise governance and process discipline when AI initiatives are spreading faster than oversight can keep up. The article reflects the 10 20 70 view, where sustainable AI success depends more on processes, talent, change management, and governance than on model quality alone. Without that foundation, additional tooling often increases complexity instead of delivering reliable, scalable outcomes.
👉 Read our full editorial: Shadow AI is exposing identity and data control gaps in IAM