Skip to content
Glossary · Industry term

Shadow AI

Also known as: unsanctioned AI, ungoverned AI

AI capability operating outside IT governance visibility. The 2024 framing meant unsanctioned tools — workers pasting data into consumer chatbots outside IT review. The 2026 pattern is different: agentic capability silently activating inside already-approved tools through configuration changes the original procurement did not anticipate, such as Custom GPT actions, Copilot custom agents, and MCP server connections from approved IDEs.

How this publication uses it

Discovery has to look at capability state, not vendor identity. An inventory that asks which AI vendors the organisation has approved misses the deployments where the vendor was approved but the agentic capability arrived later through configuration. That distinction is the load-bearing claim of AM-036, reviewed on a 60-day cadence.

Tracked claims that use this term

Articles that analyse this term

Primary sources

Vigil · 80 reviewed