Somewhere in your organisation, right now, someone is pasting a contract into a chatbot to get a summary before a meeting. Someone else is asking an AI tool to tidy up a spreadsheet of customer complaints. A developer is sharing a block of code to find a bug. None of them think of this as a security event. Each of them has just sent company data to a third party that nobody approved.
This is shadow AI: the use of AI tools and features outside the organisation's knowledge, approval or control. It is the most widespread information security risk most organisations have not yet measured.
Why it is not just shadow IT again
Security teams have dealt with unapproved software for twenty years, so it is tempting to treat shadow AI as the same problem with a new name. It is not, for four reasons.
- Every prompt is an upload. With shadow IT, the risk was mostly where data was stored. With AI, data leaves in the normal course of the conversation, one paste at a time, often without anyone noticing.
- Nothing needs to be installed. A browser tab or a phone app is enough, so the controls built to stop unapproved installs never see it.
- It arrives inside approved tools. Vendors are switching on AI features in products you already use. The tool passed your assessment last year; its new AI assistant never did.
- The output comes back in. AI answers flow into reports, code and decisions. A wrong or invented answer becomes an integrity problem, not just a confidentiality one.
What is actually at risk
Confidential and personal data
Contracts, financial results, customer records, staff details and source code are exactly the material people want help with, and exactly what should not leave the organisation unprotected. Personal data brings data protection obligations with it, including the UAE's personal data protection law and sector rules on top.
Retention and training
Free and personal AI accounts often keep conversations and may use them to improve the vendor's models. Once data is in someone else's training pipeline, there is no meaningful way to get it back.
Access you did not mean to grant
AI assistants increasingly ask to connect to email, calendars, file storage and code repositories. One click on "Allow" can give an unknown app ongoing access to a mailbox or a whole drive, long after the person stops using it.
Decisions built on bad answers
AI tools can be confidently wrong. When unchecked output finds its way into a board paper, a customer reply or production code, the error carries the organisation's name, not the tool's.
Why banning it fails
The first instinct is often to block every AI site and send a stern email. It rarely works. Staff move to their phones and personal laptops, where you have even less visibility, and the productivity they were chasing is lost to the organisation entirely. A ban without an alternative turns a manageable risk into an invisible one.
A practical playbook
The organisations handling this well follow a simple sequence: see it, offer something better, set clear rules, then enforce them.
- Discover what is already in use. Look at web proxy and DNS logs for AI services, review app permissions granted in your email and collaboration platforms, check browser extensions on managed devices, and ask procurement which subscriptions are being expensed.
- Provide an approved option quickly. An enterprise AI service with single sign on, no training on your data, defined retention and audit logs removes most of the reason to go around the rules.
- Make the data rules simple. Three levels people can remember: what can go into approved AI freely, what can go in with care, and what must never go in. Use real examples from their own work.
- Add technical guardrails. Extend data loss prevention to AI destinations, restrict which apps users can authorise against company accounts, and block unapproved AI services on managed devices once a sanctioned option exists.
- Bring vendors into scope. Add AI questions to third party risk assessments: does the product use AI, where is the data processed, is it used for training, and can the feature be switched off?
- Invite people to declare their tools. A short amnesty, where staff can list the AI tools they use without consequence, often reveals more than any log review.
- Review regularly. The AI landscape changes monthly. Revisit the inventory, the approved list and the rules at least every quarter.
Five questions every leadership team should ask
- Do we know which AI tools and AI features our people are using today?
- Have we given staff an approved, secure option, or only a list of prohibitions?
- Do our people know what data must never be entered into an AI tool?
- Which third party apps have been granted access to our email, files or code, and who approved them?
- Do our vendor contracts say how our data may be used by their AI?
Shadow AI is not a reason to fear AI. It is evidence that people want it. Security's job is to make the safe path the easy path, so that the next contract summary happens in a tool the organisation can see, govern and trust.