Shadow AI
Shadow AI is the AI use no one approved and no one is tracking. Learn why it is your blind spot and how shadow AI discovery works from logs you already collect, with no endpoint agents.
23 June 2026 · 6 min read
Shadow AI is any use of AI tools inside an organisation that has not been approved or is not being tracked, such as staff using personal accounts or free AI apps for work. It matters because a firm cannot govern, cost or evidence AI use it cannot see, which is exactly the use a client questionnaire, an auditor or a regulator will probe. Shadow AI can be discovered without endpoint software by reading the firewall, proxy, secure web gateway or SIEM logs a firm already collects, which show which AI services devices connect to, by destination, without capturing prompt content.
Most firms now have AI in use that nobody formally approved. A paraplanner pasting a client's circumstances into a free chatbot to draft a suitability letter. A trainee solicitor summarising a witness statement in a browser tool they found last week. A bookkeeper running a spreadsheet macro that quietly calls an AI service. None of it went through procurement. None of it appears on any register. That is shadow AI, and if you run compliance, risk or IT at a regulated firm, it is already your problem.
Shadow AI is any use of artificial intelligence inside your firm that sits outside your approved, governed list of tools. It is the AI equivalent of "shadow IT" — the personal apps and unsanctioned software that staff adopt because they are faster or easier than the official option.
It comes in three broad shapes:
The common thread is that the use is real, ongoing and undocumented. People rarely adopt shadow AI to cause harm. They adopt it because it helps them get the work done.
Shadow AI is not a fringe habit. In Microsoft and LinkedIn's 2024 Work Trend Index, published on 8 May 2024, 78% of the people who use AI at work said they bring their own AI tools rather than ones their organisation provided. Earlier, a Salesforce survey of more than 14,000 workers, run with YouGov in October 2023, found that more than half of the workers who use generative AI do so without their employer's formal approval. Methods and wording differ between studies, but the direction is consistent: in any firm of more than a handful of people, some AI use is happening in tools no one approved, and some of it touches information you would not want in a public model.
For an unregulated business, shadow AI is mostly an information-security headache. For an FCA-authorised adviser, a law firm or an accountancy practice, it touches obligations you are accountable for.
If you cannot say which AI tools your staff use, you cannot evidence that client data has been handled properly — and "we didn't know" is not a defence a regulator accepts.
Consider the specific exposures:
The reputational risk is just as concrete. The first time you hear about a tool may be when a client, an auditor or the regulator asks a question you cannot answer.
The instinct is to install monitoring agents on every device. For most regulated SMBs that is slow, intrusive and resisted by staff. The good news: you almost certainly already hold the evidence you need.
Every time someone uses an AI tool over the web, their device connects to that tool's destination — and your firewall, web proxy, secure web gateway (SWG) or SIEM logs that connection. Detection by destination means you can see which AI services are being reached from your network, from a browser, a desktop app or a script, without putting anything new on a single laptop.
This is the approach Evaident takes. It reads the logs you already collect and turns them into a clear picture of which AI destinations are in use and, where your logs carry user identity, by whom. A few honest limits worth stating plainly:
That division of labour is the point. You get visibility from data you own, without a rollout project.
Discovery is not the goal — a decision is. For each tool that surfaces, take one of three actions and write it down:
The register matters as much as the decisions. It gives you one tamper-evident, hash-chained record of AI use across approved tools, in-house agents and the shadow apps you have discovered — the artefact you produce when a regulator, an auditor or a client asks how AI is governed in your firm. This is also why your AI policy is not evidence on its own, and it is one part of the wider discipline of AI governance. Evaident maps that evidence to the EU AI Act, UK GDPR, FCA Consumer Duty and SYSC 9, and the SRA Code. It supports your compliance function rather than replacing it, and it is not legal advice.
Shadow AI is not a reason to ban AI. It is a reason to find out what is actually happening, make calm decisions, and keep a record you can stand behind.
A good first step is to see what your own logs already reveal. Run an exposure check to find the AI tools in use across your firm, or read how Evaident maps to your obligations on the /fca page.
The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.