Shadow IT took about fifteen years to become a board-level concern. Shadow AI is getting there in about eighteen months.
The pattern is identical — employees adopting software without IT's knowledge because the official route is slower than the unofficial one. What's different is the speed, the volume, and the fact that a meaningful share of it never touches a procurement system at all. An engineer expensing a $20/month AI assistant does not look like a software purchase on any report your finance team currently runs.
Why AI Adoption Outpaces Traditional Shadow IT
Classic shadow IT usually required a decision. Someone had to evaluate a tool, convince a few colleagues, and put a departmental card behind an annual contract. That friction acted as a natural brake, and it left a paper trail.
AI tools removed nearly all of that friction at once:
- Individual sign-up is the default. Most AI products are designed to be adopted by one person in ninety seconds, with the team plan sold later. There is no evaluation stage to intercept.
- The price sits under every approval threshold. A $20–$40 monthly seat clears most expense policies without a second signature. Fifty of them across an organization is a five-figure annual line item that nobody has ever seen totalled.
- A lot of it is genuinely free. Free tiers mean adoption leaves no financial trace at all — which is worse, not better, because the data exposure is identical and the spend signal you would normally catch it with does not exist.
- The category is still forming. "AI tool" covers assistants, coding agents, meeting transcribers, image generators, research tools, and a long tail of niche point solutions. Teams solving the same problem rarely land on the same product.
What we see in discovery: in engagements where we specifically look for AI tools, the count of distinct AI products in use is routinely several times what IT expects — and the majority are single-seat subscriptions that never appear in the software asset inventory because they were never procured as software.
What Actually Goes Wrong
Sensitive data leaving through an unreviewed channel
This is the risk that makes shadow AI different in kind rather than just in degree. A shadow project management tool holds the data someone deliberately put in it. A shadow AI assistant holds whatever an employee pasted into it while trying to get their work done — contract language, customer records, unreleased financials, source code, patient details.
None of that has been through a data processing review. Nobody has checked the retention policy, or whether the vendor trains on submitted content, or whether the processing happens in a jurisdiction your compliance obligations permit. If you operate under GDPR, HIPAA, or any sector regime with data residency requirements, an employee's personal AI subscription is a processing relationship you are accountable for and have never documented.
Paying several times for the same capability
The financial version of the same problem. Three teams independently adopt three different AI assistants that overlap by eighty percent. Two teams buy separate meeting transcription tools while the transcription feature they already pay for sits unused inside the conferencing platform. Nobody is doing anything unreasonable; the spend is just never aggregated anywhere it would look wrong.
Dependencies nobody has declared
Workflows form around these tools quickly. A weekly report gets drafted by an AI tool. A support macro gets generated by one. A code review step depends on an agent. When the employee who expensed it leaves, or the vendor changes its pricing, the workflow breaks and IT has no record that the dependency existed.
How This Differs From Classic Shadow IT
If you have already read our breakdown of the hidden costs of shadow IT, the cost categories will be familiar — redundant spend, compliance exposure, integration debt, support overhead. The framework still applies. Three things change how you have to hunt for it:
| Dimension | Classic shadow IT | Shadow AI |
|---|---|---|
| Unit of adoption | Team or department | Individual |
| Typical trace | Departmental card, annual invoice | Personal expense claim, or none at all |
| Time to entrench | Months | Days |
| Primary exposure | Data stored in the tool | Data pasted into the tool |
The practical consequence: a discovery method built around invoices and contracts will find most of your classic shadow IT and almost none of your shadow AI.
How to Surface Shadow AI
Three sources, in order of how much they return for the effort.
1. Expense report analysis
Pull twelve months of expense claims and search for the recurring small-value software charges most reviewers approve without reading. You are looking for repeated monthly amounts in the $15–$60 range against vendor names that never appear in your software inventory. This is the highest-yield single exercise available to you, and it needs no tooling beyond a spreadsheet.
2. SSO and identity logs
If your identity provider is in the path, its application list is a near-complete record of what people actually sign into — including tools adopted with a work email and no purchase. Many AI products offer "continue with Google" or "continue with Microsoft" as the default sign-up, which means the record exists even when the money trail does not.
3. Browser extension and network review
Managed browsers report installed extensions, and a large share of AI tooling arrives as one. Network or CASB logs cover the rest. Treat this as the sweep that catches what the first two missed, not the place to start — it takes the most coordination and returns the most noise.
Do this before you write the policy. A shadow AI policy written without knowing what is already in use tends to ban the eight tools you happened to think of and say nothing about the forty in production. Discovery first, policy second.
Fold It Into Rationalization, Not Alongside It
The most common mistake here is standing up a separate "AI governance" workstream. It duplicates effort, competes for the same stakeholders, and produces a second inventory that immediately drifts from the first.
Shadow AI is a discovery problem and a redundancy problem, which is exactly what an application rationalization process already handles. Add AI tools as a category in your existing inventory, score them with the criteria you already use, and treat "three tools doing one job" the same way you would treat three project management tools. The only genuinely new step is a data-handling review for anything that has had company information pasted into it.
If you are running a portfolio review already, the mechanics are covered in our walkthrough of how to conduct a software portfolio audit — the AI additions slot into the discovery and scoring phases without changing the shape of the process.
Where to Start This Week
- Run the expense report search. One analyst, one afternoon, and you will know the size of the problem.
- Export the application list from your identity provider and diff it against your software inventory.
- Pick the single most widely used AI tool you find and get a data processing review done on it. That one review usually tells you whether you have a governance problem or a spend problem.
- Add an "AI" flag to your application inventory so the next review does not start from zero.
Not sure how much AI tooling is already running inside your organization? Our application rationalization process surfaces unapproved tools — AI included — during portfolio discovery. Book a free portfolio assessment →