Transom

Shadow AI

Also called: shadow AI, unsanctioned AI

AI tools, agents, and integrations that people run without the knowledge or approval of security or IT.

A developer spins up an MCP server on a work laptop. A team signs up for an agent product with a personal card. Someone wires a company data source into a side-project assistant. None of it is inventoried, so none of it is monitored, patched, or offboarded.

Why it matters

You cannot secure what you don't know exists. Shadow AI is how sensitive data ends up flowing through unvetted models, how exposed MCP servers and gateways end up on the internet under a company's IP space, and how a departed employee's agent keeps running. Discovery — including external fingerprinting of your own address space — is the first control.

Exposure map

Live counts of instances showing this pattern will appear here once the exposure map is collecting data.

Related terms

Sources

Added 2026-09-02. Last reviewed 2026-09-08. Definitions in this space are evolving; entries are dated so revisions stay legible.