1 article with this tag
Shadow AI is employees using AI tools the company hasn't approved or doesn't manage (chatbots, AI browser extensions, coding assistants, meeting-note AI, AI agents connected to work accounts) for work. It's the AI form of shadow IT. The main risks: confidential or personal data entered may be stored by the provider and, depending on plan and settings, used for training (consumer and business terms differ); OAuth grants and API keys hand third-party tools access to mail and drives; output errors and licensing problems; and privacy-law and audit obligations. A ban alone pushes usage out of sight, so provide an approved tool on business terms that don't train on inputs, a short rule on what data may be entered, SSO and admin controls, regular review of OAuth grants and extensions, and an ask-first channel.