HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 28.07.2026 10:32 CET 51 dossiers MITRE ATT&CK mapping

Editorial explainer · official sources (ENISA, NIST)medium

Shadow AI: the risk isn't artificial intelligence, it's the kind you use in secret

Every time an employee pastes a confidential document, a piece of code or customer data into a public chatbot to save time, the company has a problem it cannot see: Shadow AI, the use of artificial-intelligence tools outside IT's control. It is the evolution of Shadow IT, and the instinctive reaction — ban everything — is almost always the wrong one. An explainer on what those who use AI in secret really risk, on what official frameworks like the NIST AI Risk Management Framework suggest, and on why the answer is cultural and about governance before it is technical.

The invisible gesture

There is a gesture that happens dozens of times a day in any company and that no firewall records: an employee, to save time, pastes into a public chatbot a contract, the minutes of a meeting, a customer list, a fragment of source code. There is no bad intent, there is a deadline. But in that gesture a piece of data that was meant to stay inside the perimeter leaves, and ends up on a service the company does not control, has not assessed, often does not even know exists. This is Shadow AI: the use of artificial-intelligence tools outside IT's knowledge and control. It is the updated version of an old phenomenon — Shadow IT, the apps and services employees adopt on their own — with a difference that weighs: generative AI invites you to give it exactly the data it should not see.

What is really at risk

The most immediate risk is data leakage. What is entered into a public AI service may be stored, processed, in some cases used to train the models: confidential information, personal data, intellectual property can leave the organisation without anyone noticing.

  1. 01
    Confidential data in a public service
    stored or reused outside the company's control
  2. 02
    Personal data without a legal basis
    possible GDPR breach if it reaches third parties
  3. 03
    Wrong outputs taken at face value
    hallucinations enter real decisions

But it is not only about data going out. There is a compliance risk: if that data includes personal information, giving it to a third-party provider — perhaps outside the EU — without a legal basis and without safeguards can amount to a GDPR breach. There is a quality risk: generative models can produce answers that are wrong but plausible — so-called hallucinations — and if an unverified output enters a business decision, the error propagates. And there is the attack surface every uncatalogued tool adds, from third-party plugins to prompt injection.

Why banning doesn't work

The instinctive reaction, faced with all this, is the ban: "AI is prohibited." It is the same reaction the human factor has always received — blame whoever clicked — and it is just as ineffective. The ban does not eliminate Shadow AI: it pushes it deeper into the shadows. People use these tools because they work, because they save time; removing the tool without offering an alternative only means the same tool gets used in secret, with more care about not being caught than about protecting the data.

0
traces in the logs
the gesture never touches a system the company controls
2
possible roads
ban and push into the shadows, or govern and make it safe
4
the NIST AI RMF functions
Govern, Map, Measure, Manage

The road the official frameworks point to is the opposite: govern instead of prohibit. The NIST AI Risk Management Framework (AI 100-1) organises AI risk management around four functions — Govern, Map, Measure, Manage — that all start from the same premise: you cannot manage what you do not know. First you map which AI tools are used and for what, then you assess the risks, then you put measures in place. ENISA, in its threat-landscape reports, places AI both among attackers' tools and among the surfaces to protect: the problem is not the technology itself, it is ungoverned use.

Culture before the tool

Translated into practice, tackling Shadow AI means three things, in this order. Offer a safe alternative: approved AI tools where company data does not end up in a public model. Give clear rules: a data classification that says what may and may not be entered, in plain language, not a thirty-page policy no one reads. And make it possible to ask: a channel where an employee can ask "may I use this tool for this task?" without feeling guilty, so that usage comes into the light instead of hiding.

This is an explainer, not the attack of the day; but it is exactly the kind of risk that decides whether the technical defences hold. The lesson is the same as the human factor's: people are not the weak link to scold, they are a system to design. If the only way to do your job well is to bypass the rules, the rules are wrong. The references that matter — NIST's framework and ENISA's reports — are verifiable at the official sources at the top of the page.

More dossiers