top of page
Sertis
AC_member_horizontal_reversed_fullclr_PNG.png

Shadow AI: The AI Risk Organizations May Not See Coming

  • Writer: Sertis
    Sertis
  • Jul 14
  • 4 min read

Today, AI has become part of the daily work routine for millions of employees.


Marketing teams use AI to summarize reports and plan campaigns.

HR teams upload employee information to help draft job descriptions.

Developers paste source code into AI assistants to troubleshoot issues.

Finance teams ask AI to summarize M&A plans before important meetings.


These activities are happening across organizations worldwide, and in many ways, this is a positive sign. It reflects how employees are embracing AI to work faster, improve productivity, and focus more of their time on higher-value tasks.


In many cases, AI adoption like these happens organically. Employees discover new tools, experiment with them, and quickly integrate them into their workflows because they help them work more efficiently. While this rapid adoption can drive productivity, it can also create blind spots for the organization.


However, without clear visibility into which AI tools are being used, what data is being shared, and whether those tools meet internal security and compliance requirements, organizations may find themselves struggling to maintain oversight.


This is where the concept of Shadow AI comes into play.


What Is Shadow AI?


Shadow AI refers to the use of AI tools within an organization without formal oversight, approval, or governance. 


The concept is similar to Shadow IT, where employees adopt software outside of officially sanctioned systems. However, Shadow AI introduces a new level of complexity as employees are not simply using external software but often sharing information with third-party AI services.


In fact, Shadow AI is not necessarily the result of malicious intent or policy violations. In most cases, employees are simply trying to work more efficiently and take advantage of new technologies that help them perform their jobs better.


The challenge is that AI adoption is frequently occurring faster than governance frameworks can evolve. As a result, organizations may struggle to understand how AI is being used, what data is being shared, and where potential risks exist.


The Risks of Shadow AI


At first glance, asking AI to summarize a document or generate a report may seem harmless. However, the risk often lies in the data being shared behind the scenes.

Research from Cyberhaven found that approximately 11% of information submitted to AI tools contains sensitive business data, including customer information, financial forecasts, source code, and confidential business documents.


That percentage may appear small until it is viewed at scale. But when hundreds or thousands of employees interact with AI every day, even a small percentage can represent a significant amount of sensitive information leaving the organization's direct control.


The challenge becomes even more complicated because organizations often lack visibility into how many AI tools are actually being used. According to Productiv's 2026 research, large enterprises use an average of 14 AI tools, while IT teams typically have visibility into only four or five of them.


In other words, many organizations are trying to govern AI without seeing the full picture.

Some tools may never have undergone a security assessment. Others may not have been evaluated for compliance requirements or data-handling practices. Yet employees continue using them because they provide immediate value.


This creates a growing gap between AI adoption and AI governance.


Why 2026 Is a Turning Point


Shadow AI is no longer simply an IT or cybersecurity concern. It is rapidly becoming a governance issue that demands executive attention. Regulators around the world are placing greater focus on AI transparency, accountability, data protection, and risk management.


In Thailand, the Personal Data Protection Commission (PDPC) has released guidance on personal data protection in AI development and deployment, helping organizations assess risks and implement appropriate safeguards throughout the AI lifecycle.


Globally, regulations such as the EU AI Act are beginning to influence organizations operating across borders or handling data connected to European markets. For Thai organizations with customers, partners, or data flows linked to Europe, these developments are becoming increasingly relevant.


At the same time, AI Governance is beginning to appear in compliance audits alongside established areas such as cybersecurity and data governance.


Together, these trends highlight a broader shift: AI is no longer viewed solely as a productivity tool. It is becoming a strategic issue that affects organizational resilience, risk management, and long-term competitiveness.


Restriction Is Not the Answer


When discussing Shadow AI, the first reaction is often to block or restrict external AI tools. In practice, however, this approach is rarely possible. Employees will continue seeking tools that help them work faster, improve efficiency, and meet growing business expectations. Preventing AI usage altogether often drives adoption further underground rather than eliminating it.


The objective should not be to reduce AI adoption, but to ensure AI is used within a framework that is secure, transparent, and aligned with organizational requirements.

Most organizations should focus on three key areas:


  • Visibility: Understand which AI tools are actually being used across the organization and how they are being utilized.

  • Policy: Establish clear guidelines regarding acceptable AI use, including which types of data can and cannot be shared with external AI services.

  • Infrastructure: For organizations with stricter security requirements, options such as Private LLMs or Private AI Environments can provide greater control while still enabling employees to benefit from AI capabilities.


Conclusion


Shadow AI is not inherently a problem. In many cases, it is a natural consequence of employees adopting new technologies to work more effectively. The real challenge is not stopping AI adoption,but creating an environment where AI can be used safely, transparently, and responsibly. Organizations that can balance innovation with governance will be better positioned to capture the benefits of AI while managing the risks that come with it.


If your organization is exploring AI Governance frameworks or evaluating Private LLM strategies, Sertis can help design and implement solutions that align with your security, compliance, and business requirements.


Contact our experts to learn how to build AI systems that are powerful, secure, and enterprise-ready: contact us

Have a project in mind?

bottom of page