Blog · AI
Shadow AI: Regaining Control Without Blocking Teams

On this page
Shadow AI reveals genuine business needs. Here’s how to frame, secure, and leverage these AI uses without hindering teams.
Shadow AI in business: regaining control without blocking teams
In many companies, AI is already in use. Not always as part of a major project led by the IT department. Not always with a tool approved by management. It often arrives through business teams, sales, support, ops, HR, or internal consultants.
An employee summarizes meeting notes with ChatGPT. A support team drafts customer responses with Claude. An ops manager analyzes an Excel file with Gemini. A marketer tests Perplexity to speed up competitive intelligence. A project lead prototypes with Lovable, Bolt, v0, or Cursor.
That’s shadow AI.
The parallel with shadow IT is clear. When official tools don’t meet needs quickly enough, teams find their own solutions. This isn’t always bad news, it often highlights a real business need. The problem arises when these uses remain invisible, undocumented, unsecured, and unintegrated with the IT system.
The right question isn’t whether to ban AI in business. The real question is understanding what’s happening, why teams use these AI tools, what real AI risks exist, and how to turn these uses into useful, reliable, and maintainable solutions.
1. What is shadow AI?
Shadow AI refers to the use of AI tools by teams without clear guidelines, official approval, IT oversight, or proper integration into the IT system.
It can take many simple forms.
A salesperson pastes CRM notes into ChatGPT to draft a follow-up email. A finance team asks an AI tool to analyze an Excel spreadsheet. A manager uses a transcription assistant to summarize a meeting. A support team generates draft customer responses. An employee connects Make or Zapier to an AI model to automate a repetitive task. A business user builds a mini-app with Lovable, Bolt, v0, or Cursor to solve an internal pain point.
In some cases, the use is low-risk, like rephrasing a public text or brainstorming ideas for a meeting agenda. In others, the risk is more serious, such as processing customer data, HR information, financial data, or confidential documents in a public tool.
Avoid an overly harsh reaction. Most of these uses aren’t malicious. Teams are trying to save time. They’re testing. They’re bypassing inefficiencies. They’re responding to an urgent need. Shadow AI is often a valuable weak signal: it reveals where the company lacks tools, fluidity, or AI automation.
2. Why shadow AI emerges in companies
Shadow AI rarely appears by chance.
The first reason is simple: business teams need to move fast. They have targets, clients to serve, cases to process, and reports to produce. When an AI tool can save thirty minutes on a tedious task, the temptation to use it immediately is strong.
The second reason is accessibility. In the past, automating a process required an IT project, a budget, a timeline, and developers. Today, an employee can open ChatGPT, connect a no-code tool, write a prompt, import a file, and get results in minutes.
The third reason is IT team saturation. In many SMEs, mid-sized companies, and scale-ups, IT is already managing security, support, licenses, integrations, business projects, migrations, and technical debt. Not every small request can be addressed quickly.
There’s also a gap between existing software and on-the-ground reality. An ERP, CRM, or business tool covers the official process. But it doesn’t always address daily pain points: copying data between tools, summarizing conversations, categorizing requests, preparing a summary, checking an attachment, or drafting a document.
Finally, leadership often asks teams to “use AI” without providing a clear operational framework. Teams hear the message. They experiment. But without AI governance, everyone moves forward in their own way.
Shadow AI is therefore more a symptom than a cause. It reveals a tension between business needs, expected speed, and the organization’s ability to provide secure solutions.
3. The real risks of shadow AI
Shadow AI isn’t automatically dangerous. But it creates risks when no one knows what’s being used, with what data, for what purpose, and with what level of control.
The scale of the phenomenon is now measurable, and it can’t be dismissed as a marginal issue. The 2025 annual report by 1Password, based on a survey of 5,200 office workers across six countries, found that 52% had downloaded applications without IT approval and 42% bypassed IT to boost productivity. On AI specifically, 27% of French employees reported using unapproved tools, a figure comparable to the US (25%), even though France is the country in the sample where traditional shadow IT is the least widespread. In other words, the progress made in managing traditional tools has not extended to AI. Study: 1Password 2025 annual report.
The first risk is data leakage or misuse of sensitive information. A simple example: a sales team pastes customer data into a public AI tool to prepare a proposal. Even with good intentions, the company loses control over the data flow.
The second risk is the lack of traceability. If a business decision relies on an AI response, the company must be able to track which tool was used, what data was sent, what response was generated, and who validated it. Without this, the company loses the ability to maintain control.
The third risk is the quality of the responses. A model may produce a clear, seemingly useful answer that is actually false or incomplete. For internal reformulation, this may not matter. But for a client response, legal analysis, HR decision, or financial recommendation, the stakes are entirely different.
The fourth risk involves fragile automations. A team might create a Make or Zapier workflow with an AI component, then connect it to a CRM, email system, or invoicing tool. Initially, it works. Then a format changes, an API evolves, a prompt drifts, or an error slips into production. Without oversight, logs, or exception handling, AI automation becomes a grey area.
There’s also the risk of dependency on external tools, unmanaged access, proliferation of individual accounts, loss of internal knowledge, and technical debt.
An internal prototype can effectively address a real need. But if it’s impossible to maintain, secure, or integrate, it quickly becomes an organisational risk. This is exactly what we see with some prototypes built using vibe coding tools: the business idea is sound, but moving to production requires a proper technical overhaul. On this point, the issue aligns with the challenges of taking over AI-coded projects.
On the compliance side, pragmatism is key. GDPR applies as soon as personal data is processed. The CNIL reminds us that prompts can also contain personal data, and that protection must be considered from the design stage of AI systems. The AI Act, meanwhile, provides for a phased implementation, with certain obligations already in force and full application scheduled for 2 August 2026, with specific timelines depending on the case.
Two benchmarks help move beyond generalities on this timeline. From 2 August 2026, the European AI Office and the authorities of the Member States are responsible for implementing and enforcing the AI Act; the Office can request technical documentation for a model, assess it, impose corrective measures, and issue fines. Transparency obligations, meanwhile, come into force that same month: generated content must be identifiable as such, and certain content, such as deepfakes or texts published to inform on matters of public interest, must be clearly and visibly labelled. In practical terms, for an SME, this means shadow AI is no longer just a data leakage risk: producing generated content without disclosing it becomes a regulatory breach. Official framework: the European Commission’s AI regulatory framework, and for personal data, the CNIL’s AI dossier.
4. Why banning doesn’t work
Blocking all AI tools may seem reassuring. In practice, it rarely solves the problem.
When a ban is too broad, usage doesn’t necessarily disappear. It just becomes less visible. Employees use personal accounts. They switch to other tools. They avoid discussing it with IT. Dialogue shuts down.
The company then achieves the opposite of what it intended: less visibility, fewer field reports, more workarounds, and less ability to secure legitimate use cases.
The right goal isn’t “zero unauthorised AI”. It’s rather: visible, understood, prioritised, and secured usage.
This requires a mature approach. Not everything is approved. Not everything is blocked. Useful cases are distinguished from dangerous ones. Business teams are allowed to test, but within a clear framework. This is the foundation of healthy AI governance.
5. How to regain control without slowing teams down
Step 1: Map existing uses
The first step is to make usage visible. Identify the AI tools in use, the teams involved, use cases, data handled, expected gains, and risks.
The simplest approach is often to conduct brief interviews with business teams. Not as a police-style audit, but as field listening: “Which tasks take up too much of your time? Which AI tools are you testing? What actually helps you? What seems fragile?”
This mapping reveals where the real needs lie. It can be conducted as part of anAI framework, with a business, technical, and security perspective.
Step 2: Classify uses by risk level
Not all uses are equal.
Low-risk use may include reformulating public text, brainstorming, or summarising non-sensitive content. Medium-risk use may involve internal documents, non-sensitive business data, or decision support. High-risk use covers personal data, customer data, financial data, HR decisions, legal matters, health data, or critical automation.
This classification avoids vague debates. It allows quick approval for simple uses, framing for intermediate ones, and blocking or redesigning high-risk cases.
Step 3: Define simple rules
An effective AI policy must be understood by teams. Otherwise, it won’t be followed.
Rules should address concrete questions: Which data can be used? Which tools are allowed? Which uses require validation? Who is responsible for the outcome? When is human review mandatory? How should a use case be documented?
A good rule doesn’t need to be long. For example: “No identifiable customer data in unvalidated AI tools.” Or: “Any AI-generated response sent to a client must be reviewed by a human.” These rules are simple, yet they already change a lot.
Step 4: Provide secure alternatives
You can’t ask teams to stop using a helpful tool without offering a better option.
Alternatives can take several forms: an internal AI assistant, an Open WebUI-type interface, a RAG connected to the document base, tools with SSO and access management, or validated, maintainable automations.
An AI assistant connected to your data can answer internal questions with sources, access rights, logs, and refusal rules. A enterprise RAG can help teams retrieve reliable information from procedures, contracts, tickets, product sheets, or internal documents.
For workflows, a more robust approach may involve business automations with supervision, logs, error handling, and human validation for sensitive cases.
Step 5: turning the best use cases into real business tools
Some informal uses should be abandoned. Others deserve to be industrialised.
A heavily used prompt by a support team can become a business assistant. A makeshift automation in Make or Zapier can evolve into a robust n8n workflow. A prototype built with Lovable or Cursor can become a maintainable, documented application integrated into the IS.
This is where shadow AI becomes valuable. It acts as a real-world lab. It reveals where AI delivers tangible benefits in business. But to move from testing to production, you must address AI security, permissions, data, oversight, costs and maintenance.
6. The role of IT, business teams and management
Shadow AI cannot be handled by IT alone. It’s a shared responsibility.
Management sets priorities, acceptable risk levels and trade-offs. It avoids vague directives like “do AI” without a framework. It provides a clear roadmap.
Business teams identify pain points, repetitive tasks and use cases. They are best placed to determine where AI truly helps, and where it only adds complexity.
IT secures, integrates and industrialises. Its role is not just to say no. It must also provide the right environments, access, integrations and standards.
External partners can help audit, frame and build. The goal is to move faster without adding technical debt. This is often useful when a company wants to turn a prototype into a stable tool or modernise an existing application base with anapplication modernisation.
7. What a mature shadow AI approach looks like
A mature shadow AI approach isn’t a bloated, over-engineered system.
It’s more like a clear framework: AI use cases are mapped, validated tools are known, sensitive data is protected, access is controlled, logs exist, critical cases require human validation and high-ROI projects are prioritised.
Teams know what they can do on their own. They also know when to seek input from IT, security or business. Prototypes don’t linger indefinitely in a corner. The best ones follow a proper product trajectory: scoping, testing, evaluation, integration, deployment and maintenance.
This level of maturity keeps team momentum without creating a shadow IT. That’s the key. The goal isn’t to slow down digital transformation. The goal is to prevent AI from developing in isolation, uncontrolled, unmonitored and without collective memory.
From weak signals to actionable projects
Shadow AI isn’t just a risk. It’s also a valuable indicator of the company’s real needs.
A team using ChatGPT, Claude, Gemini, Copilot, Perplexity, Notion AI, Make, Zapier or Cursor rarely does so to bypass the organisation for fun. They’re trying to move forward. They’re highlighting that a process is too slow, a tool is missing, data is hard to leverage or a task deserves automation.
Organisations that listen to these signals, frame them and industrialise them will gain a real competitive edge. Those that simply ban them risk losing visibility into what their teams are actually doing.
At Scroll, we help companies audit their AI use cases, frame priority scenarios, deploy secure AI assistants, automate business processes and turn prototypes into robust tools. The idea isn’t to do AI for the sake of AI. The idea is to build useful, maintainable solutions integrated into your operational reality.
Related articles
Sep 22, 2026
Jev: the AI model that decides instead of writing
Launched in September 2026 by TypeSafe AI, Jev does not generate text: it returns typed, calibrated decisions. What it is, what it costs, and three use cases.
Sep 07, 2026
How much does an AI project cost, from POC to production?
The model price is not the point. Where the budget actually goes, how to calculate the API versus dedicated server threshold, and what makes it slip.
Aug 28, 2026
AI Act: what actually applies since 2 August 2026
The Digital Omnibus pushed high-risk obligations to December 2027. What already applies, what was postponed, and what to do in between.