30 Days Gen AI Risk Trial -Start Now
Skip to main content

Interactive Guide

What is
Shadow AI?

Shadow AI is the use of AI tools by employees without the organisation's approval or oversight.

Explore the Risks

The Hidden Problem

Published surveys show why organisations should investigate unapproved AI use.

of global knowledge workers surveyed used AI at work, Microsoft and LinkedIn, 2024Microsoft + LinkedIn
75%
of workers surveyed said their company had clearly articulated policies for approved AI tools and use cases, Salesforce, 2023 surveySalesforce
21%
of workplace generative-AI users surveyed had used unapproved tools, Salesforce, 2023Salesforce
55%
of 200 US enterprise IT directors and executives surveyed were concerned about Shadow AI privacy and security risks, Komprise, 2025Komprise
90%

Separate surveys, not a comparable dataset. Each figure has its own population and date. Salesforce's 2024 summary reports its 2023 survey; Komprise surveyed US organisations with 1,000+ employees.

Shadow AI in the Wild

Click any card to see how these common scenarios put your organisation at risk.

01ChatGPT for Code & DocsDevelopers pasting proprietary code into public AI assistants.Click to learn more →Click to collapse ↑

Employees copy sensitive source code, internal documentation, and customer data into ChatGPT or similar tools, bypassing security controls and potentially exposing trade secrets.

02Personal AI AssistantsStaff using personal AI accounts for work tasks.Click to learn more →Click to collapse ↑

Employees use personal subscriptions to Claude, Gemini, or Copilot for work-related tasks. Company data flows through unmonitored, ungoverned channels with no audit trail.

03Unauthorised API IntegrationsTeams connecting AI APIs without IT approval.Click to learn more →Click to collapse ↑

Engineering and product teams integrate AI APIs directly into workflows, sometimes hardcoding API keys and sending production data to third-party models without security review.

04AI Browser ExtensionsUnvetted AI plugins processing company data.Click to learn more →Click to collapse ↑

AI-powered browser extensions for writing, summarising, and translating silently process everything on screen, including confidential emails, financial data, and HR records.

05AI-Powered AnalyticsShadow data pipelines feeding external AI models.Click to learn more →Click to collapse ↑

Business analysts upload datasets to AI analytics platforms without governance. Customer PII, financial records, and strategic data end up in third-party training sets.

06AI Image & Content GenerationMarketing teams using unapproved generative AI.Click to learn more →Click to collapse ↑

Teams generate content using Midjourney, DALL·E, or other tools, risking copyright infringement, brand inconsistency, and inadvertent disclosure of unreleased product details.

Interactive Guide

Is Your Organisation At Risk?

Answer these questions to assess your Shadow AI exposure.

Do employees use AI tools that haven't been approved by IT?
Is there no formal AI usage policy in your organisation?
Can employees access public AI tools on work devices without restrictions?
Are there departments using AI APIs without security review?
Do you lack visibility into which AI tools are being used and by whom?
Has your organisation experienced data being shared with external AI services?

The Impact is Real

Unapproved AI use can create data, compliance, security and intellectual-property risks. These are risk scenarios, not measured incident rates.

  1. Data Leakage

    Sensitive information submitted to an unapproved service may leave the organisation's intended controls.

  2. Compliance Violations

    Unapproved processing can bypass the organisation's privacy, contractual and approval checks.

  3. Security Breaches

    Unreviewed AI integrations can introduce permissions, credentials and data paths that security teams have not assessed.

  4. IP Exposure

    Proprietary code or confidential documents may be disclosed to an external provider.

How to Address Shadow AI

A comprehensive approach to turning Shadow AI from a risk into a governed advantage.

  1. STEP 1

    Discover

    Discover AI use on endpoints where Aona's browser plugin or native app is deployed. Review coverage for the clients and input paths your teams use.

  2. STEP 2

    Assess

    Use tool inventory and data-risk information to prioritise review. Your team determines applicable obligations and whether additional controls are needed.

  3. STEP 3

    Govern

    Configure approve, restrict or block policies for supported AI tools and data-protection controls for supported interactions.

  4. STEP 4

    Monitor

    Review recorded usage and policy events in Aona's dashboard. Available evidence depends on endpoint coverage, supported paths and configured retention.

Aona supports these steps with covered-endpoint visibility, configured policies and sensitive-data protection.

See it for yourself

See how Aona discovers Shadow AI in your org

See how Aona can surface employee AI use on covered endpoints and apply controls to supported interactions.