# What is Shadow AI?

> Shadow AI is an industry governance term for AI systems, services or features used, connected, developed or deployed without the visibility or approval required by an organization.

- Canonical URL: https://yellowcube.eu/glossary/shadow-ai/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It can include employees using public generative-AI accounts, teams calling unreviewed model APIs, locally run models, unofficial agents and AI capabilities introduced through an update to an otherwise approved software service. The activity is not necessarily malicious; the defining problem is that normal risk ownership and control processes are bypassed or absent.

Without an accurate inventory, an organization may not know what information is sent to a provider, which retention terms apply, what identities or tools an agent can use, or whether outputs influence important decisions. A practical response combines discovery with sanctioned alternatives, clear data-handling rules, education, accessible review and exception paths, and proportionate controls.

### Key points

- **Discovery scope:** Look beyond well-known chat websites to browser extensions, developer tools, SaaS features, API traffic, cloud resources, notebooks, model repositories, local runtimes, agents and automation platforms.
- **Triage questions:** Identify the owner, purpose, users, provider, data classes, model and region, connected systems, permissions, retention, contractual terms and whether output drives consequential action.
- **Risk reduction:** Offer approved services, apply identity and least-privilege controls, enforce data-loss protections where appropriate, monitor use, train staff and make legitimate adoption easier to register.
- **Important limitation:** Domain blocking, network monitoring, expense records and staff surveys each reveal only part of the picture; embedded, local and indirect AI use can remain invisible. An indiscriminate ban can also push useful activity further outside governance.

### Related terms

[Shadow IT](<https://yellowcube.eu/glossary/shadow-it/>) · [AI governance](<https://yellowcube.eu/glossary/ai-governance/>) · [AI security posture management (AI-SPM)](<https://yellowcube.eu/glossary/ai-security-posture-management/>) · [Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/>) · [Operational technology (OT) asset inventory](<https://yellowcube.eu/glossary/operational-technology-asset-inventory/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>)

### Sources

[NIST AI Risk Management Framework 1.0](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10) · [CISA and UK NCSC Guidelines for Secure AI System Development](https://www.cisa.gov/news-events/alerts/2023/11/26/cisa-and-uk-ncsc-unveil-joint-guidelines-secure-ai-system-development) · [NIST AI RMF Playbook: Govern](https://airc.nist.gov/airmf-resources/playbook/govern/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

