Generative AI (GenAI) tools have moved from novelty to daily utility faster than most organisations anticipated. Employees across every function, including legal, finance, HR, engineering, marketing, and operations, are using public AI tools to summarise documents, draft communications, analyse data, generate code, and accelerate decisions. The problem is not the productivity gain. The problem is that most organisations have no reliable visibility into which tools are being used, what data is being entered, or whether sensitive information is leaving controlled environments.

This phenomenon is known as shadow AI: the use of AI tools and services without the knowledge, approval, or oversight of an organisation's IT, security, legal, or compliance functions. It is not a future risk. It is happening now, across industries and geographies, and it is creating a category of cyber, privacy, and governance exposure that existing controls were not designed to address.

This research paper examines what shadow AI is, why it differs from traditional shadow IT, where sensitive data exposure occurs, how organisations can detect and govern unapproved GenAI use, and what practical controls reduce risk without blocking the productivity benefits that employees are already realising.

What Is Shadow AI?

Shadow AI refers to the use of artificial intelligence tools, platforms, or services within an organisation without formal approval, security review, or governance oversight. It is a subset of the broader shadow IT problem, but with characteristics that make it materially more dangerous.

In practice, shadow AI most commonly manifests as employees using browser-based GenAI tools, such as public large language model (LLM) interfaces, AI writing assistants, AI coding tools, or AI-powered document summarisers, to complete work tasks. These tools are often free, require no installation, and are accessible from any device with an internet connection. That accessibility is precisely what makes them difficult to govern.

Shadow AI also includes the use of AI features embedded within approved SaaS platforms that have not been separately reviewed. An organisation may have approved a project management tool, a CRM, or a productivity suite, only for that vendor to quietly introduce GenAI capabilities that process user data in ways the original security review did not contemplate. This second form of shadow AI is often overlooked entirely.

The ISACA December 2023 survey of Australian and New Zealand organisations found that around 63% of employees were already using AI in the workplace, despite only 11% of organisations having a formal policy in place. Research published in the 2025 Shadow AI Report by Josys, which surveyed 500 Australian technology decision-makers, found that more than one in three Australian professionals regularly upload sensitive company data, including strategy documents, financials, and customer information, into AI platforms, often without any formal oversight. The same report found that 70% of organisations have moderate to no visibility into what AI tools are being used within their operations.

Why Shadow AI Is Becoming a Cyber Risk Priority

Shadow AI has moved to the top of the cyber risk agenda for a straightforward reason: the volume and sensitivity of data being entered into uncontrolled AI environments is growing faster than governance frameworks can respond.

Unlike most shadow IT, which typically involves accessing an unapproved application or storing data in an unapproved location, shadow AI involves actively feeding organisational data into external systems that process, store, and in some cases train on that input. The risk is not simply that an employee is using an unapproved tool. The risk is that confidential client information, proprietary source code, internal financial data, HR records, or strategic plans may be transmitted to a third-party AI provider's infrastructure with no contractual protections, no data residency controls, and no audit trail.

The regulatory environment is also tightening. In Australia, amendments to the Privacy Act introduce new transparency requirements around automated decision-making, effective December 2026. Organisations that cannot demonstrate visibility and control over how AI tools interact with personal information will face increasing regulatory exposure. Similar obligations exist under the EU AI Act, the UK ICO's guidance on generative AI, and sector-specific frameworks across financial services, healthcare, and critical infrastructure.

Security teams are also beginning to recognise that shadow AI expands the attack surface in ways that are difficult to monitor. When employees use personal accounts to access AI tools, those accounts fall outside identity and access management controls. When AI tools are accessed via personal devices, endpoint detection and response (EDR) telemetry may not capture the activity. When outputs from AI tools are copied into business processes without validation, the organisation may be acting on information derived from a model it has never assessed.

Research from IBM's Cost of a Data Breach Report has consistently shown that data breaches involving third-party or cloud-based services carry higher average costs than those confined to on-premises environments. Shadow AI introduces a class of third-party data exposure that is largely invisible to existing breach detection mechanisms.

How Shadow AI Differs from Traditional Shadow IT

Shadow IT is a well-understood problem. Employees use unapproved applications, store data in personal cloud storage, or connect unauthorised devices to corporate networks. The risks are real but largely familiar: data stored outside approved systems, applications without security patching, and services without contractual data protection obligations.

Shadow AI inherits all of those risks and adds several that are unique to AI systems.

Data is actively processed, not just stored

When an employee saves a file to a personal cloud storage account, the data is stored but not transformed. When an employee pastes a document into a GenAI tool, the data is actively processed by an external model. Depending on the provider's terms of service, that data may be retained, used to improve the model, shared with third parties, or accessible to other users in certain configurations. The act of using the tool is itself a data transfer event.

Outputs carry their own risk

Shadow IT does not generate outputs that re-enter business processes. Shadow AI does. An employee who uses an unapproved AI tool to summarise a legal document, draft a board report, or generate code may introduce errors, hallucinations, or biased outputs into consequential decisions without any validation step. The organisation may not know the output was AI-generated, let alone that it came from an unvetted model.

The attack surface includes the model itself

Shadow IT expands the attack surface by adding unmanaged endpoints or services. Shadow AI expands it further by introducing unvetted AI models that may themselves be compromised, manipulated through prompt injection, or designed to exfiltrate data. Prompt injection attacks, where malicious instructions are embedded in content that an AI tool processes, are an emerging threat vector that has no equivalent in traditional shadow IT.

Governance frameworks are less mature

Organisations have decades of experience governing shadow IT through network controls, endpoint management, and acceptable use policies. AI governance frameworks are newer, less standardised, and often not yet integrated with existing security, privacy, and procurement processes. The NIST AI Risk Management Framework (AI RMF) provides a voluntary structure, but adoption is uneven and implementation guidance for shadow AI specifically remains limited.

Where Sensitive Data Exposure Happens

Understanding where shadow AI creates data exposure requires looking at the specific workflows where employees are most likely to use unapproved GenAI tools. The following scenarios are drawn from documented incidents and common enterprise use patterns.

Legal and contracts

A staff member pastes a client contract into a public GenAI tool to generate a summary before a meeting. The contract contains commercially sensitive terms, client names, pricing structures, and confidentiality obligations. The AI tool processes the full document on external infrastructure. No data processing agreement exists between the organisation and the AI provider. The client has not consented to their information being processed by a third-party AI system.

Software development

A developer uses a public AI coding assistant to debug a section of proprietary source code. The code contains business logic, API keys, database connection strings, or references to internal system architecture. The AI provider's terms of service permit the use of submitted code to improve the model. The organisation's intellectual property is now part of an external training dataset. This scenario mirrors the widely reported 2023 incident in which engineers at Samsung's semiconductor division inadvertently leaked sensitive internal source code and meeting notes by submitting them to a public AI tool.

Finance and commercial data

A finance team member uploads a spreadsheet containing revenue forecasts, margin data, or acquisition targets into an AI tool to generate a summary or identify trends. The data is commercially sensitive and, in some cases, may constitute material non-public information. The organisation has no record of the transfer and no ability to retrieve or delete the data from the AI provider's systems.

Human resources and incident management

A manager uses a public AI tool to rewrite a confidential HR investigation report or a security incident summary. The document contains personal information about employees, details of an internal investigation, or information about a security event that has not been disclosed. The AI tool processes the full document, and the manager has no visibility into how that information is handled.

Security team discovery

In many organisations, security teams discover shadow AI usage only after reviewing browser logs, proxy logs, or SaaS access data during an unrelated investigation. The discovery is reactive rather than proactive, and by the time it occurs, data may have been entering external AI systems for months.

The Problems Organisations Face With Shadow AI

Unapproved tool usage

Employees may use personal or public GenAI tools without IT, security, legal, or compliance approval, creating data exposure that the organisation has no visibility into.

Sensitive data entering external systems

Client information, source code, credentials, contracts, financial data, and internal documents may be entered into AI tools the organisation does not control, with no contractual data protection obligations in place.

No visibility across the environment

Security teams may not know which AI tools are being accessed, from which devices, by which users, or what data is being submitted, making risk assessment and incident response significantly harder.

DLP controls not designed for AI

Existing data loss prevention controls were built for email, file transfer, and removable media. Many do not inspect browser-based AI traffic effectively, leaving a significant gap in data movement visibility.

Unvalidated AI outputs in business processes

AI-generated outputs may be copied into reports, decisions, code, or client communications without validation, introducing errors, hallucinations, or biased content into consequential processes.

Fragmented governance across functions

Legal, privacy, procurement, and cyber security teams may each assess AI risk independently, creating inconsistent controls, duplicated effort, and gaps where no single function has clear ownership.

Blocking drives underground usage

Blanket restrictions on AI tools often push employees toward less visible workarounds, including personal devices, personal accounts, or obscure tools, resulting in less oversight rather than less usage.

Policy without understanding

Acceptable use policies may exist on paper, but employees may not understand what constitutes sensitive data, which tools are approved, or what the practical consequences of non-compliance are.

How Organisations Can Detect Unapproved GenAI Use

Detection is the foundation of any shadow AI governance programme. Organisations cannot govern what they cannot see, and most organisations currently have significant blind spots in their AI visibility.

Browser and proxy telemetry

The most accessible starting point for many organisations is browser and proxy log analysis. GenAI tools are predominantly browser-based, and traffic to known AI provider domains, including those operated by major LLM providers, can be identified through DNS logs, proxy logs, or next-generation firewall (NGFW) application identification. This approach provides a baseline view of which AI services are being accessed from managed devices on corporate networks, though it does not capture usage on personal devices or via mobile data connections.

SaaS discovery and CASB

Cloud Access Security Broker (CASB) solutions and SaaS discovery tools can identify AI applications being accessed through corporate identity providers or from managed endpoints. Modern CASB platforms maintain catalogues of thousands of AI and GenAI applications, categorised by risk level, data handling practices, and compliance posture. This provides a more structured view of the AI application landscape than proxy logs alone, and enables policy-based controls such as blocking high-risk applications or requiring authentication through approved identity providers.

Security Service Edge (SSE) platforms

Security Service Edge (SSE) platforms, which combine CASB, Secure Web Gateway (SWG), and Zero Trust Network Access (ZTNA) capabilities, provide the most comprehensive visibility into cloud application usage, including AI tools. SSE platforms can inspect traffic at the application layer, identify data being submitted to AI tools, and apply data loss prevention (DLP) policies to that traffic in near real time. For organisations with a mature SSE deployment, this represents the most effective technical control for shadow AI.

Endpoint telemetry

Endpoint detection and response (EDR) and unified endpoint management (UEM) solutions can provide visibility into browser-based AI usage on managed devices, including the identification of browser extensions that provide AI functionality. This is particularly relevant for AI coding assistants and productivity tools that operate as browser extensions or IDE plugins, which may not be visible through network-layer controls.

Identity and access visibility

Many AI tools allow users to authenticate with personal Google, Microsoft, or Apple accounts. When employees use personal accounts to access AI tools, those sessions fall entirely outside corporate identity and access management (IAM) controls. Organisations that rely solely on SSO-based access controls will have no visibility into AI tool usage authenticated through personal accounts. Addressing this gap requires a combination of network-layer controls and user awareness, rather than identity controls alone.

DLP limitations

Data loss prevention (DLP) tools were designed primarily to detect and block the movement of sensitive data through email, file transfer, and removable media. Many DLP solutions have limited capability to inspect the content of HTTPS-encrypted traffic to AI platforms, particularly when that traffic is submitted through browser-based interfaces rather than file uploads. Organisations should not assume that existing DLP controls provide adequate coverage for shadow AI data movement. AI-specific DLP capabilities, available through some CASB and SSE platforms, are more effective but require specific configuration and tuning.

Detection should not be used solely as an enforcement mechanism. Organisations that use detection data primarily to identify and discipline employees who use unapproved AI tools are likely to drive usage further underground. Detection data is most valuable when used to understand the demand for AI capabilities, identify the highest-risk usage patterns, and inform the development of approved alternatives.

Practical Controls for Reducing Shadow AI Risk

  • Establish an AI acceptable use policy

    Create a clear, practical policy that explains what data can and cannot be entered into GenAI tools, distinguishes between approved and unapproved tools, and provides employees with a path to request approval for new tools.

  • Maintain an approved AI tools register

    Publish and maintain a register of AI tools that have been reviewed and approved for business use, categorised by permitted use cases and data classification levels.

  • Deploy visibility tooling

    Use browser telemetry, proxy logs, SaaS discovery, CASB, SSE, endpoint telemetry, and identity data to build a comprehensive picture of where AI tools are being accessed across the environment.

  • Apply AI-aware DLP controls

    Where technically feasible, apply data loss prevention controls to sensitive data movement into AI platforms, using CASB or SSE platforms with AI-specific DLP capabilities rather than relying on legacy DLP tools alone.

  • Tier AI usage by risk level

    Separate low-risk AI usage, such as drafting non-sensitive content, from high-risk usage involving regulated data, client information, source code, or confidential commercial material, and apply proportionate controls to each tier.

  • Provide approved AI alternatives

    Ensure employees have access to approved AI tools that meet their productivity needs, reducing the incentive to use unapproved alternatives. Approved tools should be enterprise-grade, with appropriate data handling terms and security controls.

  • Deliver practical AI security training

    Train staff using concrete examples of safe and unsafe AI prompts, real-world scenarios relevant to their roles, and clear guidance on what to do when they are unsure whether a tool or use case is approved.

  • Integrate AI risk across functions

    Bring security, privacy, procurement, legal, and third-party risk processes together under a unified AI governance model, with clear ownership and escalation paths for AI-related risk decisions.

  • Review AI usage regularly

    Establish a regular review cycle, at minimum annually and more frequently as the AI tool landscape evolves, to reassess approved tools, update policies, and identify new usage patterns that require governance attention.

Why Governance Must Enable Safe AI Adoption

The instinct to respond to shadow AI with blanket restrictions is understandable but counterproductive. Research consistently shows that when organisations block AI tools without providing approved alternatives, employees find workarounds. They use personal devices, personal accounts, or less well-known AI tools that are harder to detect. The result is not less shadow AI, it is less visible shadow AI.

Effective AI governance starts from the premise that employees are using AI tools because those tools provide genuine productivity value. The governance challenge is not to eliminate that value but to channel it through environments that the organisation controls and understands.

This requires a shift in how security, legal, privacy, and procurement teams approach AI risk. Rather than treating every AI tool as a threat to be blocked until proven safe, organisations benefit from a tiered approach that distinguishes between low-risk AI usage, such as using an approved AI writing assistant for non-sensitive content, and high-risk usage involving regulated data, client information, source code, or confidential commercial material.

The NIST AI Risk Management Framework (AI RMF) provides a useful structure for this tiered approach, organising AI risk management around four core functions: Govern, Map, Measure, and Manage. Applied to shadow AI, this means establishing governance structures and policies (Govern), identifying where AI tools are being used and what data they touch (Map), assessing the risk level of each use case (Measure), and applying proportionate controls (Manage).

Governance also needs to be cross-functional. Shadow AI is not purely a security problem, a privacy problem, or a procurement problem. It sits at the intersection of all three, and organisations that manage it through siloed functions will have gaps. A unified AI governance model, one that brings together security, privacy, legal, procurement, and business leadership, is more effective than any single team acting alone.

Training is a critical and often underinvested component. Policies that prohibit the entry of sensitive data into AI tools are only effective if employees understand what constitutes sensitive data, can recognise the difference between approved and unapproved tools, and have a clear path to request approval for new tools they want to use. Practical, scenario-based training, using real examples of safe and unsafe AI prompts, is more effective than policy documents alone.

Fortura Perspective

At Fortura, we work with security and risk teams across industries who are grappling with the same fundamental challenge: AI adoption is outpacing governance, and the gap between what employees are doing and what security teams can see is widening.

What we observe consistently is that shadow AI is not primarily a technology problem. It is a governance and culture problem that has technology dimensions. Organisations that approach it as a purely technical challenge, deploying CASB or DLP controls and considering the problem solved, typically find that those controls address only a fraction of the actual usage. The harder work is building the governance structures, policies, and training programmes that make safe AI use the path of least resistance for employees.

We also observe that the organisations making the most progress are those that treat AI governance as an enablement function rather than a restriction function. They are building approved AI tool registers, providing secure alternatives to the public tools employees are already using, and creating lightweight approval processes that give employees a fast path to get new tools reviewed. This approach reduces shadow AI by reducing the incentive for it.

The regulatory environment is also shifting in ways that will make AI governance a compliance requirement rather than a best practice. In Australia, the Privacy Act amendments effective December 2026 introduce new transparency obligations around automated decision-making. Organisations that have not yet established visibility and control over their AI tool landscape will find themselves under increasing pressure from regulators, clients, and insurers.

Fortura's AI and Emerging Technology Risk Assessment is designed to help organisations understand their current shadow AI exposure, identify the highest-risk usage patterns, and build a practical governance roadmap. Our Cyber Risk advisory practice works alongside security and business teams to translate that roadmap into controls, policies, and training that are proportionate to the organisation's risk profile and operational context.

Conclusion

Shadow AI is not a niche technical problem. It is a mainstream enterprise risk that sits at the intersection of cyber security, data privacy, legal liability, and operational governance. Employees are using GenAI tools because those tools are genuinely useful, and that usage will continue to grow regardless of whether organisations have governance frameworks in place.

The organisations that manage shadow AI risk most effectively are not those that block AI usage most aggressively. They are those that build the visibility, governance, and approved alternatives that make safe AI use the default. That means investing in detection capabilities to understand the current landscape, establishing clear policies that employees can actually follow, providing approved tools that meet the productivity needs driving shadow usage, and integrating AI risk into existing security, privacy, and procurement processes.

The next step for most organisations is a structured assessment of their current AI tool landscape: what tools are being used, by whom, for what purposes, and with what data. That assessment provides the foundation for a governance programme that is proportionate, practical, and capable of keeping pace with the rate at which AI capabilities are evolving.

If your organisation is ready to understand its shadow AI exposure and build a governance framework that enables safe AI adoption, Fortura's AI and Emerging Technology Risk Assessment is a practical starting point. Reach out to our Cyber Risk advisory team to discuss your current environment and where the highest-priority gaps are likely to be.