
Shadow AI is the use of AI tools employees adopt without approval: personal ChatGPT accounts, browser extensions, AI features quietly switched on inside SaaS. It matters because company data flows into systems nobody vetted. Governance starts with discovery through SSO and network logs, then a sanctioned alternative. Bans just push usage underground.
What counts as shadow AI?
Shadow AI is any AI tool doing company work without having passed through approval. The personal ChatGPT account a marketer uses for draft copy. The browser extension that summarises pages, and reads every one of them to do it. The AI feature a SaaS vendor switched on inside a tool you bought years ago for something else entirely.
The name borrows from shadow IT, the unsanctioned SaaS wave of the last decade, and the dynamics repeat almost exactly. What changed is speed and surface. An unsanctioned project tool held project data; a general-purpose chatbot will happily accept anything an employee can copy.
The defining feature is not bad intent. Most shadow AI starts as initiative: someone found a faster way to work and never thought of pasting text into a chatbot as a data transfer. It is one, though. Company data flows into systems nobody vetted, under terms nobody read.
Sanctioned AI, by contrast, is boring on purpose. A contract, an admin console, an entry in the tool register. The whole aim of governing shadow AI is to make the boring path the easy one. Boring still has to be fast, though; a sanctioned tool that takes three weeks of approvals to reach is shadow AI's best recruiter.
How do you discover it?
Three lenses, and each catches usage the others miss. None needs new software; they run on records you already keep. Worked as a checklist:
- SSO and OAuth logs. Export the app grants and sign-ins from your identity provider and look for AI tools staff have connected to their work accounts. This catches everything that touches your identity layer.
- Network DNS logs. Pull 30 days of DNS or proxy logs and match them against known AI domains. This catches usage on the corporate network that never went near SSO.
- Expense reports. Search card statements and expense claims for AI subscriptions. This catches the paid tools, which tend to be the heavily used ones; nobody expenses a tool they opened once.
- Then ask. Run a no-consequences survey of what teams actually use. Logs find tools; amnesty finds workflows, and workflows are the thing you end up governing.
The output of all four steps is one artefact: an inventory of tools in real use, each tagged with what kind of data goes into it.
Then rerun it. Discovery is not a one-off audit; new tools appear weekly and vendors keep switching features on. A quarterly rerun of the same four steps, diffed against the last inventory, takes a fraction of the first pass and catches the drift.
Why do bans fail?
Because a ban without an alternative does not reduce usage; it reduces visibility. Staff move to personal devices and personal accounts, and all three discovery lenses go dark at once. The data keeps flowing. You just stop seeing it.
Hence the sanctioned-alternative rule: never remove a tool without offering an approved way to do the same job. If people adopted a tool on their own, the tool was doing work someone needed done. A ban that ignores the need is a bet that the need will politely disappear. It won't.
There is a second cost to blanket bans that shows up later: they poison discovery. The amnesty survey only works while staff believe honesty is safe, and a ban enforced by punishment teaches the opposite lesson in one round. The pattern is old; every control that ignores demand produces a black market, and AI is the easiest black market in corporate history to join. No procurement, no install, a free account and thirty seconds.
Underground usage is the expensive kind.
What does proportionate governance look like?
Tiered by data sensitivity, not by tool. Tool-based rules chase a moving target, since the set of AI products changes monthly while your data classes barely change at all. The question that sets the tier is what data enters the prompt, because that is where the risk actually lives.
Low-sensitivity use, drafting internal notes or summarising public material, gets a light touch: register the tool, move it onto a company account, carry on. Uses touching personal data or client material get real controls: an approved tool under contract, with the prohibited data classes spelled out in your acceptable-use policy (the two-page version in our companion piece AI·09). Credentials and the most sensitive classes get hard blocks, and those blocks hold precisely because everything below them stayed permissive.
Proportionality is what makes the regime survivable. A governance model that treats a grammar checker like a data exfiltration channel gets ignored, and once staff ignore one rule they stop distinguishing between rules.
Write the tiers down and publish them internally. Staff comply with rules they can predict, and a published tier table turns "will I get in trouble for this" into a question with an answer. Ambiguity is what actually drives usage underground; the tools are just where it lands.
Zavior gives shadow AI somewhere to surface: a tool register with an owner, a data-sensitivity tier and a review date against every entry, so discovery becomes an inventory rather than a quarterly panic.
Frequently asked questions
Is shadow AI a PDPA or Privacy Act breach risk?
It can be. Personal data pasted into an unvetted tool is a disclosure to a third party, and the PDPA's obligations in Singapore (the Privacy Act's, for Australian operations) follow the data into that tool. The organisation, not the employee, answers for it.
Should you block AI domains?
Only where the data risk justifies it, and only alongside a sanctioned alternative. Blocking as a first move pushes usage onto personal devices, which defeats the discovery lenses you depend on. Block last, not first.
What is a sanctioned alternative?
An approved AI tool on a company contract with enterprise controls: SSO, admin visibility, and terms that restrict how your data may be used. It does the job the shadow tool was doing, through an account you can actually see.
Zavior · AI Governance
Discovery only pays off if someone owns what happens next. Zavior runs the SSO, network and expense sweep for you, then sits down with your team to set the sanctioned alternative and the acceptable-use tiers before staff drift back into shadow use. The same assessment runs for schools governing student and staff AI use.
Book a free 30-minute business assessment →This is general information, not legal advice.