Shadow AI — What New CISOs Need to Do Before It Bites Them
Picture a business analyst who wants to help her team move faster. She has thousands of customer support tickets to review, and a summary that would normally take three days sitting in front of her. So she opens a free AI tool, pastes in the data, and gets exactly what she needs in twenty minutes. She sends it off with a note to her manager: "Used Claude to summarize all the customer complaint data. Saved me three hours!" She is thrilled with herself. And she should be. She found a way to do more in less time.
What she did not know was that sitting inside that AI summary was a condensed version of thousands of customer records, support tickets, and PII that had just been sent to an external large language model through a free consumer account. No data processing agreement. No approved vendor. No logging. No way to know what had been retained on the other side.
This is a scenario I have watched play out at multiple organizations. And if you are a new CISO, I can almost guarantee it is happening in your organization right now. You just might not know it yet.
Shadow AI Is the New Shadow IT, and It Moves Faster
We have been talking about Shadow IT for two decades. Employees spinning up personal Dropbox accounts, using Gmail for work docs, running their own SaaS tools without IT approval. Most organizations eventually got their arms around it, at least enough to reduce the blast radius when something went wrong.
Shadow AI is a different animal. The tools are free or nearly free. They are embedded in browsers, in productivity suites, in coding environments. They work invisibly. And they are genuinely useful. That is what makes them so dangerous from a governance standpoint. People are not being reckless; they are being efficient. The business analyst who processed customer data thought she was doing the right thing for the team.
The speed of adoption is the problem. Shadow IT took years to reach critical mass inside most organizations. Shadow AI is already there. According to multiple enterprise surveys in the past year, somewhere between 60 and 75 percent of employees are using AI tools at work, many of which have never been reviewed, approved, or even acknowledged by security or IT. That number is almost certainly higher in knowledge-worker-heavy organizations.
As a new CISO, you do not have the luxury of getting comfortable before this hits you. You need a plan on day one.
What's Actually at Risk When Employees Use Unsanctioned AI
Let me be concrete about what Shadow AI exposure looks like in practice, because it is easy to wave at it generally and not actually address the specific risks.
Data exfiltration through prompts. When an employee pastes a sales contract, a financial model, or a patient record into an AI tool to get a summary or rewrite, that data may be sent to a third-party model provider, stored in training logs, or retained by the vendor under terms the employee never read. Your DLP tools almost certainly are not watching for this. Most are tuned for email and USB drives, not AI prompt submissions.
Intellectual property leakage. Source code, product roadmaps, go-to-market strategies. Your engineers and product teams are feeding this into AI tools every day. Some of those tools are free consumer versions with no enterprise data protection guarantees. You may be losing trade secrets without a single security alert firing.
Regulatory and compliance exposure. If you are in healthcare, finance, or any other regulated vertical, your employees sending protected data to an unapproved AI vendor may be creating HIPAA, GDPR, or PCI violations without realizing it. Regulators are actively developing guidance on AI data handling, and "we did not know" will not be a defense for long.
AI-generated outputs used as fact. This one does not get enough attention. Employees are using AI tools to draft reports, summarize research, and make recommendations. When those outputs contain hallucinations or biased results and get acted on, the downstream consequences fall on your organization. Legal, financial, reputational. All of it.
Third-party model risk you cannot see. Your approved vendor list is your control surface. Shadow AI blows a hole right through it. When your employees are using tools you have never vetted, you have no visibility into where those models run, what data they retain, whether they have been trained on appropriately sourced data, or what their incident response posture looks like.
How to Find Out What's Already Happening in Your Organization
Before you can govern something, you have to see it. Here is how to start building visibility without creating a culture of paranoia or burning political capital on day one.
Start with your network and proxy logs. Most AI tools hit recognizable domains: api.openai.com, claude.ai, gemini.google.com, copilot.microsoft.com, and dozens of others. Pull a week of outbound traffic and filter for known AI endpoints. What you find will surprise you. Organizations that think they have "a few people using ChatGPT" often have hundreds of daily active users hitting multiple AI services.
Run a quick anonymous employee survey. Frame it as understanding how people are doing their work, not catching anyone. You want people to tell you the truth. Ask which tools they use regularly, which ones they use for work tasks, and whether they have ever entered any kind of business or customer data. The candor you get from an anonymous survey will outpace what you would get from any technical scan.
Talk to your most productive departments. Shadow AI concentrates in your highest-output teams: sales, engineering, finance, marketing, legal. The people who have found AI genuinely useful are often the ones using it most freely. Have a few conversations. Listen without judgment. You will get a clearer picture of the real use cases than you will get from logs alone.
Check your SaaS portfolio for embedded AI. Tools you already pay for, such as Microsoft 365, Salesforce, Slack, and Google Workspace, have been adding AI capabilities at a rapid pace. Some of those are covered under your existing agreements. Many are not. Pull the release notes from your major SaaS vendors over the past 12 months and audit what AI capabilities have been added and whether they are within scope of your data agreements.
Building an AI Use Policy That People Will Actually Follow
Here is the trap most new CISOs fall into: they respond to the Shadow AI problem with a blanket prohibition. "No AI tools without explicit approval." Full stop.
I understand the instinct. It is clean, it is defensible, and it eliminates ambiguity. But it does not work. Employees who are already getting real productivity value from these tools will route around a blanket ban. They will use their personal devices. They will work from home without VPN. You will push the behavior underground, lose whatever visibility you had, and still have all the risk.
The policy you need is one that channels behavior rather than blocks it. Establish clear data classification rules for AI use. Define what data is and is not appropriate to use with AI tools, and communicate it in plain language. A tiered model works well: public information and internal non-sensitive data can go into approved AI tools; anything customer-facing, regulated, or confidential stays off those platforms until you have appropriate vendor agreements in place.
Build an approved AI tools list and make it easy to use. One of the reasons people reach for unapproved tools is that the approved path is too slow or too painful. If your procurement and security review process takes four months, employees are not going to wait. Streamline the review process for AI tools, create a fast-track path for low-risk use cases, and actively communicate what is approved and why.
Make the policy about data, not about tools. "Don't use ChatGPT" is easy to route around. "Don't enter customer PII into any AI tool that is not on our approved list" is about a specific behavior with a specific risk. People understand the why. They are more likely to comply. They are also more likely to flag a concern when they are unsure.
The Technical Controls That Actually Move the Needle
Policy is essential, but controls are what catch the cases where policy fails.
Update your DLP rules for AI destinations. If your Data Loss Prevention tooling is not monitoring for data being sent to AI endpoints, fix that now. Add the major consumer AI domains to your DLP watchlist. Flag uploads and large text submissions to those domains. You do not necessarily need to block everything, but you need to know what is happening.
Implement browser-level controls for unmanaged AI access. For corporate managed devices, browser extensions and endpoint management tools can restrict access to unapproved AI services. This is especially useful for preventing consumer versions of tools that have enterprise-grade alternatives you have already approved. If you have paid for Microsoft Copilot, there is no reason employees need to be using the free ChatGPT tier with no data protections.
Build AI into your vendor risk management program. Every AI tool that touches any company data needs to go through your VRM process. That means understanding where data goes, what is retained, whether the vendor has signed a DPA, and what their security posture looks like. Create an AI-specific addendum to your standard vendor questionnaire that covers model training data, output logging, and incident response procedures.
Get logging on your approved AI tools. For AI tools you have sanctioned, make sure you have usage logs that you can query: who is using what, when, what types of prompts, what data classifications are involved. This is not surveillance. It is the same audit trail you would want for any other business-critical application.
Getting the Organization Behind You: From Employees to the Board
Shadow AI is not just a security problem you can solve from the security team. It is a business behavior problem that requires buy-in at every level of the organization.
With the board, frame Shadow AI as business risk, not technology risk. Directors respond to liability, regulatory exposure, and reputational damage, not to technical explanations about prompt injection or data retention policies. Tell them that employees are actively using AI tools the company has not vetted, that this creates potential regulatory and IP exposure, and that you have a plan to get it under control. Quantify what you can. Make it concrete.
With the executive team, position yourself as an enabler. Your CEO and business unit leaders want AI productivity gains. That is the whole conversation in most boardrooms right now. If you walk in as the person trying to slow AI adoption down, you will lose. Walk in as the person who is going to help the business adopt AI safely and at scale. Propose an approved AI program that gives the organization more of what it wants while reducing the risk. Be the yes. Just a structured yes.
With employees, lead with empathy. Most of the people using Shadow AI tools are not trying to create security problems. They are trying to do their jobs better. Acknowledge that. Make the approved path genuinely easier than the unapproved one. Train people on the specific risks using real stories, not abstract warnings. Real examples land.
With HR and Legal, make them partners from the start. Shadow AI policy enforcement is a lot harder without HR alignment. Cases that require discipline need HR involved early. Legal needs to be part of developing your policy so it is defensible. Do not treat this as a security program in isolation. Build the coalition.
Key Points
- Shadow AI is already present in your organization. The question is not whether it is happening. It is whether you have visibility into it.
- The real risks are data exfiltration through prompts, IP leakage, regulatory exposure, and third-party model risk you cannot audit.
- Blanket bans do not work. Build policy that channels behavior toward approved tools rather than prohibiting AI outright.
- Update your DLP and vendor risk management programs specifically for AI. Your existing controls almost certainly have blind spots here.
- Getting organizational support requires different framing for different audiences: business risk for the board, enablement for the business, empathy and clarity for employees.
Pro Tips
- Run a Shadow AI discovery sprint before you build your policy. Two weeks of network log review and a few candid employee conversations will tell you more than a year of theoretical risk modeling.
- Partner with your most AI-enthusiastic business leaders first. Find the VP of Engineering or Sales leader who is already pushing AI adoption hard. Make them your champion for the approved AI program, not your adversary.
- Negotiate enterprise data agreements proactively. For any AI tool gaining real traction, get ahead of the vendor conversation. Negotiate zero-retention agreements, data processing addenda, and audit rights before the tool becomes too embedded to move off of.
- Treat AI hallucination risk as a business process risk. Work with department heads to identify where AI-generated outputs are being used in decisions and build human review checkpoints into those workflows.
- Create a safe reporting channel for AI-related incidents. Build a non-punitive path for employees to flag mistakes. You want to know about problems before they become breaches.
Pitfalls to Avoid
- Do not conflate approved AI tools with safe AI tools. Approval is the beginning of the work, not the end. Every approved tool still requires proper configuration, data classification alignment, and usage governance.
- Do not build your AI policy in a vacuum. If Legal, HR, and the business are not in the room when you write it, you will write something they will undermine the moment they see it.
- Do not ignore AI embedded in tools you already use. The biggest Shadow AI risk for most organizations is not employees signing up for ChatGPT. It is the AI capabilities baked into your existing SaaS stack that nobody noticed getting turned on.
- Do not make the approved AI process harder than using a consumer tool. If getting a tool approved takes four months and seven signatures, you have already lost.
- Do not let this become a one-time project. The AI tool landscape changes faster than almost any other technology sector. Build an ongoing review cadence into your program from day one.
Final Thought
Shadow AI is not a problem you are going to eliminate. The tools are too useful, too accessible, and too embedded in how people work now. Your job is not to stop it. It is to shape it. The CISOs who handle this well will be the ones who lean into AI adoption rather than against it. They will build programs that give employees more of what they are already reaching for, with guardrails that protect the organization without killing productivity. You have a window right now. Most organizations are still in the early, messy phase of AI adoption where behaviors have not fully calcified. Get your visibility, build your policy, and get your controls in place before the problem outgrows your ability to manage it. Because it will outgrow you fast if you wait.
If this gave you something useful, subscribe to InfoSec Made Easy for more straight-talk on what it actually takes to lead in security today. Share it with a peer who just stepped into a CISO role. They need this conversation now, not six months from now. And drop a comment below: what is your biggest Shadow AI challenge right now? I read every one.
Comments ()