Guide

Shadow AI: why your best employees hand their keys to an agent

Shadow AI has changed in kind: after data pasted into a chatbot, credentials handed to agents. The detection checklist for CIOs and CISOs, the seven clauses of a policy that holds, and the only answer that puts it out for good.

Published July 20, 2026

Shadow AI is the use of artificial intelligence tools by your teams without IT approval: personal accounts, company data, no trace. The phenomenon is massive: according to IDC (2025), 86% of French companies send sensitive data to non-sovereign AI tools. And it has just changed in kind: after data pasted into a chatbot, credentials handed to agents. This guide gives you the detection grid, the clauses of a policy people will actually follow, and the reason neither will be enough on its own.

The paradox: it is your best people

The employee who installs an AI tool without asking is not the slacker of the team. It is the person who wants their work done faster and better, and who found nothing in the official stack to do it with. Shadow AI is distributed like initiative: it starts with your most driven profiles. Punishing it without offering something better means sanctioning exactly the behaviour the company claims to want.

That is the first thing to understand before writing any policy: shadow AI is a demand signal. It tells you, precisely, where your current tools fall short.

The 2026 shift: from chatbot to agent

The first era of shadow AI was a document pasted into a public chatbot. The risk was real but bounded: a data leak, a confidentiality breach, text folded into a third-party model's training.

The second era began with open-source personal agents, OpenClaw being the best-known, which an employee installs in minutes and connects to their mailbox, calendar or the CRM with their own credentials. The difference is one of kind, not degree: a chatbot saw your data pass by, an agent holds your keys. It has standing access, it acts (sends, edits, replies), and its authorizations often outlive the tool itself, forgotten in your directory. An unfortunate email sent by an agent binds the company as surely as one written by hand, with one aggravating factor: nobody will know where it came from.

The detection checklist

The real extent can be measured in one to two weeks, with means you already have. In order of yield:

  1. OAuth grants in your directory. Third-party applications authorized on your corporate mail accounts, sorted by grant date. This is where agents show up, and it is the highest-yield review: it detects and lets you revoke in the same motion.
  2. Network and proxy logs. Traffic to the domains of the major model providers, by volume and by department. A spike in a department with no approved AI tool is an answer in itself.
  3. Browser extensions. The inventory through device management: AI assistants install there first, closest to the data on screen.
  4. Expense reports. AI subscriptions reimbursed as "software" or paid on personal cards. Finance sees what the IT department does not.
  5. Code repositories. A secrets scan across your repos: model-provider API keys turn up with discouraging regularity.
  6. The device fleet. Agents and command-line tools installed on workstations, visible in your device inventory.
  7. The no-blame interview. Announce a declaration window without sanctions: who uses what, on which data, for what purpose. It is the only item on the list that measures the need as well as the risk, and it prepares the next step.

The seven clauses of a policy people will follow

An AI policy holds under three conditions: short, applicable from memory, and able to say yes quickly. A policy that answers in three months manufactures the very shadow AI it claims to forbid.

  1. Three data classes, and what each one allows: public, internal, sensitive. Simple enough to apply on the fly, without asking anyone.
  2. The list of approved tools, with a committed response time for any addition request. The response time is the most important clause: it is what makes the workaround pointless.
  3. Never company credentials in an unapproved tool. No password, no session cookie, no OAuth delegation. The rule applies to agents first and foremost.
  4. No autonomous write access for an agent to a production system: every outbound action (send, edit, publish) goes through human validation.
  5. Professional accounts only, with training exclusion verified in writing, contract in hand, not on the word of a marketing page.
  6. No-blame incident reporting. Fear of blame is the first obstacle to detection; a punitive policy makes you blind.
  7. A register of AI usage, maintained and reviewed at a fixed cadence. It is what your cyber insurer, your enterprise clients and the regulator will ask for, in that order.

For the supervised use of consumer tools themselves, the minimal charter is detailed in ChatGPT at work: the clear-eyed guide.

The only answer that puts it out

Prohibition moves the usage to personal phones, where the risk remains and the measurement disappears. Policy frames the demand but does not extinguish it: it was there before the policy was. What puts shadow AI out is an official alternative better than the workaround: agents that actually work across the company's tools, answers that cite their sources, on an instance IT governs end to end, audit log included. The day the approved tool is the most effective one, shadow AI stops being a temptation and becomes what it should always have been: a list of needs, ranked by your own teams.

To assess where you stand, the audit grid for your internal AI asks the seven questions in the order an auditor will; and what a CIO can demand from a governed AI layer is detailed on the page for CIOs and CISOs.

Frequently asked questions

Is shadow AI illegal?

No text forbids it as such. It causes breaches of other obligations: GDPR when personal data flows to an undeclared processing, professional secrecy, the confidentiality clauses of your client contracts. And the deployer obligations of the European AI regulation assume you know which AI systems are used in the company, which is impossible without an inventory.

Is blocking AI tool domains at the firewall enough?

No. Blocking moves the usage to personal phones, outside all visibility: the risk stays whole, the measurement disappears. Blocking can complement a policy on the most sensitive data; it replaces neither detection nor the alternative.

What is the difference between shadow IT and shadow AI?

Speed, first: an AI account is created in two minutes, with no installation and no purchase. Gravity, next: users paste in precisely the documents that matter. Agency, finally, specific to the second era: an undeclared application stored your data, an undeclared agent acts with your access.

Where do we start?

With measurement: OAuth grants and network logs give you a state of play within a week. Then the policy, short and quick to say yes. Then the alternative, without which the first two wear out. If the inventory surprises you, it is working; and if the subject deserves a proper review, let's talk.