📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Shadow AI

What is Shadow AI?

Shadow AI is the use of unsanctioned generative-AI services (ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral, Grok, GitHub Copilot, and similar) by employees inside an organisation. Staff who would never have emailed a spreadsheet of customer records to an outside vendor now routinely paste similar data into a generative-AI chat. Lavawall® gives you visibility into which AI tools are actually in use.

Start free, no credit card See how it works

Generative-AI discovery · user attribution · sanctioned-alternative provisioning

Definition

Shadow AI is employee adoption of generative-AI tools outside organizational oversight. It is a specific, fast-growing slice of the older "shadow IT" problem, but its risk profile is different. The data leaves the organisation as conversational text pasted into a chat box rather than as a file uploaded to a sanctioned service, so it slips past the tools and habits built to catch file-based sharing.

Three characteristics set shadow AI apart from ordinary shadow IT. First, the leakage is conversational: users underestimate how long the data persists and whether it may be used to train a model. Second, generated output can carry undisclosed licensing implications that the organisation has to assess. Third, adoption is outpacing the acceptable-use policies and data-loss-prevention tools meant to govern it.

Because the pattern is a subset of shadow IT rather than a separate category, the answer is not one more block rule. It is visibility plus sanctioned-alternative provisioning: see who is using which service, then give them a corporate-licensed AI service with documented data-handling guarantees and move them to it.

Core components

  • Generative-AI chat services. ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), Copilot (Microsoft), Perplexity, Mistral, Grok (xAI), and similar consumer-facing or developer-facing chat interfaces.
  • AI-enabled developer tools. GitHub Copilot, Cursor, JetBrains AI Assistant, Cody, Codeium, and similar tools that send code context to a model for completion or refactoring.
  • AI features in mainstream SaaS. Generative-AI features now embedded in Microsoft 365 Copilot, Google Workspace Gemini, Notion AI, Slack AI, and similar, which may be sanctioned or unsanctioned depending on the licence.
  • Model-context-leakage risk. The risk that data pasted into a model is retained, used for training, or surfaced in a subsequent unrelated prompt. This varies sharply by service, plan, and user setting.
  • Output-licensing risk. The risk that AI-generated content carries undisclosed licence implications, such as open-source code suggestions, copyrighted text fragments, or watermarked images.
  • Sanctioned-alternative provisioning. The remediation pattern: provide a corporate-licensed AI service (ChatGPT Team / Enterprise, Claude Team, Microsoft Copilot for M365, Google Gemini Workspace) with appropriate data-handling guarantees, and migrate users to it.

Why it matters

For regulated industries, shadow AI represents an active disclosure risk. A healthcare professional pasting a patient note into a consumer ChatGPT account to "make it sound nicer" is a HIPAA / PIPEDA / BC HIA / Alberta HIA disclosure event. A securities firm employee asking an AI to summarise a confidential transaction is potentially a regulated-information disclosure.

For non-regulated organisations, shadow AI still has commercial implications. Customer lists, pricing strategies, and proprietary process documentation regularly find their way into consumer AI services. The data may not be retained, the user may have selected the right setting, but the organisation has no audit trail to prove it.

For MSPs, shadow-AI visibility has become a billable conversation. Clients want to know whether their staff are using AI services, which services, and how often, and they want sanctioned-alternative recommendations they can deploy quickly.

How Lavawall® helps with shadow AI

Lavawall® reviews email metadata against a curated 1,130+ SaaS application catalog to surface SaaS usage with low false-positive rates. The catalog includes the major generative-AI services and the tools that integrate with them. The result is a list of AI applications genuinely in use, attributed to specific users.

For MSP and IT teams, the platform supports an authorisation workflow. You can sanction specific AI services by category, surface unauthorised alternatives that should be migrated to the sanctioned ones, and produce reports the client's compliance officer can use in their next review.

Because SaaS / shadow-AI discovery is bundled into the Lavawall® platform alongside patching, GRC, and breach detection, the data feeds directly into compliance evidence (CMMC 2.0 SC.L2-3.13.6, NIST CSF DE.CM-7, CIS Control 16, SOC 2 CC6.6, PIPEDA accountability principle) without a separate per-user CASB invoice.

Start free → Map controls with the GRC wizard

Frequently asked

Is shadow AI just shadow IT?
It is a subset of shadow IT with a distinctive risk profile. The conversational data-paste pattern, the rapid adoption pace, the model-training implications, and the output-licensing concerns are all characteristic of generative-AI usage in particular.
Can I just block ChatGPT and Claude at the firewall?
You can, and some organisations do, but blocking alone tends to push users to mobile data, personal devices, or VPNs. The more sustainable pattern is visibility plus sanctioned-alternative provisioning: see who is using what, deploy a sanctioned corporate service with appropriate data-handling guarantees, and migrate users to it.
Does Microsoft Copilot for M365 solve the shadow-AI problem?
It can solve a portion by providing a sanctioned generative-AI service with M365-tenant data handling, but only if the organisation also has visibility into who is still using consumer services. Copilot deployment without shadow-AI discovery just adds another tool to the mix.
How is this different from a CASB?
A CASB enforces policy at the network or API layer, actively blocking or proxying SaaS traffic. Lavawall® shadow-AI discovery focuses on visibility and attribution. For most MSP clients, visibility plus a sanctioned-alternative conversation is sufficient. CASBs and Lavawall® can coexist for clients that need active enforcement on top of visibility.