AWSMTECH

Shadow AI: The Silent Risk Behind the Adoption of Artificial Intelligence in Business

CybersecurityBy Editorial Team9 min read
Laptop displaying an artificial intelligence assistant in a dimly lit office

In just a few months, generative artificial intelligence has established itself as one of the most powerful drivers of digital transformation. Summarising a report, drafting meeting minutes, producing a commercial proposal or analysing large volumes of information is now within reach of every employee.

For businesses, the potential productivity gains are considerable. Yet behind this enthusiasm, a phenomenon is developing that senior management and IT leaders still largely underestimate: Shadow AI.

Much like the Shadow IT that accompanied the rise of cloud computing some ten years ago, Shadow AI refers to the use of artificial intelligence solutions outside the governance framework defined by the organisation. It rarely stems from malicious intent. More often, it is driven by motivated employees who simply want to work faster and more efficiently.

And yet, a few clicks can be enough to expose sensitive data, undermine a compliance policy or create vulnerabilities that remain invisible to IT teams.

01AI Entered the Workplace Before the Workplace Was Ready

In most organisations, the adoption of artificial intelligence has happened spontaneously.

An employee discovers a new AI assistant online. A manager experiments with a report-generation tool. A sales team uses a chatbot to speed up proposal writing. A marketing team automates content production.

These uses often appear before the organisation has even defined:

  • an AI acceptable-use policy;
  • a governance framework;
  • data protection rules;
  • a tool approval process;
  • control and audit mechanisms.

This is why cybersecurity specialists now regard Shadow AI as one of the major challenges of the years ahead.

According to Microsoft Learn, Shadow AI refers to the use of artificial intelligence agents or applications deployed without IT visibility or approval, creating significant blind spots in terms of security, compliance and governance. (Source: Microsoft Learn)

02Why Shadow AI Worries Cybersecurity Leaders

The fundamental problem is not artificial intelligence itself.

The real issue lies in the uncontrolled flow of information.

When an employee submits a document to a public AI service, several essential questions arise immediately:

  • Where is the data being sent?
  • In which country is it processed?
  • How long is it retained?
  • Can it be used to train a model?
  • Who can access it?
  • How can the organisation demonstrate compliance in the event of an audit?

In many cases, users themselves do not know the answers to these questions.

This lack of visibility is now one of the main challenges identified by cybersecurity experts.

France’s national cybersecurity agency, ANSSI, also stresses that the development of AI introduces new cyber issues, and recommends a risk-based approach to securing its deployment and use. (Sources: ANSSI — Artificial intelligence; ANSSI — Security recommendations for a generative AI system)

03Anatomy of a Typical Incident

Let us imagine an entirely realistic situation.

An employee receives a confidential document containing:

  • financial data;
  • customer information;
  • a strategic analysis;
  • sales forecasts.

To save time, they install a free AI extension in their browser to summarise the document automatically.

The process seems harmless.

In reality, several risks emerge at the same time.

1. Use of a Personal Account

Authentication is often carried out with a private email address that lies entirely outside the organisation’s control.

2. Installation of an Unapproved Application

No security, compliance or data protection review has been carried out.

3. Granting of Extensive Permissions

Some extensions request permission to:

  • read the pages visited;
  • access open documents;
  • interact with email;
  • access connected SaaS applications.

4. Transmission of Sensitive Information

The content analysed may be sent to external infrastructure whose processing is difficult to verify.

5. Loss of Traceability

The organisation often has no visibility over:

  • the data transmitted;
  • the users involved;
  • the exact scope of the exposure.

In a matter of seconds, strategic information can leave the security perimeter that is normally under control.

04The Risks for Swiss SMEs and Organisations

While large companies sometimes have resources dedicated to AI governance, SMEs remain particularly exposed.

Risk of Data Leakage

The information most frequently shared with AI tools includes:

  • commercial proposals;
  • contracts;
  • HR data;
  • strategic presentations;
  • financial forecasts;
  • customer data.

Yet this information often represents the organisation’s main intangible asset.

A leak or unintentional exposure can have significant operational, financial and reputational consequences.

Risk of Non-Compliance

Swiss companies operate in an increasingly demanding regulatory environment.

In particular, they must take into account:

  • the revised Swiss Federal Act on Data Protection (FADP, known in French as the nLPD);
  • the requirements of the GDPR when processing data of European citizens;
  • regulatory developments relating to artificial intelligence.

CNIL, the French data protection authority, points out that processing involving artificial intelligence systems must comply with the rules applicable to the protection of personal data. (Source: CNIL — Artificial intelligence)

As soon as an organisation does not know which tools are being used or what information is being shared, demonstrating compliance becomes particularly complex.

Increased Cyber Risk

The rise of AI tools also creates a new attack surface.

Some applications request access to:

  • Microsoft 365;
  • Google Workspace;
  • SharePoint;
  • OneDrive;
  • corporate email;
  • business platforms.

Each additional connection represents a potential risk that needs to be assessed and controlled.

Decision-Making Risk

Another danger, often less visible, lies in placing excessive trust in the answers produced by AI.

Generative models can provide incorrect, incomplete or outdated information while appearing highly credible.

Without human validation, the consequences can be significant:

  • flawed strategic decisions;
  • contractual errors;
  • inaccurate communications;
  • legal and financial risks.

05Banning AI: An Already Outdated Approach

Faced with these risks, some organisations have chosen to block access to artificial intelligence platforms altogether.

This approach, however, has a major limitation.

The history of digital technology shows that banning a useful tool rarely leads to it being abandoned.

Employees then turn to:

  • their personal smartphones;
  • their private accounts;
  • external networks;
  • uncontrolled solutions.

The result is paradoxical: the usage continues, but becomes completely invisible.

The right approach, therefore, is not prohibition.

The right approach is governance.

06Bringing AI Into a Secure Framework

The most advanced organisations are now adopting a pragmatic strategy.

Define an AI Policy

Every organisation should formalise:

  • the authorised tools;
  • the accepted use cases;
  • the prohibited data;
  • users’ responsibilities.

Train Employees

Awareness remains the most effective measure.

Users need to understand:

  • what risks exist;
  • which data can be used;
  • when to contact IT support;
  • how to identify a trustworthy tool.

Favour Approved Platforms

Organisations benefit from offering approved, governed alternatives rather than leaving teams to find consumer solutions on their own.

Establish Continuous Governance

Artificial intelligence is evolving extremely quickly.

The tools authorised today will need to be reassessed tomorrow.

Governance must therefore become a continuous process involving:

  • senior management;
  • IT;
  • cybersecurity;
  • human resources;
  • legal functions;
  • the data protection officer.

07Towards Trustworthy AI

Artificial intelligence is no longer an emerging technology. It is already embedded in the day-to-day processes of many organisations.

The question is therefore no longer whether employees use AI, but how they use it.

The organisations that succeed in their digital transformation will be those able to balance innovation, productivity and risk management.

Shadow AI is not a technological problem. It is a matter of governance, corporate culture and cybersecurity.

In a context where data is one of an organisation’s most valuable assets, true digital maturity lies less in adopting AI than in knowing how to govern it.

Is your company already using artificial intelligence?

AWSMTECH helps organisations assess existing AI usage, identify potential risks and implement a governance framework adapted to their IT environment.

Talk to an expert