The Starting Point
The question is no longer whether shadow AI exists. The question is who owns it.
Shadow AI is what happens when AI adoption moves faster than the organization's operating model. The employee sees an urgent customer issue, a messy spreadsheet, a backlog of tickets, a legal draft, a code review, or a research task. The company sees risk. Both are right.
Microsoft and LinkedIn's 2024 Work Trend Index found that 75% of knowledge workers were using AI at work and that 78% of AI users were bringing their own AI tools to work.1McKinsey's 2025 global AI survey found that 88% of respondents reported regular AI use in at least one business function, while 23% were scaling AI agents and another 39% were experimenting with them.5
That level of adoption creates a different management problem. If AI work is invisible, nobody can evaluate the tool, understand the data exposure, measure the cost, preserve the useful workflow, or assign accountability. And the risk is already material: IBM's 2025 Cost of a Data Breach research reported that one in five organizations had a breach due to shadow AI and that high levels of shadow AI were associated with $670,000 higher average breach costs.2
The answer is not a blanket ban. Employees use shadow AI because there is work to be done. The answer is a discovery and attribution system that converts unknown AI into managed AI: known asset, known user, known owner, known workflow, known data context, known policy state, and known next step.
A list of tools is a starting point. The operating question is who owns the work and what decision is required.
Unknown usage often reveals missing approved tools, slow procurement, unclear policy, or a workflow worth scaling.
Policy, security, finance, procurement, and enablement can act only when the signal resolves to people and workflows.
Scope
Shadow AI is bigger than unapproved chatbots.
The earliest shadow AI programs focused on public GenAI applications. That is still important, but the surface has widened. Netskope's 2025 GenAI report found that 90% of organizations had users directly accessing GenAI apps and 98% had users accessing apps with GenAI-powered features.3 Shadow AI now hides inside the tools companies already use, not only in obvious AI destinations.
The category also includes agentic and infrastructure-level use. Netskope's 2025 Shadow AI and Agentic AI report describes users shifting toward GenAI platforms, on-premises AI infrastructure, and custom agents, creating new security challenges that may remain under the radar of security teams.4
| Shadow AI Object | What It Looks Like | Why It Matters |
|---|---|---|
| Personal AI accounts | Employees using consumer ChatGPT, Claude, Gemini, Perplexity, image tools, or research tools for work. | Data, prompts, files, and histories may sit outside enterprise controls and audit paths. |
| Embedded SaaS AI | AI features inside CRM, support, HR, finance, design, collaboration, analytics, or sales tools. | AI usage may bypass a central AI program because it appears as a feature of an already-approved app. |
| Model and API access | Unregistered API keys, direct completions, experimental models, local fine-tunes, or personal developer accounts. | Spend, data exposure, model risk, and output quality become hard to manage or reproduce. |
| Agents and MCP servers | Custom agents, self-hosted connectors, unofficial MCP servers, tool bundles, or scripts with autonomy. | Autonomous action expands risk from data exposure to system access, workflow impact, and downstream side effects. |
| Prompts and data sources | Copied prompts, unreviewed prompt variants, raw exports, local CSVs, scraped data, or unmanaged vector stores. | Useful workflow knowledge can spread without versioning, ownership, data classification, or review. |
Operating Model
The five-layer model for shadow AI discovery.
A discovery program should not end with “found.” Each signal needs to become an accountable record that can move through approval, remediation, migration, education, or scaling.
Signals
Asset type
Owner and work
Risk and value
Decision
This is where many shadow AI programs stall. They can detect a domain, a browser event, or a blocked prompt, but they cannot answer the questions that make the signal operational: who is doing the work, what workflow is it part of, what data is involved, whether the tool is duplicative, whether the usage should be blocked or approved, and who is accountable for the follow-up.
NIST's AI Risk Management Framework explicitly calls for mechanisms to inventory AI systems and for clearly documented roles and responsibilities in AI risk management.7 That is the practical bar for shadow AI: discovery has to create an inventory entry and an ownership path.
Shows that something happened, but not whether it was risky, useful, redundant, or owned.
Shows what was used and who used it, which allows outreach, review, and education.
Shows the business reason, data context, cost, risk, and next decision path.
Attribution
Ownership attribution is the difference between a dashboard and an operating system.
Customers care about ownership attribution because it answers the question every AI program eventually faces: who is responsible for this work? Not who clicked a tool once, but who owns the business process, data, budget, policy exception, and future state.
Ownership attribution should combine multiple signals. A user may trigger the usage, but the owner may be their manager, department, cost center, application team, model platform owner, data steward, workflow sponsor, procurement owner, or security approver. The best system makes that attribution visible and correctable rather than hiding behind a single log field.
Tool seen, no user or owner.
Identity or account is known.
Department and manager known.
Business process is known.
Owner, policy, and action set.
Signals that improve ownership attribution
- Identity: SSO, browser profile, endpoint user, API key owner, service account, or personal account correlation.
- Organization: department, manager, cost center, geography, team, project, procurement record, and budget owner.
- Workflow: app path, connected systems, prompt purpose, agent trigger, repository, ticket, CRM object, document, or output destination.
- Data context: data class, source system, customer data, PII, PHI, IP, secrets, financial data, or regulated content.
- Behavior: frequency, volume, recurrence, time of day, model/provider, autonomy level, connected tools, and cost pattern.
Discovery Surface
Look for shadow AI where work actually happens.
Network logs and procurement records are useful, but they are incomplete. Shadow AI often appears through a blend of browser use, expense reports, SaaS feature activation, repository changes, model API calls, uploaded files, embedded copilots, and custom agents.
Netskope reported tracking 317 distinct GenAI apps across its customer base and found that data sent to GenAI apps in prompts and uploads increased more than 30-fold over the prior year.3 The implication is simple: the discovery surface is moving, and the volume of data flowing through it is rising quickly.
Identity
SSO, OAuth grants, browser profiles, endpoint users, service accounts, personal accounts, and API key lineage.
Access
SaaS logs, extensions, model gateways, app events, MCP servers, tool calls, repositories, and data connectors.
Spend
Invoices, cards, expenses, cloud usage, token spend, SaaS add-ons, renewals, seats, and agent runtime.
Output
Generated documents, messages, code, tickets, customer replies, reports, automations, and downstream actions.
Risk Context
Classify shadow AI by data exposure, autonomy, and blast radius.
Not every shadow AI signal deserves the same response. A marketing user testing headline variations in a personal account is different from an agent with a personal GitHub token, a raw customer export, and the ability to write back to production systems.
IBM found that only 37% of organizations had policies to manage AI or detect shadow AI, and that shadow AI incidents involved more compromised PII and intellectual property than the global breach average.2Cisco's 2025 Cybersecurity Readiness Index reported that 86% of organizations experienced AI-related security incidents in the prior 12 months, while 60% did not know the specific requests employees make to GenAI tools.6
OWASP's LLM Top 10 adds a useful security frame for shadow AI programs: prompt injection, supply chain vulnerabilities, sensitive information disclosure, insecure plugin design, excessive agency, and model theft are all risk categories that become harder to manage when AI work is unregistered.8
Action
Route the right decision instead of treating every discovery as a violation.
The companies that win with AI will not be the ones that suppress all experimentation. They will be the ones that convert experimentation into governed, reusable, economically legible work. That means the response to shadow AI should be proportional and specific.
If a tool is safe and useful, approve it. If the demand is real but the tool is risky, migrate users to an approved alternative. If the workflow is valuable, turn it into a managed pattern. If the data exposure is unacceptable, block and remediate. If the same tool appears across teams, consolidate and negotiate. If the usage is harmless but untrained, coach the user and update guidance.
Unknown tool, model, agent, prompt, data source, or account
Likely owner, workflow, team, data context, and policy state
Approve, migrate, coach, restrict, remediate, or scale
Decision paths worth standardizing
- Approve: low-risk usage with clear owner, useful workflow, acceptable provider, and policy match.
- Migrate: real demand currently happening through a tool, model, or account the company should replace.
- Coach: user intent is acceptable, but prompt behavior, data handling, or tool choice needs guidance.
- Restrict: usage is not prohibited forever, but needs conditions, limits, review, or a safer pattern.
- Block: sensitive data, privileged action, regulatory exposure, or high autonomy creates immediate risk.
- Scale: shadow workflow is valuable enough to turn into an approved template, agent, or enablement pattern.
Program Design
Run shadow AI discovery as a weekly ownership loop.
A one-time scan ages out quickly. The AI surface changes when a vendor adds a feature, an employee tries a new app, an agent gets a new connector, a team copies a prompt, or a developer adds an API key. Discovery needs a cadence that keeps the map alive.
Catch new domains, tools, models, keys, MCP servers, sensitive data events, and ownerless activity.
Assign likely owners, confirm workflow context, dedupe repeated findings, and route decisions.
Migrate risky usage, consolidate duplicate tools, approve useful patterns, and close policy gaps.
Revise approved tools, training, procurement, model policy, data access, and adoption plans.
Failure Modes
Common mistakes in shadow AI discovery.
If employees believe discovery exists only to punish them, they will hide usage or move to harder-to-see channels.
A tool list does not explain workflow value, data exposure, cost, policy state, or accountable owner.
Many shadow AI risks now live inside SaaS tools and workflow platforms the organization already approved for other purposes.
Copied prompts and unmanaged data exports can carry the real risk even when the model provider is approved.
Some findings belong to procurement, finance, legal, data governance, enablement, engineering, or the business owner.
Shadow AI can reveal the workflows employees most urgently need help with. Useful demand should be captured, not buried.
Proxon Approach
Proxon turns shadow AI into an ownership queue.
Proxon is built around a simple operating idea: hidden AI work should become an accountable record. The platform discovers shadow tools, models, MCP servers, prompts, data sources, and agents, then attaches enough context for the right person to make the right decision.
Surface AI models, MCP servers, tools, data sources, prompts, SaaS features, personal accounts, and agents.
Normalize every finding into asset type, status, usage, calls, connected systems, data sensitivity, and policy state.
Attach likely owner, team, workflow, department, cost center, manager path, and business context.
Create alerts, approvals, remediation tasks, migration paths, policy updates, and reusable patterns.
| Shadow AI Question | Proxon Answer | Decision Unlocked |
|---|---|---|
| What shadow AI exists? | Inventory across models, MCP servers, tools, data sources, and prompts, with shadow flags and status. | Move from anecdote to an actual managed queue of assets. |
| Who owns this? | Owner attribution by user, team, department, manager path, workflow, and connected business system. | Send the finding to the person who can approve, fix, fund, or retire it. |
| What is the risk? | Risk reason, data sensitivity, policy state, calls, connected tools, privileged actions, and audit trail. | Separate low-risk experimentation from urgent data or autonomy exposure. |
| What should happen next? | Alert routing for shadow assets, sensitive data, ownerless workflows, approval gaps, and data handling issues. | Approve, migrate, coach, restrict, block, remediate, or scale the pattern. |
| What demand should we keep? | Usage volume, recurrence, workflow context, team adoption, cost, and outcome evidence. | Convert useful shadow AI into sanctioned tools, templates, agents, or enablement programs. |
Find the hidden AI work before it becomes hidden risk.
See how Proxon discovers shadow AI, attributes ownership, and routes the decision that comes next.
Book a Demo →Sources
Research referenced in this guide.
- Microsoft and LinkedIn, 2024 Work Trend Index.
- IBM, Cost of a Data Breach Report 2025 press release.
- Netskope, Cloud and Threat Report: Generative AI 2025.
- Netskope, Cloud and Threat Report: Shadow AI and Agentic AI 2025.
- McKinsey, The State of AI: Global Survey 2025.
- Cisco, Cybersecurity Readiness Index 2025.
- NIST AI RMF Core, Govern, Map, Measure, and Manage.
- OWASP, Top 10 for Large Language Model Applications.