Interactive Guide
What is
Shadow AI?
Shadow AI is the use of AI tools by employees without the organisation's approval or oversight.
Explore the RisksThe Hidden Problem
Published surveys show why organisations should investigate unapproved AI use.
- of global knowledge workers surveyed used AI at work, Microsoft and LinkedIn, 2024Microsoft + LinkedIn
- 75%
- of workers surveyed said their company had clearly articulated policies for approved AI tools and use cases, Salesforce, 2023 surveySalesforce
- 21%
- of workplace generative-AI users surveyed had used unapproved tools, Salesforce, 2023Salesforce
- 55%
- of 200 US enterprise IT directors and executives surveyed were concerned about Shadow AI privacy and security risks, Komprise, 2025Komprise
- 90%
Separate surveys, not a comparable dataset. Each figure has its own population and date. Salesforce's 2024 summary reports its 2023 survey; Komprise surveyed US organisations with 1,000+ employees.
Shadow AI in the Wild
Click any card to see how these common scenarios put your organisation at risk.
01ChatGPT for Code & DocsDevelopers pasting proprietary code into public AI assistants.Click to learn more →Click to collapse ↑
Employees copy sensitive source code, internal documentation, and customer data into ChatGPT or similar tools, bypassing security controls and potentially exposing trade secrets.
02Personal AI AssistantsStaff using personal AI accounts for work tasks.Click to learn more →Click to collapse ↑
Employees use personal subscriptions to Claude, Gemini, or Copilot for work-related tasks. Company data flows through unmonitored, ungoverned channels with no audit trail.
03Unauthorised API IntegrationsTeams connecting AI APIs without IT approval.Click to learn more →Click to collapse ↑
Engineering and product teams integrate AI APIs directly into workflows, sometimes hardcoding API keys and sending production data to third-party models without security review.
04AI Browser ExtensionsUnvetted AI plugins processing company data.Click to learn more →Click to collapse ↑
AI-powered browser extensions for writing, summarising, and translating silently process everything on screen, including confidential emails, financial data, and HR records.
05AI-Powered AnalyticsShadow data pipelines feeding external AI models.Click to learn more →Click to collapse ↑
Business analysts upload datasets to AI analytics platforms without governance. Customer PII, financial records, and strategic data end up in third-party training sets.
06AI Image & Content GenerationMarketing teams using unapproved generative AI.Click to learn more →Click to collapse ↑
Teams generate content using Midjourney, DALL·E, or other tools, risking copyright infringement, brand inconsistency, and inadvertent disclosure of unreleased product details.
Interactive Guide
Is Your Organisation At Risk?
Answer these questions to assess your Shadow AI exposure.
The Impact is Real
Unapproved AI use can create data, compliance, security and intellectual-property risks. These are risk scenarios, not measured incident rates.
Data Leakage
Sensitive information submitted to an unapproved service may leave the organisation's intended controls.
Compliance Violations
Unapproved processing can bypass the organisation's privacy, contractual and approval checks.
Security Breaches
Unreviewed AI integrations can introduce permissions, credentials and data paths that security teams have not assessed.
IP Exposure
Proprietary code or confidential documents may be disclosed to an external provider.
How to Address Shadow AI
A comprehensive approach to turning Shadow AI from a risk into a governed advantage.
- STEP 1
Discover
Discover AI use on endpoints where Aona's browser plugin or native app is deployed. Review coverage for the clients and input paths your teams use.
- STEP 2
Assess
Use tool inventory and data-risk information to prioritise review. Your team determines applicable obligations and whether additional controls are needed.
- STEP 3
Govern
Configure approve, restrict or block policies for supported AI tools and data-protection controls for supported interactions.
- STEP 4
Monitor
Review recorded usage and policy events in Aona's dashboard. Available evidence depends on endpoint coverage, supported paths and configured retention.
Aona supports these steps with covered-endpoint visibility, configured policies and sensitive-data protection.
See how Aona discovers Shadow AI in your org
See how Aona can surface employee AI use on covered endpoints and apply controls to supported interactions.