GlossaryFloor 4 · The Organisationa mosaic: AI is only one tile among manyFloor 4 · The Organisation
shadow AI
No. 019 · v2026-08FR: shadow AIShadow AI is the use of AI tools by employees outside any official framework: like a personal spreadsheet that ends up running an entire department, without anyone ever having decided that it should exist.
What it is not
Shadow AI is not a matter of indiscipline. In almost every observed case it involves people trying to do their job well with tools their organisation has not given them: the signal is a lack of equipment, not a lack of loyalty. Nor is it confined to consumer tools opened in a browser, since an AI feature switched on by default in already approved software produces exactly the same effects, without anyone having installed anything. Banning without providing an equivalent does not make the usage disappear: it makes it invisible.
In depth
A gap in speed
Shadow AI comes from a gap in speed: a tool becomes available in minutes, while an organisation takes months to assess it, contract for it and open it up. Since there is nothing to buy and nothing to install, the decision to use it drops down to the level of each individual, where it escapes all visibility. It takes three main forms: publicly available tools used with internal data, AI features already present in approved software and switched on without review, and personal automations that a single person understands and that a department ends up depending on. The last two are the hardest to see, because strictly speaking no rule has been broken.
The risks, by name
The risks are better named precisely than invoked as a block. The first is data leaving the controlled perimeter, with contractual and regulatory consequences that do not depend on the person’s intent. The second is a decision taken on an output that nobody checked and of which no trace remains: the organisation becomes unable to reconstruct why it did what it did. The third is invisible dependency, when a chain of steps cobbled together by one employee becomes necessary to a department’s operation and leaves with them. The risk is not uniform for all that: rewording a text that is already public and dropping a client file into an outside service do not belong to the same world, and treating them alike discredits the rule.
Why banning fails
The blanket ban fails in a reasonably well documented way: it moves the usage onto personal devices, where nothing is left to observe. What works better comes down to two moves: providing an approved equivalent quickly, and stating what may leave and what may not by category of data rather than by tool name, since tools change faster than rules. What remains is to treat shadow AI as information rather than as a fault, because what people do outside the framework draws the map of real needs, often more faithfully than an internal survey. An organisation that regularises these uses moves faster than one that discovers them during an audit.
Relations where the neighbours live
Check 3 questions · click your answer
Level 1 · Recognise
An employee rewords their emails with an AI feature switched on by default in software the company has already approved. Is this shadow AI?
Level 2 · Distinguish
A company blocks access to AI assistants from its network. What effect is most often observed?
Level 2 · Distinguish
Which reading of shadow AI leads to the most useful decisions?
Try it 1 practice
Concrete things to try where this term comes up, in ten minutes.
Who works with this 1 role
The roles for which this term is part of the ordinary work.
Lexigraph, "Shadow AI", v2026-08, https://www.lexigraph.org/en/shadow-ai/, CC BY 4.0.