AI is already delivering meaningful gains across organisations. Teams summarise faster, research better, draft content in minutes, and accelerate analysis that used to take hours. In the right hands, AI genuinely expands what a small team can achieve.
The problem is that AI adoption rarely happens only through approved channels. Shadow AI, the unregulated and unauthorised use of AI tools inside an organisation, has become one of the biggest risks associated with modern AI adoption. In most cases it is not malicious, it is simply invisible – and that is what makes it dangerous.
Microsoft and LinkedIn’s 2024 Work Trend Index found that 75% of knowledge workers use AI at work, and 78% of AI users bring their own AI tools to work. That behaviour is even more common in small and medium-sized companies.
What Shadow AI Looks Like in Real Environments
Shadow AI is not a single tool. It is a set of behaviours that bypass the organisation’s controls.
Common examples include:
- An employee pastes a customer email thread into a public chatbot to draft a reply.
- A manager uploads a contract or pricing sheet to get a quick summary.
- A developer uses a personal AI coding assistant account to debug a production issue and shares a snippet that includes secrets or internal endpoints.
- A team installs an AI browser extension that can read what is on-screen, what is typed, or what is copied.
- A staff member uses a consumer AI transcription service for internal meetings because it is quicker than approved tooling.
These actions often happen through unmanaged browser sessions, personal accounts and non-corporate AI tools, which means they sit outside SSO, audit logging, DLP, retention controls, and incident response playbooks.
The Core Technical Risk: Uncontrolled Data Egress
Shadow AI turns ordinary work into untracked data movement. The risk is not limited to “training data”. The immediate problem is that sensitive information can leave your control without any contractual safeguards, without consent, and without your security team even knowing it happened.
Cyberhaven’s research analysing 1.6 million workers found that 8.6% of employees had pasted company data into ChatGPT, and 11% of the data pasted was classified as confidential. They also reported that 4.7% of employees pasted sensitive data such as source code, client information, or strategic documents.
When that includes personal data, it is not just a security incident. It becomes a governance, contractual, and potentially a regulatory issue.
Real-World Incidents: When “Quick Help” Becomes a Leak
A widely cited example came from Samsung in 2023, where engineers reportedly uploaded sensitive information including source code to ChatGPT while seeking help with debugging. It isn’t clear what level of severity this leak represented, but notwithstanding, Samsung responded by restricting and then banning certain generative AI tools internally. In light of the incident, Amazon discovered a similar leak of proprietary code being uploaded to OpenAI, prompting another urgent round of warnings to staff using ChatGPT. JP Morgan lead the charge in US banking following their own leak scare, followed quickly by the other major banks.
The details matter here because the behaviour is normal in modern teams. Shadow AI turns these normal workflows into accidental exfiltration.
See also: Guarding High-Value IP in the Age of AI
Shadow AI Expands the Attack Surface in Specific Ways
Shadow AI is often discussed as a policy problem, but the technical surface area is concrete and measurable. The main risk categories below are the ones we see repeatedly across organisations.
1. Sensitive data disclosure through prompts and uploads
Prompts are data. Uploads are data. Chat transcripts can become records that are retained longer than the user assumes, copied into other tools, or accessed by accounts you do not manage.
This is especially risky for:
- Client, patient, or employee data
- Financial data, pricing, or deal terms
- Intellectual property and unpublished work
- Credentials, API keys, tokens, and internal URLs
- Regulated content and audit material
2. Prompt injection and insecure output handling
Even when you use AI in internal workflows, attacker-controlled text can manipulate AI behaviour. This is now well documented in the OWASP Top 10 for LLM Applications, which lists prompt injection and insecure output handling as leading risks.
A practical example: a support team pastes an email into an AI tool to summarise it, but the email contains hidden instructions that influence the AI output, which then leads the user to take an unsafe action, share sensitive data, or run untrusted steps.
3. Browser extensions and embedded copilots
Consumer AI extensions can read page content and clipboard data, and some integrate with web apps in ways that bypass normal inspection and logging. If the organisation has not approved the tool, security teams often have no reliable view of what it collects.
4. Code assistants and secret leakage
Developer workflows are a high-risk path because code is dense with secrets, internal endpoints, error traces, and configuration detail. A single pasted stack trace can include enough information for an attacker to escalate access if it is later exposed or reused elsewhere.
This risk is increasingly visible at scale. Cisco’s 2025 Cybersecurity Readiness Index highlights that many organisations lack confidence in identifying unapproved AI tools, with smaller businesses struggling the most.
Why Shadow AI is So Common
Shadow AI is not niche. Multiple surveys point to wide adoption.
- Microsoft reports that 78% of AI users bring their own AI tools to work.
- A Gartner survey of cybersecurity leaders (March to May 2025) found that 69% of organisations suspect or have evidence that employees are using prohibited public GenAI.
- WalkMe’s 2025 survey reported that 78% of employees say they use AI tools not provided by their employer.
This is happening because AI removes friction. When approved tools lag behind real workflows, staff route around them, especially under time pressure.
A Technical Approach to Reducing Shadow AI Risk
Blocking “AI” as a category rarely works because AI is embedded across tools and platforms, and staff can reach consumer services from personal devices. A better approach is to build controls around identity, data, and auditability.
1. Establish an approved AI stack that is usable
If the sanctioned tool is slow, limited, or hard to access, shadow usage will win. Provide an approved option that supports real tasks, with clear guidance on what is safe to input.
2. Control access through identity
Use SSO where possible, enforce MFA, and prevent use of personal accounts for business tasks. If your AI tools sit outside identity controls, you lose visibility and the ability to respond quickly when something goes wrong.
3. Apply DLP and data classification to AI pathways
Treat AI tools as another egress route, similar to email and file sharing. Extend DLP to cover clipboard, browser uploads, and SaaS interactions so sensitive data can be blocked or redacted before it leaves the organisation.
4. Create audit-ready logging
Log who used which AI tool, when, and from which device, then route that telemetry into your SIEM for correlation and alerting. Without this, you cannot investigate incidents properly.
5. Lock down unmanaged endpoints
Shadow AI grows fastest on unmanaged devices. Strong endpoint management reduces risk by enforcing configuration, restricting risky extensions, and controlling where sensitive data can be copied and uploaded.
A Dr Logic perspective
AI should be a competitive advantage, not a hidden liability. But if AI is already in use inside your business, the key question is simple: do you know where your data is going when people use it?
At Dr Logic, we help organisations adopt AI in a way that protects data, preserves trust, and stays supportable as usage scales. That means putting practical guardrails in place across identity, devices, and data flows, while still allowing teams to innovate quickly – in short, we specialise in securing AI adoption without slowing it down.
Whether you’re thinking of future AI workflows or concerned about the security of your existing setup, we’re here to guide the way – book a free consultation today.



















































