BlogIT and security
What is shadow AI? A practical guide for IT and security teams
Employees are pasting source code, customer records, and contracts into AI tools nobody approved. Here is what shadow AI is, why the controls you already run rarely catch it, and how to get ahead of it without slowing anyone down.
The Nullgen team
13 min read

Somewhere in your organization right now, someone has a chat window open next to their real work. They are not doing anything they would describe as risky. They are debugging a stack trace, tightening up a customer email, or asking for a summary of a forty-page document. The tool is fast, free, and genuinely helpful — and nobody in IT approved it, or knows it is there.
That is shadow AI, and it has quietly become one of the most common ways company data leaves the building. This guide explains what it is, how it differs from the shadow IT you already manage, why your existing controls rarely catch it, and what a practical response looks like.
Shadow AI, defined
Shadow AI is the use of generative AI tools inside an organization without the knowledge, approval, or oversight of its IT and security teams. It includes consumer chatbots such as ChatGPT, Gemini, and Claude used through personal accounts, the assistants built into browsers and productivity apps, and the growing crop of “chat with your document” tools that sit one search result away.
The word shadow is not an accusation. Most of this use is well intentioned: people are trying to get through their work faster, and the approved option is missing, slower, or simply not installed on the machine in front of them. Microsoft and LinkedIn’s 2024 Work Trend Index found that 78% of people who use AI at work bring their own tools rather than wait for their employer to provide one, and about half are reluctant to admit they use AI for their most important tasks. The problem is not intent. The problem is that company data ends up somewhere you cannot see, on terms you never negotiated.
Three properties set shadow AI apart from every other kind of unsanctioned software, and they are worth spelling out because they are exactly what defeats the controls most teams already run.
It is frictionless. There is nothing to install and often no account to create. A free tier and a browser tab are enough.
It hides inside traffic you already allow. Gemini lives on google.com. Copilot lives on microsoft.com. A prompt is an ordinary HTTPS request to a domain your proxy has probably permitted for years.
The risk is in the content, not the app. A chatbot is harmless until someone pastes a customer list into it. The line between safe and unsafe is whatever happens to be in the text box.
How shadow AI differs from shadow IT
Security teams have spent a decade getting good at shadow IT. Discovery tools flag the new SaaS domain, finance flags the expense claim, and the CASB flags the OAuth grant. A rogue file-sharing account is a problem, but it is a problem with edges: you can find it, cut it off, and pull the files back.
Shadow AI has almost none of those edges, which is why the playbook that worked for unsanctioned apps mostly does not transfer.
What it is
- Shadow IT
- Unsanctioned apps and services: a personal file-sync account, a team’s project board, a chat workspace nobody approved.
- Shadow AI
- Unsanctioned AI use: a personal chatbot account, a browser copilot, an AI feature switched on inside an app you already approved.
The footprint it leaves
- Shadow IT
- A sign-up, an OAuth grant, a new domain in the proxy log, an expense claim.
- Shadow AI
- A text box. Often no install, no account, and a domain you already allow.
How data leaves
- Shadow IT
- Files uploaded or synced over weeks.
- Shadow AI
- Pasted into a prompt in seconds, in the middle of ordinary work.
What the network sees
- Shadow IT
- A new SaaS domain you can categorize and block.
- Shadow AI
- HTTPS to google.com, microsoft.com, or a domain that launched last week.
How you find out
- Shadow IT
- App discovery, CASB reports, finance reviews.
- Shadow AI
- Usually a colleague asking whether it was okay to paste that — if you find out at all.
Can you take it back?
- Shadow IT
- Often. Delete the account, revoke the token, pull the files.
- Shadow AI
- No. Once the prompt is sent, retention and training are the vendor’s decision.
| Dimension | Shadow IT | Shadow AI |
|---|---|---|
| What it is | Unsanctioned apps and services: a personal file-sync account, a team’s project board, a chat workspace nobody approved. | Unsanctioned AI use: a personal chatbot account, a browser copilot, an AI feature switched on inside an app you already approved. |
| The footprint it leaves | A sign-up, an OAuth grant, a new domain in the proxy log, an expense claim. | A text box. Often no install, no account, and a domain you already allow. |
| How data leaves | Files uploaded or synced over weeks. | Pasted into a prompt in seconds, in the middle of ordinary work. |
| What the network sees | A new SaaS domain you can categorize and block. | HTTPS to google.com, microsoft.com, or a domain that launched last week. |
| How you find out | App discovery, CASB reports, finance reviews. | Usually a colleague asking whether it was okay to paste that — if you find out at all. |
| Can you take it back? | Often. Delete the account, revoke the token, pull the files. | No. Once the prompt is sent, retention and training are the vendor’s decision. |
What shadow AI looks like in practice
Shadow AI rarely announces itself. It does not appear as a new vendor in procurement or a spike on the SOC dashboard. It surfaces later, usually as a question in a team channel from someone who has just realized what they pasted. These four patterns show up in almost every organization.
The developer under pressure
A service is throwing errors in production. The engineer copies the full stack trace, configuration included, into a public chatbot and asks what is wrong. The trace contains internal hostnames, a database connection string, and an API key that was never meant to leave the environment.
The account executive with a spreadsheet
Quarter end is close. An AE exports 2,400 customer rows — names, email addresses, contract values, renewal dates — and asks an assistant to flag the accounts most likely to churn. That export now sits with a vendor the company has no data-processing agreement with.
The analyst with a deadline
The approved copilot is slow this afternoon, so the analyst opens a personal Gemini tab in the same browser and keeps working. Same laptop, same data, different account. Nothing in SSO or the proxy logs looks unusual, because nothing new was accessed.
The sidebar that reads the page
A browser assistant is docked next to the CRM. It offers to summarize the record on screen, so someone clicks. A customer’s full account history leaves the browser in one click, and no file was ever uploaded.

None of this is hypothetical. In 2023, engineers at Samsung pasted proprietary source code and internal meeting notes into ChatGPT while trying to fix bugs and draft minutes. The company responded by temporarily banning generative AI tools on company devices while it built an internal alternative. Nobody involved was trying to leak anything. They were trying to finish their work — which is precisely what makes shadow AI so hard to stop with awareness alone.
Why shadow AI is a bigger risk than it looks
It is tempting to file shadow AI under “awareness training” and move on. The numbers suggest that would be a mistake.
43%
of breached organizations in IBM’s 2026 study reported a security incident involving shadow AI — more than double the year before.
IBM, Cost of a Data Breach Report 2026
$5.39M
average cost of a breach involving shadow AI. Roughly one in five of those incidents also drew a regulatory fine.
IBM, Cost of a Data Breach Report 2026
Nearly 40%
of employee interactions with AI tools involve sensitive data, and roughly a third of that use happens through personal accounts.
Cyberhaven Labs, 2026 AI Adoption & Risk Report
Behind those figures sit four concrete problems, and each one gets harder the longer the data has been gone.
There is no recall
Once a prompt is sent, retention, training, and deletion are governed by the vendor’s consumer terms rather than your contract. You cannot pull the paste back, and you usually cannot prove it was deleted.
You cannot protect what you cannot inventory
Every control in your program — classification, access reviews, processing agreements, breach notification — assumes you know where data lives. Shadow AI creates copies in places that are on nobody’s list.
Contracts and regulators do not grade on intent
Customer agreements typically restrict who may process their data. An unapproved AI vendor is an unapproved processor whether or not anyone meant it to be, and IBM found that about one in five shadow AI incidents ended with a fine.
Incident response has nothing to work with
A breach you can scope is a breach you can close. “We think someone pasted the customer list somewhere” comes with no log, no timestamp, and no list of affected records. It is a suspicion, not an incident.

You cannot run an incident response on a paste you never saw.
Why the controls you already have miss it
Most organizations already run three or four controls that sound as though they should cover this. Each does something useful. None was designed for a text box.
URL and DNS blocklists
- What it does well
- Blocking a known consumer chatbot domain on the corporate network.
- Where shadow AI slips through
- New assistants and wrappers launch every week, so the list is always behind. Blocking google.com or microsoft.com to reach the AI inside them is not an option. And a block on the office browser simply moves the paste to a personal phone, where you have no visibility at all.
DLP and CASB
- What it does well
- File uploads, email attachments, and sanctioned SaaS where you hold the API keys.
- Where shadow AI slips through
- A prompt is a small request body inside TLS to a domain that may already be on your allowlist. Without full interception and inspection tuned for prompts, nothing fires — and full interception means storing everything employees type, which creates a privacy problem of its own.
Acceptable-use policy
- What it does well
- Setting expectations and giving managers something concrete to point to.
- Where shadow AI slips through
- A policy does not stop a paste at six in the evening. IBM’s 2026 report found that 68% of breached organizations had no AI governance in place to manage AI or detect shadow AI. Policy is necessary. On its own, it is not a control.
A sanctioned assistant
- What it does well
- Giving people a safe default and removing most of the temptation to look elsewhere.
- Where shadow AI slips through
- Adoption is never total. The gap between the approved copilot and whichever tool happens to be open right now is exactly where shadow AI lives.
The common thread is that each of these controls acts on the container — the domain, the file, the account — while the risk sits in the content of a single field. A control that works has to act where the paste happens.
A practical four-step playbook
You do not need a new platform to get started. You need visibility, a decision, a control, and a path for legitimate use — in that order.
- 1
Discover how AI is actually being used
Before writing anything down, find out what people are doing and why. Pull AI-related domains from proxy and DNS logs, review OAuth grants in your identity provider, check browser extension inventories, and — most usefully — ask teams directly, with no penalty attached. You will learn which approved tools are missing or too slow, and that is the root cause you need to fix.
- 2
Decide what is allowed, for whom, with which data
Write an AI acceptable-use policy people can actually follow: which tools are approved, which categories of data may never go into a prompt, and how to request an exception. Keep it to a page. Pair it with a sanctioned assistant good enough that most people stop looking.
- 3
Put a control at the prompt
Enforce the policy where the risk is: the moment someone types or pastes into an AI prompt field on a managed browser. Block by default, allow the tools you have approved, and make the block visible so people understand what happened and why. This is the step most programs skip, and it is the one that turns a policy into a control.
- 4
Give people a fast path to yes
A block with no exit creates workarounds. Route requests for AI access to a named approver, make approvals time-boxed by default, and review the request log monthly. The requests tell you what people need, which feeds straight back into step one.
Where prompt blocking fits
Step three is where Nullgen comes in. Nullgen is a browser extension that recognizes AI prompt fields on any website — including assistants that launched last week — and stops text from being typed or pasted into them. The rest of the page keeps working: search, documentation, the CRM, the ticketing system. Only the prompt is blocked.
Detection runs entirely on the device. The text someone was about to paste is never sent to Nullgen or to anyone else, so the control does not create the privacy problem that prompt-inspecting proxies do. There is no TLS interception, no certificate rollout, and no new inline failure point in the network path.
The free extension covers a single browser, which is the right way to evaluate it: install it on your own laptop, open an assistant, and try to paste something. Nullgen Pro is the fleet version.
Zero-touch deployment through Intune, Jamf, Google Workspace, or Group Policy, pinned so the person at the keyboard cannot remove it.
Policies that allow or deny specific AI sites for selected users, synced to enrolled browsers in real time.
Access requests that route to named approvers, with temporary or permanent grants.
One dashboard for users, devices, requests, and policies — the inventory shadow AI never had.
In other words, the paste becomes a request, and the request becomes a record. That is the difference between hoping people follow the policy and knowing the control was there.
Key takeaways
Shadow AI is unapproved AI use with company data. It is usually well intentioned, and it is already happening in your organization.
It behaves differently from shadow IT: no install, no new domain, no trail — and no way to get the data back.
URL blocklists, DLP, and policy each act on the container. The risk is in the content of a single prompt field.
Start with discovery and a one-page policy, then enforce at the prompt and give people a fast path to approved access.
Prompt blocking on managed browsers is the control that closes the gap, and the free extension is enough to test it today.
Frequently asked questions
Is shadow AI the same thing as shadow IT?
They are related but not the same. Shadow IT is unsanctioned software and services; shadow AI is unsanctioned use of AI tools, which usually requires no software at all. The controls that catch shadow IT — app discovery, OAuth reviews, expense audits — mostly do not see shadow AI, because there is nothing to install and the data leaves through an ordinary text field.
Should we just block ChatGPT and the other big assistants?
Blocking domains buys a little time but does not solve the problem. New assistants appear constantly, AI is now built into sites you cannot block, and a blocked office browser pushes the same paste onto a personal phone. A better approach is to allow approved tools, block the prompt everywhere else, and give people a way to request exceptions.
Does prompt blocking mean IT reads what employees type?
Not with Nullgen. Detection runs in the browser, on the device, and prompt text is never sent to Nullgen or to your administrators. Approvers see which site was requested and for how long — not what anyone was about to type.
What about AI built into tools we already approve?
Approved assistants can be allowed by policy for the users who need them while everything else stays blocked. The goal is not to stop AI. It is to make sure company data only goes into tools you have vetted, under terms you have agreed to.
How long does a rollout take?
The free extension installs in about a minute on a single browser. Pro deploys through the MDM you already run — Intune, Jamf, Google Workspace, or Group Policy — so a fleet rollout is a policy push rather than a network project.
Sources
- IBM and Ponemon Institute, Cost of a Data Breach Report 2026
- Microsoft and LinkedIn, 2024 Work Trend Index: AI at Work Is Here. Now Comes the Hard Part
- Cyberhaven Labs, 2026 AI Adoption & Risk Report
- TechCrunch, “Samsung bans use of generative AI tools like ChatGPT after April internal data leak,” May 2023
Try it on some office computers
Install the free extension, open any assistant, and try to paste. When you are ready for the fleet, Nullgen Pro deploys through the MDM you already run and routes exceptions to the people who should approve them.