AI threat catalogueReliability and Responsible UseProduction
Shadow AI (Unsanctioned AI Service Use)
Employees or business units use AI services without company approval or oversight (shadow AI). Confidential data flows to external providers, and compliance gaps and an unmanaged attack surface emerge.
Description
Freely available AI tools such as chatbots, translators, or coding assistants are within everyone's reach and promise quick productivity gains. Where clear rules or an approved internal offering are missing, employees adopt such services on their own initiative and enter customer data, trade secrets, or source code into third-party systems. The external provider can access these inputs and may use them to train its models; contractual safeguards and data protection checks are absent. The company loses track of where AI is in use, which decisions depend on it, and which data leaves the organisation. Surveys show that this kind of use is widespread and continues to grow.
Possible impact
Leaked trade secrets cannot be taken back; for personal data, the company risks GDPR violations because there is no legal basis and no data processing agreement. Obligations under the EU AI Act, such as deployer duties and AI literacy, cannot be met for systems the company does not know about. At the same time, unverified AI results flow into work products, and every uncontrolled service enlarges the attack surface.
Example
A sales employee copies a customer list including revenue figures into a free online chatbot to draft a presentation. The confidential data now sits on an external provider's servers, beyond any control of the company; comparable incidents are publicly documented.
Recommended mitigations (7)
Every mitigation states its control type, effect, implementation level and the reason for the classification.
AI usage policy and communicationGovernance & compliance
- Effect
- Preventive
- Implementation level
- Organization, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “AI usage policy and communication” is primarily a governance and compliance control: Binding usage rules, accountability, and permitted-use boundaries govern AI use; communication and control processes put them into practice.
Approved AI tool catalogueGovernance & compliance
- Effect
- Preventive
- Implementation level
- Organization, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Approved AI tool catalogue” is primarily a governance and compliance control: Binding rules, control objectives, or oversight define permitted use and accountability; complemented by binding workflows.
Egress monitoring for AI-service trafficTechnical
- Effect
- Detective
- Implementation level
- Infrastructure, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Egress monitoring for AI-service traffic” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
Data classification awareness trainingPeople & competence
- Effect
- Preventive
- Implementation level
- Organization, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Data classification awareness training” is primarily a people-and-competence control: Human knowledge, attention, or professional judgment produces the protective decision; complemented by binding workflows.
DLP controls for AI data flowsTechnical
- Effect
- Preventive, Detective
- Implementation level
- Data, Application, API & agents, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “DLP controls for AI data flows” is primarily technical: System-enforced inspection, transformation, or blocking rules stop or neutralize disallowed content before further processing; complemented by binding workflows.
Sanctioned enterprise AI offeringOrganizational & process-based
- Effect
- Preventive
- Implementation level
- Application, API & agents, Organization, Use & operations
- Complementary control type
- Governance & compliance, Technical
- Reason for the classification
- “Sanctioned enterprise AI offering” is primarily organizational and process-based: Defined selection, operating, or lifecycle procedures make the control binding and repeatable; complemented by rules and oversight as well as technical implementation.
Periodic AI usage auditsOrganizational & process-based
- Effect
- Detective
- Implementation level
- Organization, Use & operations
- Complementary control type
- Governance & compliance
- Reason for the classification
- “Periodic AI usage audits” is primarily organizational and process-based: A planned, repeatable assessment with ownership and documented follow-up creates the protective effect; complemented by rules and oversight.
Framework mappings
Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.
Verified references (7)
Every reference states the framework, the exact location and the publishing organisation.
- OWASP LLM Top 10 LLM02:2025 Sensitive Information DisclosureLLM02:2025 Sensitive Information Disclosure, official category page OWASP FoundationOriginal
- NIST AI RMF Section 2.12 Value Chain and Component IntegrationSection 2.12, p. 12 National Institute of Standards and Technology (NIST)Original
- NIST AI RMF NISTAML.05 Supply Chain AttacksTaxonomy Index, pp. x–xi; Section 3.2, pp. 41–43 National Institute of Standards and Technology (NIST)Original
- EU AI Act Article 4 AI literacyArticle 4 European Union (EUR-Lex)Original
- GDPR Article 25(1)–(2) Data protection by design and by defaultArticle 25(1) and 25(2) European Union (EUR-Lex)Original
- BIML BIML-LLM inference:10 User RiskPDF p. 19, [inference:10:user risk] Berryville Institute of Machine Learning (BIML)Original
- BIML BIML78 inference:5 User RiskPDF p. 20, [inference:5:user risk] Berryville Institute of Machine Learning (BIML)Original
Terms on this page
Glossary terms that occur in this entry. Every link leads to the full explanation.
- Shadow AI AI tools used without the organisation knowing or approving.
- AI literacy (Art. 4 EU AI Act) Duty to ensure the people involved can use AI systems competently.
Related threats
More entries from the topic group Reliability and Responsible Use.
Assess this threat in your own system
The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.
Cite this entry
For reports, policies or internal documents; the link leads directly to this entry.
“Shadow AI (Unsanctioned AI Service Use)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/shadow-ai/