Versatile AI Risk Assessment

AI threat catalogueReliability and Responsible UseProduction

Shadow AI (Unsanctioned AI Service Use)

Employees or business units use AI services without company approval or oversight (shadow AI). Confidential data flows to external providers, and compliance gaps and an unmanaged attack surface emerge.

As of: July 2026 · Catalogue version 2026.07.17.3 · 7 mitigations · 7 verified sources

Description

Freely available AI tools such as chatbots, translators, or coding assistants are within everyone's reach and promise quick productivity gains. Where clear rules or an approved internal offering are missing, employees adopt such services on their own initiative and enter customer data, trade secrets, or source code into third-party systems. The external provider can access these inputs and may use them to train its models; contractual safeguards and data protection checks are absent. The company loses track of where AI is in use, which decisions depend on it, and which data leaves the organisation. Surveys show that this kind of use is widespread and continues to grow.

Possible impact

Leaked trade secrets cannot be taken back; for personal data, the company risks GDPR violations because there is no legal basis and no data processing agreement. Obligations under the EU AI Act, such as deployer duties and AI literacy, cannot be met for systems the company does not know about. At the same time, unverified AI results flow into work products, and every uncontrolled service enlarges the attack surface.

Example

A sales employee copies a customer list including revenue figures into a free online chatbot to draft a presentation. The confidential data now sits on an external provider's servers, beyond any control of the company; comparable incidents are publicly documented.

Recommended mitigations (7)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM02:2025NIST AI RMF Section 2.12 · NISTAML.05EU AI Act Article 4GDPR Article 25(1)–(2)BIML BIML-LLM inference:10 · BIML78 inference:5

Verified references (7)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Reliability and Responsible Use.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Shadow AI (Unsanctioned AI Service Use)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/shadow-ai/

← Back to the full catalogue