Employees have always found ways to submit corporate data to places it should not go. Whether through webmail services, file-sharing platforms, or ad hoc online tools, the leakage of sensitive information via unsanctioned channels is as old as the commercial internet. Shadow AI, however, is not simply the latest iteration of this familiar problem. The nature of generative AI tools, the volume of data they ingest, and the speed at which they have been adopted make the risk categorically different from what came before.
What is shadow AI?
Shadow AI refers to the use of artificial intelligence tools by employees without the knowledge, approval, or oversight of their organisation’s IT or security teams. It is a close cousin of shadow IT, which has long described the adoption of unsanctioned software and cloud services in the workplace. Where shadow AI differs is in the nature of the interaction: generative AI tools such as ChatGPT, Google Gemini, and a rapidly growing ecosystem of specialist applications are designed to receive, process, and learn from user inputs. An employee who submits a customer complaint, a draft contract, or a set of internal performance data to one of these tools is not merely using unauthorised software; they are transferring potentially sensitive or regulated data to a third-party platform with its own data retention and training policies, often without any understanding of where that data ends up.
The scale of the problem
The adoption of generative AI across the enterprise has been remarkably rapid. McKinsey’s 2025 global survey found that the vast majority of organisations were already using AI regularly in at least one business function. Netskope’s Cloud and Threat Report, drawing on enterprise analytics from October 2024 to October 2025, found that nearly half of generative AI users in corporate environments were accessing tools through personal accounts, entirely outside the visibility of IT and security teams. The number of distinct generative AI SaaS applications Netskope tracked in enterprise environments grew almost fivefold within a single year.
These trends describe something qualitatively different from the shadow IT of the past decade. When an employee pastes a paragraph into an online grammar checker, the exposure is limited and discrete. When that same employee pastes a contract summary, a client email chain, or financial projections into a generative AI tool and asks it to draft a board paper, the volume and sensitivity of data transferred in a single interaction is far greater. The conversational interface actively encourages users to provide richer context with each prompt. The Samsung incident of 2023, in which engineers submitted proprietary source code and meeting transcripts to ChatGPT within weeks of the company permitting its use, illustrates how quickly well-intentioned productivity gains can produce material data exposure.
Why this matters under UK regulation
Organisations subject to the UK GDPR retain clear obligations around data minimisation, lawful basis for processing, and accountability, all of which are engaged when employees submit personal or commercially sensitive data to third-party AI platforms. The ICO’s AI and Biometrics Strategy, published in June 2025, sets out regulatory priorities around transparency, bias, and individual rights, with a statutory Code of Practice on AI and automated decision-making expected in due course. The Data (Use and Access) Act 2025, phased in through to June 2026, introduces more flexible provisions for automated decision-making but does not relax the core data protection principles.
The NCSC’s guidance on AI and cyber security for senior leaders is similarly direct: unmanaged data flows to external AI platforms represent a governance failure, regardless of the user’s intent. The National Protective Security Authority explicitly identifies shadow AI as a threat to organisational security.
A layered approach to managing shadow AI
No single control will address the breadth of this risk. Effective management requires a layered strategy that combines technical enforcement with governance, culture, and the provision of viable alternatives.
The first layer is network-level visibility and control. Most modern web filtering and secure web gateway solutions now maintain dedicated categories for generative AI sites. Enabling monitoring or restriction of these categories provides a baseline of visibility into which tools are being accessed and by whom. This alone is insufficient, as employees can circumvent network controls through personal devices and mobile connections, but it establishes the foundation on which more granular controls can be built.
The second layer involves endpoint and browser-based enforcement. Microsoft Purview now offers endpoint data loss prevention capabilities that can detect and block the pasting or uploading of sensitive data to generative AI sites via supported browsers, with native integration in Microsoft Edge and extension-based support for Chrome and Firefox. CrowdStrike’s Falcon AI Detection and Response platform provides unified visibility into AI tool usage across endpoints, SaaS environments, and cloud infrastructure, enabling organisations to surface shadow AI activity and enforce governance policies. Browser-level controls, such as policies that restrict the use of unsupported browsers where DLP protections cannot be applied, help to close circumvention gaps.
The third layer, and arguably the most impactful, is the provision of sanctioned AI tools. Research consistently demonstrates that where organisations provide enterprise-grade AI alternatives with appropriate guardrails, unauthorised use drops substantially. Blocking generative AI entirely is rarely sustainable, and evidence suggests that bans simply drive usage underground rather than eliminating it. Providing a governed path of least resistance is both more practical and more effective.
The fourth layer is training and communication. Employees need to understand not only that certain tools are prohibited, but why. Effective awareness programmes should explain the data protection implications of submitting corporate information to external AI platforms, set out clear dos and don’ts, and provide practical guidance on when and how to use sanctioned alternatives. As the AI landscape shifts and new tools emerge, this cannot be a one-off exercise; awareness must be maintained through regular, proportionate communication.
The fifth and most foundational layer is formal AI governance. The majority of organisations still lack formal AI governance policies, and without structured oversight the other layers cannot function coherently. An effective governance framework should classify AI tools into tiers from fully approved through to prohibited, establish clear ownership and accountability for AI risk, mandate ongoing discovery and audit of AI usage, and integrate with existing information security and data protection frameworks.
Moving forward
Shadow AI cannot be solved by policy alone, nor by technology alone. It requires a coordinated response spanning technical controls, user enablement, and governance, underpinned by an honest assessment of how AI tools are actually being used within the organisation. The organisations that manage this effectively will be those that treat AI governance not as a barrier to adoption, but as the mechanism that makes responsible adoption possible.
Evolve North works with organisations across the UK to develop and implement proportionate AI governance frameworks, from initial risk assessment and policy development through to technical control implementation and ongoing assurance. If your organisation is grappling with shadow AI, our team would welcome a conversation.
If you want to discuss how we can help you with any data protection, technical or governance requirements relating to AI, reach out on t 01748 905 002 or info@evolvenorth.com. We can help.
