Managing Shadow AI and Unapproved Tool Adoption

Shadow AI is systems, tools or models deployed without going through your governance process. A department uses ChatGPT with customer data because it solves their problem faster than waiting for approved tools. A team builds a machine learning model to optimise their workflow because compliance approval feels slow. These are shadow AI risks.
Shadow AI is not a compliance failure; it is a governance design failure. If line 1 is building workarounds to your governance process, your process is too slow, too restrictive or people do not believe it is fair. You cannot eliminate shadow AI through punishment; you can only reduce it by making approved paths faster and more attractive than shadow AI.
Detect shadow AI through several mechanisms. Survey line 1 teams about tools and systems they are using that might involve AI. Ask data protection teams whether they have found personal data being processed by tools outside approved systems. Ask IT security whether they have found unusual API calls to generative AI services. Ask finance which vendors the business is paying for AI software without procurement going through official channels. None of these will find all shadow AI, but they will find some.
When you discover shadow AI, do not immediately shut it down. Instead, investigate what problem it is solving and why approved paths did not work. A team using ChatGPT probably found that ChatGPT solved their problem quickly and approved tools either did not exist or required months of setup. Help them migrate to an approved tool quickly. If no approved tool exists and there is demand for what they are doing, that tells you what to add to your toolkit.
Shadow AI creates risk because systems operating outside governance can process data unsafely, use prohibited practices, or lack human oversight. If a department is using an AI tool to screen job applicants without documenting that AI is used (so candidates cannot request human review), that is a legal exposure. Your task is to bring systems into governance, not to punish the people using them.
Some organisations use a quarantine approach: when shadow AI is discovered, it continues operating in a restricted way (limited data access, user audit logging, no integration with formal decisions) whilst the team works to move it into approved governance. This lets the team continue their work whilst you assess risk and plan migration.
Culture matters enormously in managing shadow AI. Organisations where compliance is seen as enabling business have less shadow AI than organisations where compliance is seen as obstructing it. If your governance process is fast, transparent and helps teams deploy AI safely, they will use it. If your governance is slow and unpredictable, teams will build workarounds. Invest in speed and communication alongside rigour.
Build a transparent onboarding process for new AI tools. When a department wants to use a new tool, they can request it through a form that takes a day to process. Compliance looks at the tool’s data handling practices, whether the vendor can meet your security standards, and whether the tool fits your approved technology stack. If it does, it takes a week to integrate and users get onboarded. If this process is fast, teams will use it instead of sneaking tools in.
Cloud AI services (ChatGPT, Claude, Gemini) are common shadow AI in many organisations. Teams use them because they are free, accessible and powerful. Create an approved process for using these services. Acceptable uses might include: drafting text, brainstorming, analysis of publicly available information. Prohibited uses are: processing personal data, customer information, confidential data or special category data. Issue guidance, train users and then monitor for violations.
Shadow AI is often a leading indicator of governance process problems. If you see lots of people using unapproved AI tools, ask yourself what approved paths they rejected and why. This feedback loop, if acted on, improves governance.
Document what shadow AI you find and what you did about it. This evidence matters to regulators. If a regulator audits you and finds shadow AI you knew about but did not remediate, that looks like negligence. If you find shadow AI, assess it, develop a plan and execute on it, that is governance working as intended.
