Glossary

Shadow AI

Also known as: shadow artificial intelligence

Shadow AI is the use of artificial intelligence tools, models, or agents without the knowledge or approval of an organization's IT and security teams. It ranges from employees pasting company data into public chatbots to business users building unsanctioned agents in Copilot Studio. Like shadow IT before it, shadow AI creates blind spots: data may leave controlled boundaries, and no policy governs how it is used. Discovering and governing this hidden usage is essential to managing AI risk.

Shadow AI grows because AI tools are easy to reach and genuinely useful. People adopt them to move faster, often without realizing the data-protection or compliance implications of feeding corporate content into an unmanaged service.

Why it is a problem

Unsanctioned AI usage means data can leave governed boundaries and decisions can be made by tools no one has reviewed. It also undercuts regulatory alignment, including the EU AI Act, because the organization cannot account for what it does not see.

How Rencore helps

Rencore gives you tenant-wide visibility into AI usage across Microsoft 365 and the Power Platform, surfacing agents and services so they can be brought under AI governance and monitored with recommended policies.

See AI governance for the controls that address shadow AI.