What shadow AI is
Public ChatGPT on a personal account. A consumer Claude session. An unsanctioned browser plugin. Gemini tried “just this once” on client text. The work happened. The enterprise record did not.
Why the PDF fails
Deadline pressure, missing licences, and a tool that is simply better at a narrow task will route around the official Copilot tenant. Security then finds the pattern in a DLP hit or a screenshot after the fact, disconnected from every other AI event in the firm.
On the same control loop
Untracked and policy-relevant use is observed, detected, traced, scoped, and proved on the same loop as sanctioned tools. Policy on the row includes shadow AI. The partner sees the exception next to the work.
One trail, two kinds of use
A shadow event still needs attribution: who, which system, what was asked, which policy should have applied. If those rows live in a different product, they will not be in the export when a client asks what AI touched the matter.
- Sanctioned Copilot and enterprise ChatGPT on the same log as unsanctioned visits.
- Policy label visible on the row.
- Hash-chain export that includes the exceptions.
Questions
Related
