SIGNAL//DESK
AI governancesrc: OWASP LLM Top 10

Shadow AI

Shadow AI is when employees use unauthorized AI tools to do their work without the company's knowledge, which is like sneaking unvetted software into the office that could accidentally share private company secrets with outsiders.

Shadow AI refers to the deployment or utilization of AI applications and large language models by staff without formal IT or security approval, bypassing established governance frameworks and creating significant blind spots regarding data privacy, regulatory compliance, and third-party vendor risk.

Shadow AI denotes the proliferation of unauthorized AI-driven systems and models within an enterprise environment, operating outside the purview of centralized IT and security oversight. This phenomenon introduces systemic vulnerabilities, including unauthorized data exfiltration, non-compliance with data protection mandates (e.g., GDPR, CCPA), and unmanaged supply-chain risks stemming from opaque third-party model provenance and data processing practices.

evolution

  1. 2022-11 · history
    ChatGPT Launch

    The public release of ChatGPT triggers widespread, unmanaged adoption of generative AI tools by employees across corporate environments.

  2. 2023-05 · history
    Samsung Data Leak Incident

    Samsung bans internal use of generative AI after employees inadvertently uploaded sensitive source code and meeting notes to ChatGPT.

  3. 2023-09 · history
    Formalization of Shadow AI

    Industry analysts and cybersecurity firms begin explicitly using the term 'Shadow AI' to categorize unauthorized AI usage as a distinct enterprise risk.

  4. 2024-02 · history
    Enterprise Governance Shift

    Major security frameworks and compliance standards begin incorporating specific controls to detect and mitigate Shadow AI as a standard IT security requirement.


← all terms