Shadow AI risks
Shadow AI is AI used at work without the people responsible for data and risk knowing. Here are the seven risks it creates, and the control that fits each one.
1. Data leaves under terms nobody agreed
Text, files, code and recordings go to a provider under that provider's consumer or self-serve terms, not a contract you negotiated. Whether inputs are kept, for how long and whether they're used for training depends on the product and plan.
Control: approve a small set of tools on business terms and say what data may go into each.
2. Confidential and personal data goes with it
Client material under an NDA, personal data and regulated records don't stop being subject to their rules because a tool was adopted informally.
Control: a clear "never paste" list in your AI policy, and training that shows real examples.
3. Agents act with someone's access
Agent services browse, fill in forms, send messages and build software on a person's behalf, using that person's accounts. A mistake or a prompt injection then acts with real authority.
Control: register every agent with an owner, give it its own least-privilege credentials, and require a person's approval for actions that send, pay, delete or change access.
4. Keys and scripts nobody owns
Traffic to a model API usually comes from software: a script, an integration or an agent, often using a personal API key. When that person leaves, the key and the data flow stay.
Control: find the application behind each model API call, move it to a company-owned key, and give it a named owner.
5. Meeting recordings and transcripts pile up
Recorders join calls, record everyone and keep transcripts, sometimes without every participant being asked.
Control: one approved recorder, with a rule on telling participants and a retention period.
6. Decisions without a record
When AI output feeds a decision, there's no record of which tool produced it or what it was given.
Control: the person who uses AI output checks it and owns it; significant uses are noted.
7. Obligations you can't show you meet
Frameworks such as the NIST AI Risk Management Framework start from knowing which AI systems are in use. In the EU, the AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures for a sufficient level of AI literacy among their staff (Article 4, applying since 2 February 2025). An inventory is the first piece of evidence.
Control: keep an inventory, review it monthly, and record training.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex: Article 4 (AI literacy) and Article 113 (application dates).
- European Commission: AI literacy, questions and answers
- NIST AI Risk Management Framework
- Checked 28 September 2026.