Shadow AI
Workers are feeding confidential company documents into public AI tools every day. Most organizations have no idea it's happening.
Somewhere right now, an employee is pasting a draft contract into a public AI tool to clean up the language. The response comes back in seconds. The language is better. They move on. Nobody flagged it. No alarm went off. Nothing about the moment felt like a moment at all.
By Aaron Rose · Tech Reader Magazine · July 28, 2026
Podcast 🎧 • Video 📽 • Short 📽
Just Someone with a Deadline
The document they pasted had a client name in it. A pricing structure. A delivery timeline that hadn't been announced yet. A clause that reflected the company's negotiating position on penalty terms. None of that is why the employee opened the AI tab. They needed help with a sentence. The rest of the document just came along for the ride.
This is what shadow AI looks like at ground level. Not a rogue actor. Not a deliberate breach. Just someone with a deadline and an AI tool in a browser tab, doing what works.
The term itself — shadow AI — is borrowed from an older problem. Shadow IT emerged in the early smartphone era, when workers started bringing their own devices to the office before companies had policies for it. They used personal Dropbox accounts to share files before enterprise cloud storage existed. They installed their own software on company machines because the approved tools were slower, older, or simply absent. IT departments were perpetually catching up to behavior that had already become standard practice.
The pattern now is the same. The tools are different. The data flowing through them is not.
What Gets Pasted Into AI Tools
It is worth pausing on what actually lives inside the kinds of documents that employees paste into AI tools, because the contents are easy to underestimate when the goal is just to fix a paragraph.
A contract draft contains client identity, deal structure, payment terms, and the specific language a company has chosen — or been forced to accept — on liability, indemnification, and termination. A proposal contains pricing that hasn't been shared with the market, competitive positioning, and a picture of how the company values its own work. An internal memo can contain personnel decisions, acquisition interest, product roadmaps, or the kind of candid strategic thinking that organizations specifically do not want outside the room.
None of this is classified. Most of it isn't even formally marked confidential. It is simply the ordinary texture of business — information that has value precisely because it isn't public, and that loses some of that value the moment it is.
What Happens to the Input
Public AI tools are operated by companies with their own infrastructure, their own data handling practices, and their own terms of service. Those terms vary. Some providers retain input data to improve their models. Some do not. Some offer enterprise tiers with stronger data isolation guarantees that the worker using the free browser tab has not purchased. Some have data residency commitments that apply only to paying customers above a certain contract tier.
The gap between what a terms-of-service document says and what an employee using a free AI tool understands about data handling is, in most cases, total. The question of whether a given prompt is retained, reviewed, or used in any form downstream is not something most users have thought about, because nothing in the experience of using the tool prompts them to.
The tool responds. The tool is helpful. The interaction ends. What happened to the input is not visible from the output.
The question of whether a given prompt is retained, reviewed, or used in any form downstream is not something most users have thought about,
A Typical Scenario
At 2:14 pm, an employee prompts an AI. That prompt includes confidential contract information. The response comes back seconds later. The employee copies the suggested language into their draft, closes the AI tab, and sends the document to the client at 2:31 pm. By 3:00 pm they have moved on to something else entirely.
In the logs of the AI provider — to whatever extent logs are kept — there is a record of an input that contained a company name, a client name, a pricing schedule, and three paragraphs of negotiated legal language. The employee does not know this. Their manager does not know this. The IT department does not know this because there is no log on the company's side at all.
Most Companies Have No Policy
Organizations that have a shadow AI problem almost always have something else first: a policy vacuum. Either no approved AI tool exists, or one exists but hasn't been communicated clearly, or the approved tool is slower and less capable than the public alternative, or guidance was issued once in an email that nobody read.
The worker filling that vacuum isn't making a statement about the policy. They often don't know a policy exists. They are solving a problem in front of them with the best available tool, which happens to be a free browser tab that anyone can open.
This is precisely what shadow IT looked like. The employees who started using personal iPhones for work email in 2008 were not, by and large, attempting to circumvent security policy. They had a better device. The company's device was worse. The choice felt obvious. It took years — and the emergence of an entire mobile device management industry — before organizations developed the governance frameworks to match the behavior that was already widespread.
Clients Are Starting to Ask for AI Auditing
Something similar is beginning to happen now, and it is happening on a timeline that will compress faster than the shadow IT era did, because the regulatory environment is more developed and the questions being asked are more specific.
Auditors are starting to add AI usage to their inquiry lists. Not because there is a comprehensive AI audit standard yet — there isn't — but because clients are asking, regulators are signaling, and cyber insurers are beginning to want to understand what data is moving through which systems. The questions don't have clean answers. The frameworks are being drafted. But the asking has begun.
Industries with existing data governance obligations are feeling this earlier than others. A law firm operating under privilege obligations, a healthcare organization subject to HIPAA, a financial services company under SEC recordkeeping rules — each of these already has a regulatory posture around data handling that shadow AI behavior can complicate in ways that are only beginning to be formally examined. The regulators who govern those industries are not waiting for a new AI law to ask whether existing rules apply to new tools.
The frameworks are being drafted. But the asking has already begun — from auditors, from insurers, from clients who want to know where their data went.
The asking has already begun — from auditors, from insurers, from clients who want to know where their data went.
Every Company Will Have Compliance
The compliance trajectory of shadow IT is instructive here, because it did not stop at the enterprise. BYOD policies, mobile device management, cloud data governance — these obligations eventually reached organizations that had no IT department, no legal team, and no expectation that they would ever need to think about them. A ten-person accounting firm. A regional contractor. A solo medical practice. Compliance always travels downmarket. It takes longer to arrive. But it always arrives.
Shadow AI governance will follow the same path. The enterprises are the first to face formal inquiry, because they have auditors, because their contracts have data handling clauses, because their cyber insurance renewals now include questions that require answers.
But the small company that has no IT department to shadow is not exempt from the underlying dynamic. Its employees are using the same public tools. Its documents contain the same kinds of information. The fact that nobody is asking yet is a function of timing, not of scale.
When the asking reaches smaller organizations — through insurance requirements, through client contracts, through industry association guidance, through the same slow trickle by which every previous compliance wave arrived — the question will be the same one the enterprises are working through now: what were people using, what went into it, and what is the organization's obligation with respect to what it cannot fully know?
Compliance always travels downmarket. It takes longer to arrive. But it always arrives.
Where Things Stand Now
Right now, most organizations have no logging of AI tool usage, no approved alternative that workers are consistently using, and no audit trail for what data has moved through which systems. Most workers using public AI tools have not read the relevant terms of service and would not find them fully clarifying if they had. The gap between institutional awareness and daily practice is, in most places, close to total.
That gap will close. It closed with shadow IT, imperfectly and over time, through a combination of better tooling, clearer policy, and the gradual arrival of compliance pressure that gave organizations a reason to act. The same forces are assembling now, at a speed that the scale of AI adoption will likely accelerate.
What the shadow IT parallel does not resolve is the question of what happened in the interim — all the contracts that moved through systems without logging, all the data events that produced no audit trail, all the moments that felt like nothing because nothing announced itself as something. The governance frameworks that are being built now are designed for what comes next. They are not designed to account for what has already happened.
Somewhere right now, a prompt is going out with a client name in it. The response is coming back. The tab is closing. The log on the company's side remains empty, the same as it was before the question was asked, the same as it will be until someone decides it shouldn't be.
What the Enterprise AI Audit Looks Like
Compliance teams are starting to ask about AI usage. The frameworks aren't finished. The questions are being invented in real time. A look at what organizations are actually being asked — and what they don't yet know how to answer. Coming soon at Tech Reader Magazine.