Skip to content

Artificial intelligence · 3 September 2026

Shadow AI: the risk that enters the company without authorisation

Unauthorised tools, agents that execute and models that accelerate the attacker. The risk no longer waits for the innovation committee.

By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.

Original text in Spanish. Read the original Spanish version

Two panels: on the left, Shadow AI risks without an inventory; on the right, governance, policy and rehearsal controls

Shadow AI is the use of models and agents that the organisation has not approved, has not contracted and cannot audit. It is not a whim of curious employees. It is a leak of context: contracts, code, client lists and legal doubts pasted into a box that is not under your governance.

Why it appears

Because it solves a task faster than the internal procedure. Prohibiting without offering an alternative does not work. Staff do not stop pasting text into a model; they stop telling security. The risk becomes invisible and therefore more expensive.

A real inventory, not a licence inventory

The inventory that matters is not that of purchasing. It is that of use. An innovation committee may have two contracted models and the company, twenty in personal browsers.

  • Which tools are used with company data, with or without a licence.
  • Which sensitive data have already left: contracts, code, client data, legal opinions.
  • Which models are authorised and under what processing contract.
  • Who has access and with what account: corporate, personal, shared.
  • Which tools only suggest and which already execute —agents with permissions.

To suggest is not to execute

Governing a chatbot that summarises a text is not the same as governing an agent that sends emails, changes configurations or calls production APIs. That distinction is already a board decision. The governance that does not make it will arrive late.

Control list for the CEO

  1. Do we have an honest inventory of tools in use, not that of licences purchased?
  2. Which data must never leave to a model, and who enforces it?
  3. Is there an official alternative good enough for the shortcut to stop being rational?
  4. Do we distinguish in writing between models that suggest and agents that execute?
  5. What happens if a confidential contract has already left —a rehearsal, not a hypothesis?
  6. Who answers to a regulator or a client if the company’s context is in someone else’s model?

A brief policy fits on one page: which data never leave, which models do, who answers. The rest is innovation theatre.

Hypothetical inventory example

  • Use: a text assistant in an analyst’s personal browser.
  • Data class: drafts of contracts and internal emails.
  • Permission: none. Personal account, without a processing contract.
  • Risk: the company’s context leaves to someone else’s model without a record.
  • Decision: official alternative, prohibited data and a consequence if it is repeated.

References

  • NIST Cybersecurity Framework. NIST. Accessed: 2026-09-04. El inventario de usos, datos y permisos se plantea como control de identificar y proteger, no como prohibición sin alternativa.

Related articles

Crises do not book an appointment. Preparation can start today.