Skip to content

6 min read

American Corners

Shadow AI

Helpful tools, quietly risky

AI assistants are genuinely useful. They summarise long documents, draft emails, fix code, translate, and answer questions in seconds. So it is no surprise that people reach for whatever tool works, often without asking anyone.

Shadow AI is the name for exactly that: using AI tools and services that your workplace has not reviewed or approved. It is rarely done with bad intent. Someone just wants to get their work done faster, so they paste a report into a free online assistant, or sign up for a handy new app, without realising what happens to the information they hand over.

Why unapproved tools leak data

When you type or paste something into an online AI tool, that information leaves your control and lands on someone else's servers. Depending on the service, it may be stored, logged, reviewed by staff, or used to train future versions of the model. You usually cannot see any of that happening, and you cannot take the data back.

Now think about what people naturally feed into these tools to get useful answers:

  • a customer list, or personal details of clients;
  • an internal report, contract, or financial figures;
  • source code, passwords, or system details;
  • a document a colleague shared in confidence.

Any of these leaving the organisation through an unapproved tool is a data leak, even though nothing was "hacked". It can breach confidentiality agreements, privacy law, and your employer's duty to protect the people whose data it holds. And it is invisible: because the tool was never registered, no one knows the information went out at all.

The two habits that keep you safe

You do not have to become an expert on every AI service. Two simple habits cover most of the risk.

Use approved tools. If your workplace has chosen or paid for specific AI tools, use those. Approved tools usually come with agreements about how your data is handled, and they have been checked against the rules your organisation has to follow.

Ask IT when unsure. If a tool has not been approved, or you are not certain, ask before you use it, and before you paste anything sensitive into it. "Can I use this tool for this kind of information?" is a quick question that prevents a slow, expensive problem. Asking is not a nuisance; it is the responsible move.

Warning

Treat anything you type into an unapproved AI tool as if you had posted it publicly, because you may have. Never paste customer data, internal documents, credentials or secrets into a tool your workplace has not approved. When in doubt, ask IT first.

The takeaway

Shadow AI is not a story about bad people, it is about good people using handy tools without knowing the cost. The fix is not to fear AI, but to keep it inside the lane your organisation has set: approved tools for the job, and a quick question to IT whenever you are unsure.

Check yourself

AI risks

Where this lesson comes from

Built from

  • Workshop 5: AI Security Tools and Defending Against AI-Enabled Threats (V3.0): using AI responsibly at work

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement