Shadow AI: what it is, and why you should care

Shadow AI is the AI your team already uses that you cannot see — models, agents and tool connections wired into live systems, outside any oversight.

Shadow AI is the AI your team is already using that you cannot see. Not the pilot the CTO approved. The dozen quiet connections underneath it: a personal chatbot account holding last quarter's numbers, an agent wired straight into the production database, a tool server someone spun up on a Tuesday and never mentioned. It is happening right now, in every organization that gave people capable AI, and almost none of it is written down.

That is not a failure of policy. It is what happens when the most useful technology in a decade is also the easiest to adopt. People do not ask permission to be more productive.

What shadow AI actually is

Shadow AI is any use of AI inside your organization that runs outside its central visibility and control. It lives on a spectrum.

At the mild end: employees using personal ChatGPT or Claude accounts for work, pasting in customer emails, contracts and code to get through the day faster. The data leaves, quietly, and you have no record of it.

At the sharp end: AI agents connected directly to your real systems. Someone gives their assistant access to the CRM, the code repository, the internal API, the database — because it makes the agent genuinely useful. Each of those connections is a live credential handed to software that acts on the employee's behalf. None of it appears in a procurement system, a SaaS bill, or an access review.

The mild end is a data-leakage problem you have seen before. The sharp end is new, and it is the one worth losing sleep over.

It is not shadow IT with a new name

The instinct is to file this under shadow IT and move on. That undersells it in three ways.

These connections act, they don't just store. Shadow IT was largely unsanctioned apps holding data. A shadow AI connection can read and write to the system it touches — send the email, merge the branch, update the record, run the query. The failure mode is not "data sat somewhere it shouldn't." It is "software took an action nobody authorised."

They carry live credentials. Connecting a tool to an agent means handing it a key, and most connections grant broad access by default because narrow access is more work. The agent meant to read one calendar can often read every calendar and send mail as you. The blast radius of any single mistake is the whole system behind the key.

They appear faster than you can catalogue them. Adding a tool to an AI assistant is one click, using the Model Context Protocol (MCP), the emerging standard for wiring tools to agents. MCP is excellent, and that ease is exactly why people wire up their own servers against sensitive systems — shadow MCP, the AI-era version of shadow IT, except the connections can write and they multiply weekly.

Shadow ITShadow AI
What it isUnsanctioned apps and accountsUnsanctioned models, agents and tool connections
What it doesMostly stores or moves dataReads and writes to live systems
CredentialsApp loginsBroad, standing keys to internal systems
Speed of spreadProcurement-pacedOne click per connection
Who creates itAnyoneOften your highest-access staff

Why you should care

Three reasons, in order of how quickly they will find you.

The blast radius is real and it is invisible. An over-privileged agent does not need to be malicious to do damage — a confused instruction, a poisoned web page, or a tool that does more than expected is enough. These are not hypotheticals. In one documented case a Supabase MCP server could be manipulated into exposing an entire SQL database; in another a GitHub MCP setup could be steered into private repositories. Same root cause both times: broad access, no boundary, no record.

You cannot answer "what happened?" After any incident the first question is simple — what did it do, and to what. With most AI setups there is no single record of which agent called which tool, on whose behalf, with what result. That gap is a problem long before a breach. It is what a compliance team asks on an ordinary Tuesday, and "we're not sure" does not survive an audit.

It concentrates exactly where access is deepest. The employees wiring up the most AI are usually your best ones — the engineers and admins who already hold the widest access. So exposure runs deepest precisely where a mistake costs the most. Shadow AI is not a fringe problem at the edges of your org. It is densest at the centre.

You cannot govern what you cannot see

Every response to shadow AI — policy, training, a governed control plane — depends on one thing you almost certainly do not have yet: an accurate picture of what is already connected. A policy memo cannot scope a connection it has never heard of. A control plane cannot govern an agent it cannot find.

So the first move is not a committee. It is a look. Connor runs a read-only scan of your organization: it inventories the AI tools, agent connections and MCP servers on each device and maps them to the systems and credentials they can reach. Secrets are flagged as present, never read, never sent. You get one dashboard showing every connection, mapped to every person, and where the risk concentrates.

That picture is where governance starts — and usually it is the first time anyone has seen the whole board. See how the scan works, or use the form below to start one. Nothing gets installed to look.

Frequently asked questions

What is shadow AI?
Shadow AI is any use of AI inside an organization that happens outside its central visibility and control. It ranges from employees pasting data into personal chatbot accounts to engineers wiring AI agents directly into internal databases and APIs, all without IT or security knowing it exists.
How is shadow AI different from shadow IT?
Shadow IT was mostly unsanctioned apps that stored or moved data. Shadow AI connections can act: they hold live credentials and can read and write to the systems they touch. They also appear far faster, because adding a tool to an AI agent is a single click rather than a procurement cycle.
How do you find shadow AI?
You discover it, because you cannot ask a directory for it. A read-only inventory of each device surfaces the AI tools, agent connections and MCP servers already running, and maps them to the systems and credentials they can reach — without collecting any secrets.
James ZhaoCo-founder, Connor

James is the co-founder Connor. After a corporate career at Barclays and KPMG as a software engineer, he built and exited his own software company. He has spent the last three years at the forefront of AI, and the most recent of them building AI-native products and the agent platform behind Connor.

Kashif RafiqCo-founder, Connor

Kashif is co-founder of Connor. He spent his career inside two of the most heavily monitored industries there are, investment banking at Goldman Sachs and energy at BP, working on the security and technology systems that keep regulated communications and data under control. He now builds the systems that let companies publish, permit, and observe what their AI agents can do.

All posts

Find out what your team has already built.