Glossary · AI governance and risk

Shadow AI

The use of AI tools and services by staff without the organisation’s knowledge, approval or controls. Common examples include pasting work documents into public chat assistants or enabling AI features in software without review.

Why it matters

Shadow AI can expose confidential, personal or contractually restricted data to third parties, and create outputs that nobody has checked. It also signals unmet demand: people use unapproved tools because they find them useful.

Blanket bans tend to push usage out of sight. A more effective response pairs clear guidance with approved, well-configured tools that meet the same needs, plus technical controls where the risk is highest.

In practice

For example, a UK engineering consultancy might learn that staff are using public assistants to draft tender responses. It could provide an approved assistant with data retention switched off and access restricted to its bid library, then update its policy and training.

Where Rodan fits

Rodan builds governed internal AI tools that give teams a safe alternative, through AI and Decision Systems. See also how to write an AI policy for your organisation.

Related terms