Intelligence in AI Security

What Is Shadow AI and Why Is It a Security Risk Your Team Isn't Tracking?

By Brandon Rhodes
Posted on Sep 23 / 2026

An employee pastes a client's document into a free AI summarizer to save time, or an engineer pastes code into Claude to debug. There is no malicious intent, and these employees do not mean to leak data, yet every time these situations unfold, sensitive information leaves your company's hands. This is shadow AI, the unsanctioned use of artificial intelligence tools and applications without formal approval or oversight. The shadow AI meaning matters here because unlike shadow IT, which security teams have managed for years, these tools don't just store the data. They process it and train on it too.

The Visibility Gap Shadow AI Creates

The challenge with Shadow AI is not that employees are using AI tools, but that organizations often have little visibility into how those tools are being used, what data is being shared, what actions are being taken, and where information ultimately resides.

The 2026 Verizon DBIR analyzed 858,440 DLP events involving generative AI tools and found that 67% of users are accessing AI services through non-corporate accounts on their corporate-managed devices. Among these events, source code was the largest category of data submitted to AI platforms by a wide margin, followed by images and structured data. Together, these findings show a growing visibility challenge for organizations in that sensitive information is increasingly being shared with AI systems outside established governance frameworks, often beyond the reach of traditional monitoring, auditing, and security controls.

Where the Regulatory Liability Lands

The data leaving your doors is often the data that regulators seek to protect. For healthcare organizations operating under HIPAA, a clinician pasting patient information into a consumer ChatGPT account not covered by a business associate agreement may constitute an unauthorized disclosure under the Privacy Rule, and your organization bears the liability, not the AI company. That liability runs through the HHS Office for Civil Rights, which can pursue investigations, resolution agreements, and corrective action plans, with civil monetary penalties reaching $2.19 million annually as of January 2026, though that ceiling applies to the most serious tier of willful neglect. 

For financial services under PCI DSS, cardholder data flowing through shadow AI tools may violate vendor security requirements. PCI DSS is enforced contractually through acquiring banks and card networks rather than by federal statute, and consequences for non-compliance can include escalating monthly fines, a mandatory forensic investigation when the card brands require one, and suspension of the ability to process card payments. Without proper visibility into where this data is going, you may carry more liability than you realize.

When AI Tools Act on Their Own

Additionally, the problem isn't limited to employees pasting information into a chatbot. AI coding assistants, IDE extensions, and agentic tools now have access to source code, internal files, and APIs, and they can pull from that access, expose it, or act on it without anyone knowing. That access can translate into real damage: deleting or overwriting production data, pushing unreviewed code changes live, or exposing credentials and API keys embedded in a codebase. 

In July 2025, an AI coding agent from Replit ran unauthorized commands during an active code freeze and deleted a production database, wiping records for more than 1,200 executives and 1,190 companies, despite explicit instructions not to touch production. The data was ultimately recovered manually, after the agent falsely claimed a rollback was impossible. OWASP has named this "Excessive Agency," which means giving an AI system more functionality, permissions, or autonomy than a task actually needs, so a single ambiguous output can end up causing real damage without an attacker anywhere in the picture.

Due Diligence and Shadow IT Risk Management

When new technologies are introduced, proper due diligence should be performed, an extension of the same shadow IT risk management discipline security teams already practice, including:

#1

Security risk reviews: A security risk review should evaluate where the tool stores data, whether it trains on submitted inputs, what its authentication and access controls look like, and whether it integrates with existing systems in ways that expand the attack surface.

#2

Legal assessments: A legal assessment should confirm data processing terms, examine whether a business associate agreement or equivalent contractual protection is available, and identify which regulatory obligations apply to the data the tool will handle.

#3

Procurement review: Procurement processes should require the tool to pass through a formal intake and approval workflow, be evaluated against an approved vendor list, and be tied to a named business owner accountable for its ongoing use.

Shadow AI bypasses those safeguards entirely, leaving organizations without visibility into inherent risks and vulnerabilities, significantly raising their attack surface.

A Governance Challenge, Not a Technology Problem

CrowdStrike described this gap in March 2026, warning that shadow AI is accelerating faster than the oversight built to manage it, as employees and engineering teams alike adopt tools and deploy models without adequate visibility or runtime protection. The resulting governance gap grows with every new AI tool that gets adopted. The significance of this observation is that it reframes Shadow AI from a technology issue into a governance challenge. The risk is not the tool itself, but the organization's ability to maintain visibility, accountability, and control as AI adoption accelerates.

Shadow AI has evolved from an emerging concern into a measurable enterprise risk. As adoption of AI accelerates, organizations are facing growing challenges around visibility, data protection, compliance, and third-party risk. Much of the risk is not found within the use of AI itself, per se, but AI operating outside established frameworks. Organizations that invest in visibility, clear usage policies, and secure AI solutions will be best positioned to capture the benefits of AI innovation while maintaining the governance, security, and trust required to manage it responsibly.

Want to make sure AI usage is secure at your organization? Echelon Risk + Cyber's AI Secure service line was built for exactly this gap: discovering the shadow AI already running across your environment, assessing where the real exposure sits, and putting the governance structure in place (policies, ownership, monitoring) to manage it going forward. Visibility is the foundation everything else depends on, because governance policies only hold once you can see what they apply to. 

Are you ready to get started?