Shadow AI is now the third most common non-malicious insider action showing up in breach data, a fourfold jump in a single year, according to Verizon’s 2026 Data Breach Investigations Report. The same report found that 45% of employees are now regular AI users on corporate devices, up from just 15% the year before, and two-thirds of them are logging in through personal accounts their employer cannot see.
That gap between sanctioned AI programs and actual employee behavior is not shrinking on its own. Most compliance teams still discover shadow AI the hard way: an audit finding, a DLP alert, or a vendor questionnaire nobody can answer honestly. This piece walks through what shadow AI actually looks like inside a company, how to find it before an auditor does, and what ISO 42001, the EU AI Act, and NIST AI RMF each expect once you do.
What Shadow AI Actually Is (and Why “Just Block It” Fails)
Shadow AI is any AI tool, model, agent, or workflow an employee uses without going through your organization’s approval, security review, or governance process. That definition covers more ground than most people assume. It is not only an engineer pasting proprietary code into a free chatbot. It is the AI summarization feature quietly enabled inside an already-approved SaaS product, the browser extension a marketing analyst installed to speed up research, and the internal prototype a data science team spun up on a personal cloud account before anyone in compliance knew it existed.
The instinct to solve this with a ban is understandable and usually backfires. When there is no sanctioned option, employees do not stop using AI. They stop telling anyone about it. Security teams then lose the one thing they actually need: visibility. Elementum’s CIO guidance on shadow AI governance puts it bluntly: broad bans reduce visibility more than usage, and employees with no sanctioned option keep using consumer tools while disclosing less than before the ban existed.
This matters because shadow AI is not really a technology problem. It is a gap between how fast employees need to work and how fast your governance program can approve a new tool. Close that gap, and disclosure improves. Widen it with policy alone, and shadow AI just gets quieter.
Why Shadow AI Is Growing Faster Than Governance Programs Can Track
The scale of the shift shows up clearly in the data. The 2026 DBIR analyzed 858,440 DLP events tied to uploads into generative AI tools and found that source code was the single most common data type submitted, ahead of images and structured data by a wide margin. Verizon’s own commentary was unusually direct about what that means: potential intellectual property is walking out the door, not just personal data.
A separate BlackFog workforce survey, reported by Forbes in April 2026, found that 49% of workers are using AI in ways their employer has not approved, and 58% of them are doing it through free-tier tools with no enterprise data governance controls at all. Sixty percent said they would knowingly take the risk with an unapproved tool if it meant hitting a deadline.
The consequences are not hypothetical. Freshworks research cited in the same coverage found that 86% of IT leaders reported at least one negative incident tied to unapproved AI use in the past year, and nearly a quarter had experienced more than three. Meanwhile, ISACA’s 2026 research found that only 33% of organizations extend AI training to every employee, and 39% of professionals do not know whether their organization even has a documented process for shutting down an AI system mid-incident.
Put those numbers together and the pattern is straightforward. Adoption is outrunning oversight in almost every organization, not because employees are careless, but because governance programs were built for a slower pace of tool adoption than AI actually moves at.
The Real Risk: What Happens When Shadow AI Touches Regulated Data or High-Risk Use Cases
Not all shadow AI carries the same exposure. An employee using an unapproved AI tool to reformat a public press release is a policy violation. An employee using the same tool to summarize a candidate’s resume for a hiring decision, or to draft language explaining a loan denial, is something else entirely: an ungoverned high-risk use case operating with zero documentation, zero risk assessment, and zero human oversight record.
This is the distinction most shadow AI coverage skips. Discovery tools built for security teams flag every unsanctioned domain equally. But under the EU AI Act, an AI system used in employment decisions or creditworthiness assessment falls into an Annex III high-risk category regardless of whether procurement approved it. The obligations attach to the use case, not to whether the tool went through a purchase order.
The Samsung engineering team’s 2023 incident, where source code was pasted into a public chatbot, is the example everyone remembers because it was public and easy to explain. The less visible version happens weekly inside HR, legal, and finance functions: a recruiter drafting rejection language, a paralegal summarizing a contract, a finance analyst building a forecast, all in tools nobody classified. None of those look like a breach on a security dashboard, which is exactly why they get missed.
How ISO 42001, the EU AI Act and NIST AI RMF Each Treat Undocumented AI Use
Most shadow AI guidance stops at detection. It tells you to find the tools and block or approve them. What it rarely does is connect discovery to the specific clause-level obligations that make discovery necessary in the first place across the three frameworks GRC teams actually get audited against. The table below maps that ground directly.
Read this less as three separate checklists and more as one requirement stated three ways. Every framework starts from the same premise: you cannot govern, assess, or report on a system your organization does not know exists. ISO 42001 calls this scope definition. NIST AI RMF calls it mapping. The EU AI Act simply assumes it as a precondition for classification. A single AI system inventory, built to capture all three sets of requirements at once, satisfies the intent behind each.
How ISO 42001, the EU AI Act and NIST AI RMF each address undocumented AI use
| Governance requirement | ISO/IEC 42001:2023 | EU AI Act (Reg. 2024/1689) | NIST AI RMF 1.0 |
|---|---|---|---|
| AI system inventory | Clause 4.4 (AIMS scope) and Clause 8.1 (operational planning) require identifying AI systems the organization develops, procures, or uses | No explicit inventory article, but Annex III risk classification is impossible without first knowing which systems exist | GOVERN 1.1 and MAP 1.1 call for cataloguing AI systems and their context before risk can be mapped |
| Third-party / vendor AI | Annex A.5 (organizational controls) addresses supplier and third-party AI relationships | Article 25 addresses obligations across the AI value chain, including deployers using third-party systems | GOVERN 6.1 addresses third-party risks including AI supply chains |
| Employee AI use awareness | Annex A.6.2 addresses competence and awareness of personnel using AI systems | Article 4 requires AI literacy for staff dealing with AI systems, effective since February 2025 | GOVERN 2.2 calls for training staff to understand AI risks relevant to their roles |
| Undocumented high-risk use | Clause 6.1 requires risk assessment before deployment; undocumented systems bypass this by definition | Annex III high-risk systems (in scope from December 2, 2027 per the Digital Omnibus timeline) require conformity assessment employees cannot self-certify | MAP 1.5 and MEASURE 2.1 require risk characterization that cannot happen for unknown systems |
| Corrective action / monitoring | Clause 9.1 (monitoring and measurement) and Clause 10 (improvement) require ongoing detection of nonconformities | Article 26 requires deployers to monitor operation and report serious incidents | MANAGE 2.3 and MANAGE 4.1 call for ongoing monitoring and response to emerging AI risks |
A Practical Discovery Process: Finding Shadow AI Before an Auditor Does
Discovery works best as two parallel tracks running at the same time, not a single method run once. Technical discovery pulls from DLP, CASB, and network logs to identify traffic to known generative AI domains and unauthorized browser extensions. The 2026 DBIR found that more than 15% of corporate users have unauthorized AI browser extensions installed, extensions that often collect the context of every page visited, which Verizon’s data describes as functionally equivalent to an infostealer installed with the user’s own consent.
Human discovery runs alongside it: direct, low-friction surveys of department heads and team leads. This is not redundant with log analysis. Self-reported use routinely surfaces tools that never cross a corporate network at all, personal-device use of consumer AI apps for work tasks being the most common example. Neither method alone gives you a complete picture, and organizations that rely only on logs consistently undercount shadow AI in professional services, legal, and HR functions where personal devices see more work traffic than corporate ones.
Once a tool surfaces, resist the urge to sort it immediately into approved or banned. Classify first, by two variables: the sensitivity of data it touches and whether the use case resembles a regulated or high-risk category. A tool used for internal brainstorming with no sensitive data is a very different conversation than the same tool used to process applicant records.
Finding an unapproved AI tool is only the beginning. If it comes through an external vendor, you also need to understand the model behind it, where data goes, and what changes after deployment. Read our guide on third-party AI risk management for vendor AI systems to understand what that review should cover.
From Discovery to Inventory: Turning Found Tools Into a Governed AI Register
Discovery that does not feed an inventory is a one-time report that goes stale within a quarter. The tools you find need to land in the same AI system inventory that tracks your sanctioned systems, with an accountable owner assigned before anyone decides whether to approve, restrict, or retire it. Unowned entries are the single most common reason AI inventories decay after the first audit cycle.
This is where the difference between a spreadsheet and a governance-grade registry starts to matter. A spreadsheet works for the first version. It stops working the moment an auditor asks for version history, or when three teams have three different copies with conflicting risk ratings.
Govern365.ai‘s AI model registry automatically maps each discovered system to its applicable ISO 42001 controls and EU AI Act risk category as it is added, so a tool found through a shadow AI sweep enters the inventory already classified rather than sitting in a queue waiting for manual review.
The registry does not replace judgment. It removes the lag between finding a tool and understanding what it means for your compliance posture, which is usually where governance programs lose momentum after a discovery exercise.
Shadow AI discovery-to-governance checklist
- Pull DLP and CASB logs for known generative AI domains and browser extensions over the last 90 days [NIST AI RMF – MAP 1.1]
- Survey department heads directly; self-reported use consistently surfaces tools that technical scans miss [ISO 42001 – Clause 8.1]
- Classify every discovered tool by data sensitivity and use case, not just by vendor name [NIST AI RMF – MAP 1.5]
- Flag any discovered use case that resembles an EU AI Act Annex III category for expedited review [EU AI Act – Annex III]
- Add every confirmed tool to a single AI system inventory or model registry, sanctioned or not yet decided [ISO 42001 – Clause 4.4]
- Assign an accountable owner to each inventory entry before deciding to approve, restrict, or replace it [ISO 42001 – Annex A.5]
- Publish a fast-track approval path for low-risk tools so discovery does not just restart the cycle [NIST AI RMF – GOVERN 1.1]
- Deliver AI literacy training tied to the specific tools and risks found in your organization, not generic content [EU AI Act – Article 4]
- Re-run discovery on a fixed cadence (quarterly at minimum) and track the trend in unsanctioned findings [ISO 42001 – Clause 9.1]
- Report the shadow AI trend line, not just a point-in-time count, to the board or audit committee [NIST AI RMF – MANAGE 4.1]
Building a Policy That Reduces Shadow AI Instead of Driving It Further Underground
A policy that only lists prohibited tools has a short shelf life; new tools launch faster than any list can track. A policy built around approval speed and clear criteria ages much better. Employees do not generally want to violate policy. They want to finish work, and shadow AI is what happens when the approved path is slower than the unapproved one.
The organizations narrowing their shadow AI gap fastest share one structural choice: a fast-track review lane for low-risk tools, separate from the full risk assessment reserved for anything touching regulated data or a high-risk use case. That two-speed approach lets a governance team spend real scrutiny where it matters instead of applying the same weeks-long review to a grammar tool and a hiring algorithm alike.
Psychological safety plays a larger role here than most policies acknowledge. A 2026 Harvard Business Review study cited by Adaptive Security’s research on shadow AI adoption found that employees in low psychological safety environments hid AI use at a rate of 45%, compared to 17% in high psychological safety environments. Governance imposed without trust reads as surveillance, and surveillance produces silence, not compliance.
Metrics and Board Reporting: Proving the Shadow AI Gap Is Closing
A single point-in-time count of discovered tools tells a board almost nothing useful on its own. What matters is the trend: is the ratio of inventoried-and-governed systems to newly discovered unsanctioned ones improving quarter over quarter? That trend line is the actual evidence an audit committee needs to see, and it is the same evidence ISO 42001 Clause 9.1 expects for ongoing monitoring.
Three numbers are worth tracking consistently: the count of AI systems discovered through each channel (technical versus self-reported), the median time between discovery and inventory entry, and the percentage of discovered tools that were sanctioned through the fast-track path versus the full review. A shrinking median time-to-inventory is often the clearest signal that a governance program is keeping pace with actual employee behavior, more so than a shrinking raw count of shadow AI findings, which can simply mean detection has gotten worse.
Frequently Asked Questions
What is shadow AI?
Shadow AI is any AI tool, model, agent, or workflow employees use without going through an organization’s approval, security review, or governance process. It includes free consumer chatbots, unauthorized browser extensions, unregistered internal experiments, and AI features embedded in other approved software that nobody reviewed separately. The defining trait is not the tool itself but the absence of oversight.
Is shadow AI the same as shadow IT?
It is a subset with sharper risk. Traditional shadow IT (an unapproved project management app, for example) mostly creates data sprawl. Shadow AI often involves employees actively feeding proprietary text, code, or records into a third-party model, which means the exposure happens the moment the tool is used, not after a breach.
How common is shadow AI in 2026?
Verizon’s 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% the year before, and that shadow AI is the third most common non-malicious insider action in breach data. Separate workforce surveys place unapproved use as high as two-thirds of office professionals.
How do you detect shadow AI in an organization?
Combine technical and human methods. Pull DLP, CASB, and network logs for known AI domains and browser extension activity, then supplement with direct surveys of department heads, since self-reported use routinely surfaces tools log-based scans miss entirely. Neither method alone gives a complete picture.
Does the EU AI Act require companies to find shadow AI?
Not by that name, but it requires what shadow AI discovery makes possible. You cannot classify systems against Annex III risk categories, meet Article 4 AI literacy obligations, or fulfill Article 26 deployer monitoring duties for AI systems your organization does not know it is using.
What does ISO 42001 say about undocumented AI systems?
ISO/IEC 42001 Clause 4.4 requires organizations to define the scope of their AI management system, which depends on knowing which AI systems exist. Clause 8.1 extends this to operational control, and undocumented tools fall outside both by definition, creating an automatic conformity gap during audit.
Should companies just block all unapproved AI tools?
Blanket bans tend to reduce visibility rather than usage. When there is no sanctioned alternative, employees continue using consumer tools quietly and stop disclosing it, leaving security and compliance teams with less information than before the ban. A faster approval path for low-risk tools works better than prohibition alone.
How does shadow AI discovery connect to an AI system inventory?
Discovery is the input; the inventory is where it becomes governance. Every tool found through logs or surveys should be logged in the same AI system inventory used for sanctioned systems, with an owner assigned, so it can be classified, risk-assessed, and either approved, restricted, or retired on a documented basis.
Closing the Shadow AI Gap
Shadow AI is not a problem that gets solved once. It is a gap between adoption speed and governance speed that either narrows or widens every quarter, and the data from Verizon’s 2026 DBIR makes clear which direction most organizations are currently moving. Finding unapproved AI use matters less as a one-time sweep and more as a repeatable process feeding a single, owned inventory mapped against the frameworks your organization is actually audited on.
Start with one discovery pass this quarter, technical and human, and route everything you find into a single inventory before deciding what to do with it.
Govern365.ai, by the Global AI Certification Council, gives compliance and governance teams a model registry that maps discovered AI systems to ISO 42001, EU AI Act and NIST AI RMF requirements automatically. Start your 14-day free trial to see your own shadow AI gap mapped against all three frameworks at once.
