Home
Blog
The Security Risks of Shadow AI in Business

The Security Risks of Shadow AI in Business

Hwei Oh
09/15/2026
Share this article:

CISOs have known about Shadow IT, the practice of using unsanctioned software tools that can result in potential security risks, for decades. For example, a user might install an open-source tool that requires elevated privileges, only to discover later that the tool or one of its components is malicious, and the user has now opened a backdoor into the network.

IT has typically gotten around Shadow IT by restricting user privileges, such as removing the user’s right to install apps. This method isn’t perfect, especially as more and more tools become web-based, but it’s been fairly workable.

Now, security professionals are faced with a new menace: Shadow AI, the use of unsanctioned AI tools such as Claude, ChatGPT, Grok, or even locally-managed LLMs, which can lead to a wide array of new problems.

Why Shadow AI is a problem

Unlike Shadow IT, Shadow AI’s risk lies primarily in its use, not in whether something has been installed that could open a backdoor. AI tools have gained a reputation for privacy violations and aggressive data storage, making it challenging to delete data you provide to a generative AI tool.

ChatGPT is even currently under court order to store all its past chats with users, even when the user explicitly deletes the chat.

Users might inadvertently type company secrets or confidential information into these tools, resulting in data leakage. In Europe, as well as other jurisdictions with strict privacy regulations, users might type in confidential customer data, thus violating those data protection laws.

Another issue is the lack of reliability these tools have. Hallucinations are a generative AI problem that isn’t going away. For example, numerous legal professionals have been fined for using fictitious citations in reports generated by AI.

More directly, users might receive low-quality recommendations from AI on how to solve a software issue instead of calling IT.

The realities of AI usage in businesses

Blocking access to generative AI tools from your network isn’t enough because 47% of people using these tools are doing so from their personal devices. Additionally, genAI is being integrated into so many existing platforms that users can access it from almost anywhere. Microsoft Office provides Copilot while Google Docs integrates with Gemini.

Websites are also increasingly integrating AI-powered chatbots into their help sections so users can query the chatbot instead of reading the docs.

Between embedded AI, SaaS integrations, and browser extensions, blocking AI access is virtually impossible.

Users turn to these tools because they believe the tools increase productivity and speed up tasks. Grok has become especially good at “replacing Google,” performing dozens of internet searches before answering a question.

A lack of approved AI tools might be exacerbating the problem. Without approved tools, users feel forced to use personal accounts instead.

IBM’s 2025 Cost of a Data Breach Report states that 20% of organizations said they suffered a breach in which Shadow AI was involved. Of those organizations, 97% didn’t have AI access controls in place. (It should be noted that 13% of organizations suffered a breach because of sanctioned AI as well.)

The additional cost of a breach for organizations with “high levels” of Shadow AI was $670,000, compared to organizations with low levels of AI use or none at all. In total, incidents involving Shadow AI resulted in more compromises of PII (Personally identifiable information) and IP (intellectual property) information.

The IBM report also says, “The swift rise of shadow AI has displaced security skills shortages as one of the top three costly breach factors tracked by this report.”

In other words: Shadow AI is a massive security problem!

The primary risks of Shadow AI

Shadow AI increases a company’s exposure to cybersecurity risks in several ways, some more severe than others.

Data leakage and exposure

The most immediate risk is data leakage and exposure from users typing in sensitive information into insecure AI models. Unaware of an AI company’s data retention policies or that AI companies might be using prompts to further train models, employees might type in sensitive info, such as:

  • PII, like customer email addresses, phone numbers, physical addresses, or social security numbers.
  • IP information, such as confidential pitch decks or schemas for new inventions.
  • Confidential company financials.
  • Source code. (This is especially risky because AI tools are increasingly being integrated into development environments.)

Expanded attack surface and LLM-driven malware

While LLMs aren’t anywhere near creating new strains of malware, some legitimate malware risks do exist that are specific to LLMs.

For example, through social engineering, an attacker can get an employee to unwittingly generate a malicious script and then run it on their machine. The malicious script can then download payloads to the machine.

Malicious browser extensions posing as AI can also steal AI chat histories.

Model-related risks

Malicious models exist that don’t have the typical safeguards built into more mainstream tools. However, even mainstream tools suffer from hallucination, sometimes providing outputs that can lead to disastrous consequences.

Compliance and regulatory risks

In addition to the risks for the company itself, data leakage and exfiltration will almost always lead to some kind of compliance or regulatory risk. This is especially true for jurisdictions with strict privacy regulations, such as Europe with its GDPR (General Data Protection Regulation).

Certain sectors are likewise at higher risk than others, such as the health sector, which must comply with HIPAA (Health Insurance Portability and Accountability Act). The act delineates stringent controls that health professionals in the United States must keep in place to prevent abuse of a patient’s medical data. Such data is immensely valuable on the black market because it facilitates insurance fraud, which is why it’s so heavily regulated—and heavily fined when a company exposes it.

Data sovereignty is another key compliance issue when using unsanctioned AI models. When “chatting” with an AI tool, you’re sending data to servers that might reside outside the sanctioned zones according to your jurisdiction.

Real-world examples of Shadow AI failures in business

In 2003, Amazon discovered ChatGPT responses that looked “similar to internal Amazon data,” according to one of Amazon’s lawyers.

Samsung suffered a leak of top-secret source code after an employee pasted the code into ChatGPT to “optimize” it. Shortly after the leak, Apple banned ChatGPT and Microsoft Copilot for fears of similar leaks.

In the healthcare sector, 17% of employees admit to using unsanctioned AI tools, despite strict rules forbidding this. When asked why they used it, employees typically responded that their employers didn’t provide an approved version for them to use, and they were trying to speed up workflows.

Mitigation strategies

Outright bans tend to force AI usage underground, which is even riskier than knowing what’s going on. A more effective strategy would involve a combination of clear company policies (governance), better visibility, and approved alternatives.

Governance

Company policies should focus on approved alternatives instead of outright bans, as well as placing AI tools into tiers, such as:

  • Approved
  • Limited use
  • Prohibited

Users should also understand clearly why these tools are prohibited.

Visibility

A Cloud Access Security Broker (CASB) will provide better visibility into network access for tools accessed through business devices. However, it might not be sufficient to prevent access from personal devices. That’s why governance must occur first.

Approved alternatives

Approved alternatives should be as easy to use as mainstream options. Mainstream AI providers offer paid tiers for API access that have stricter controls than the general tiers, and a company can integrate these into its own solution. While these are pricier than publicly available tiers, they’re far less risky because they typically don’t retain company data.

Other options are to develop in-house tools using open-source models and make them accessible via an easy-to-use front-end.

Get help from SolCyber

SolCyber is an experienced managed security service provider (MSSP) providing cybersecurity solutions with 24/7 human-led monitoring, detection, and response.

We can help you build in the necessary governance, visibility, and alternatives to protect your organization from shadow AI. To learn more, reach out to us for a chat.

Photo by Stefano Pollio on Unsplash

Avatar photo
Hwei Oh
09/15/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14855