Shadow AI
Models, agents and AI tools in use across an organisation that no one has approved or inventoried.
What is shadow AI?
Shadow AI is model, agent and AI-tool usage that exists inside an organisation without having been approved, reviewed or inventoried. A team wires a hosted model into a support workflow on a personal key; an engineer installs an MCP server from a public registry into an editor that holds repository credentials; a department uploads a customer spreadsheet into a chat product to summarise it.
It is the successor to shadow IT, and it spreads faster for a simple reason: adopting an AI tool needs no procurement, no infrastructure and often no payment. The barrier that made shadow IT visible — someone had to provision something — is gone.
How it works
Not an attack; an adoption pattern with security consequences:
- 01
Adoption outruns review
The tool solves a real problem today. The review process takes three weeks. The tool wins, and nobody was acting in bad faith.
- 02
Data leaves the boundary
Prompts carry whatever context the task needs — source code, customer records, internal documents — to a provider with unknown retention and unknown training use.
- 03
Credentials accumulate
Agents need access to be useful, so they get tokens. Those tokens are scoped by whoever set them up, which is to say usually not scoped.
Why it matters
The exposure is invisible by construction. Nothing appears in an asset register, no vulnerability scanner reports it, and the first accurate picture usually arrives during an incident or a customer security questionnaire.
Blocking is also the response that fails. Prohibition drives usage onto personal accounts and personal devices, where there is no logging at all — the organisation trades a visible risk for an invisible one. The workable answer is discovery plus a sanctioned path that is easier than the unsanctioned one.
And the questions are now contractual. Enterprise security reviews and the EU AI Act both ask which AI systems process which data. "We are not sure" is an answer with commercial consequences.
What value it adds to find it
The real inventory
What is actually in use, rather than what was approved — usually two quite different lists.
Data-exposure visibility
Which providers are receiving which categories of data, and under what retention terms.
Credential sprawl
Personal API keys and unscoped agent tokens are the most common finding, and the easiest to fix.
A path to sanctioned use
Discovery tells you what to provide centrally. A governed alternative that is easier to use is what actually ends shadow usage.
Answers for the questionnaire
AI-SPM turns an uncomfortable question into a report you can attach.
How Safeguard uses it
Safeguard discovers unregistered model endpoints, agent frameworks and MCP servers across the estate, records what each reaches, and gives governed alternatives an inventory to route onto. See OSM and the AI governance workflow.
Find out what is already running.
Safeguard discovers the AI in use across your estate, approved or otherwise, and what each piece can reach.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.