Safeguard
Concepts & Glossary
AI Security

Shadow AI

Models, agents and AI tools in use across an organisation that no one has approved or inventoried.

Browse all concepts
◈ the lookup — ai security — the inventory gap
Definition

What is shadow AI?

Shadow AI is model, agent and AI-tool usage that exists inside an organisation without having been approved, reviewed or inventoried. A team wires a hosted model into a support workflow on a personal key; an engineer installs an MCP server from a public registry into an editor that holds repository credentials; a department uploads a customer spreadsheet into a chat product to summarise it.

It is the successor to shadow IT, and it spreads faster for a simple reason: adopting an AI tool needs no procurement, no infrastructure and often no payment. The barrier that made shadow IT visible — someone had to provision something — is gone.

Mechanism

How it works

Not an attack; an adoption pattern with security consequences:

  1. 01

    Adoption outruns review

    The tool solves a real problem today. The review process takes three weeks. The tool wins, and nobody was acting in bad faith.

  2. 02

    Data leaves the boundary

    Prompts carry whatever context the task needs — source code, customer records, internal documents — to a provider with unknown retention and unknown training use.

  3. 03

    Credentials accumulate

    Agents need access to be useful, so they get tokens. Those tokens are scoped by whoever set them up, which is to say usually not scoped.

Stakes

Why it matters

The exposure is invisible by construction. Nothing appears in an asset register, no vulnerability scanner reports it, and the first accurate picture usually arrives during an incident or a customer security questionnaire.

Blocking is also the response that fails. Prohibition drives usage onto personal accounts and personal devices, where there is no logging at all — the organisation trades a visible risk for an invisible one. The workable answer is discovery plus a sanctioned path that is easier than the unsanctioned one.

And the questions are now contractual. Enterprise security reviews and the EU AI Act both ask which AI systems process which data. "We are not sure" is an answer with commercial consequences.

Value

What value it adds to find it

The real inventory

What is actually in use, rather than what was approved — usually two quite different lists.

Data-exposure visibility

Which providers are receiving which categories of data, and under what retention terms.

Credential sprawl

Personal API keys and unscoped agent tokens are the most common finding, and the easiest to fix.

A path to sanctioned use

Discovery tells you what to provide centrally. A governed alternative that is easier to use is what actually ends shadow usage.

Answers for the questionnaire

AI-SPM turns an uncomfortable question into a report you can attach.

In the product

How Safeguard uses it

Safeguard discovers unregistered model endpoints, agent frameworks and MCP servers across the estate, records what each reaches, and gives governed alternatives an inventory to route onto. See OSM and the AI governance workflow.

Find out what is already running.

Safeguard discovers the AI in use across your estate, approved or otherwise, and what each piece can reach.

Browse all concepts

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.