Aug 12, 2026

Shadow AI

Shadow AI: How Regulated Data Walks Out the Door One Prompt at a Time

Author Laura Richardson

Somewhere in your organization today, a well-meaning employee pasted something they should not have into a chatbot. Maybe it was a paragraph from a proposal marked CUI. Maybe a patient note, or a spreadsheet of account numbers, dropped in with the innocent instruction “clean this up for me.” Nobody meant harm. That is exactly what makes shadow AI different from most insider risk: it is driven by your best people trying to work faster. 

Shadow AI is the use of AI tools outside your approved, governed environment. In an unregulated company it is a data hygiene problem. In a regulated one it is a compliance event with a timestamp, because the moment regulated data reaches an unauthorized service, obligations trigger whether or not anyone notices. 

Why This Is Worse Than Classic Shadow IT 

Shadow IT was mostly about unsanctioned apps holding company data at rest. Shadow AI adds two aggravating factors. 

The data goes somewhere you cannot audit or retrieve. Consumer AI tools may retain prompts, use them to improve services, or hold them under terms of service no procurement team ever reviewed. Once a CUI paragraph is in a consumer chatbot’s history, you cannot inventory it, you cannot produce it for an assessor, and you cannot delete it with any confidence. For a defense contractor, sending covered defense information to a cloud service that does not meet FedRAMP Moderate equivalency is not a gray area under DFARS 252.204-7012. For a hospital, ePHI in a consumer tool is a disclosure to analyze under HIPAA. For a bank, customer data has just left the Safeguards Rule perimeter. 

The friction is near zero. Shadow IT required signing up for something. Shadow AI requires a browser tab, and increasingly not even that, since AI features are being embedded into ordinary software (browsers, note-taking apps, email clients, meeting tools) faster than security teams can evaluate them. Some of your shadow AI was installed by a vendor update, not a user decision. 

Diagram showing regulated data (CUI, FCI, ePHI, NPI) exiting through three unsanctioned paths (consumer chatbot, embedded AI feature, personal device) versus the governed route through label-driven DLP into sanctioned AI services in Azure Government or AWS GovCloud.

Find It Before You Fight It 

You cannot write a credible policy against usage you have not measured. Start with visibility. 

Network and DNS telemetry will show which AI endpoints your users reach and how often. Secure web gateways and Cloud Access Security Broker (CASB)tools can categorize AI services and report volume by user and department. Endpoint DLP catches the paste-into-browser action itself. Even a simple review of expense reports and SSO logs surfaces the paid tools teams quietly adopted. 

Expect the inventory to be humbling and treat it as demand data rather than a list of offenders. Every entry tells you a job someone needed done: summarization, drafting, code help, data cleanup. That demand map is the blueprint for what your sanctioned alternative has to offer, because a ban that ignores demand just teaches people to use their phones. 

Controls That Actually Hold 

A layered approach works; a memo does not. 

Write a short, specific acceptable use policy. Name what data classes may never enter unapproved AI tools (CUI, FCI, ePHI, customer NPI, source code if that is your call), name the approved tools, and say what to do when someone slips, because early self-reporting turns incidents into cleanups. 

Enforce at the label, not just the URL. Blocklists of AI domains decay weekly. Label-driven DLP is more durable: if your documents and messages carry sensitivity labels, endpoint and browser DLP can block Regulated content from reaching any unapproved destination, including AI tools that did not exist when the policy was written. This is where a real data classification program pays off again. 

Constrain the embedded AI. Review the AI features inside software you already license and disable or configure the ones whose data handling does not meet your bar. Tenant-level settings in productivity suites, browser policies, and mobile device management all have a role. Your CMMC or HIPAA boundary does not care whether the exfiltration path was a chatbot website or a text prediction feature phoning home. 

Log and review. Alerts on attempted policy violations are coaching opportunities and leading indicators.  A spike in blocked AI traffic from one team signals a workload that needs a sanctioned solution. 

The Only Durable Fix Is a Better Legal Option 

Here is the uncomfortable pattern every security leader eventually accepts: sustained shadow AI is a symptom of unmet demand, and demand always wins over friction eventually. The organizations that successfully extinguish shadow AI are the ones that stand up an approved alternative that is genuinely good, inside a boundary built for their data. 

For defense contractors, that means AI services running in Azure Government or AWS GovCloud, inside the same enclave that already protects CUI, with identity, logging, and labels wired in. For healthcare and financial organizations, it means enterprise AI deployments with contractual data protections, no training on AI inputs, and integration with your access model. When the sanctioned tool is one click away, answers questions about your actual documents, and does not require anyone to gamble their clearance or their license, the consumer tool loses its appeal. 

Pair the carrot with honest education. People stop pasting sensitive data into chatbots when they understand that prompts can be retained, that models are not a locked drawer, and that “I deleted the conversation” deletes nothing that matters. Most shadow AI users are not defiant. They were never told, in concrete terms, what the tool does with what they type. 

VSO helps regulated organizations replace shadow AI with sanctioned AI: enclave-hosted services on Azure Government and AWS GovCloud, label-driven DLP, and acceptable use programs your assessor will respect. Ask us for a shadow AI exposure assessment.

Shadow AI is the use of AI tools and features outside an organization’s approved, governed environment, such as employees pasting work content into consumer chatbots or using AI features embedded in unvetted software.

It can be. Covered defense information sent to a cloud service that does not meet DFARS requirements is outside your authorized boundary, and depending on the circumstances it may trigger incident handling and reporting obligations. Treat it as an incident and evaluate it, rather than assuming it was harmless.

Blocking helps, but on its own it decays quickly because new tools appear constantly and AI features ship inside ordinary software. Label-driven DLP that follows the data, plus configuration of embedded AI features, holds up far better over time.

Combine network and DNS telemetry, secure web gateway or CASB reporting, endpoint DLP events, SSO logs, and expense data. The goal is a demand map showing which teams use which tools for which jobs.

A sanctioned alternative that is genuinely useful and easy to reach, hosted inside a boundary appropriate for your data, combined with clear policy and label-based enforcement. Prohibition without a viable alternative mostly relocates the problem to personal devices.

Share This Story, Choose Your Platform!