Shadow AI: the artificial intelligence your company is already using and doesn't control


Shadow AI: a inteligência artificial que a sua empresa já usa e não controla

Someone in your company used artificial intelligence today. They summarised a set of minutes, translated a proposal, asked for campaign ideas, pasted a spreadsheet into a chatbot to work out a budget variance. They didn't ask for permission and, in all likelihood, it never crossed their mind that permission was needed.

This isn't a discipline problem. It's the portrait of a technology that entered organisations through the staff door rather than the IT department's. In a PagerDuty survey conducted by Wakefield Research in April 2026 and published in June, two in three professionals admitted to having used AI tools at work in the belief that doing so breached company policy.

An UpGuard study put the figure above 80% for the use of unapproved tools, and only around half of workers say they know and understand their own company's AI policy. Often because that policy simply doesn't exist.

It's called Shadow AI. And the problem was never the technology, it's the invisibility.

What Shadow AI is

Shadow AI is the use of artificial intelligence tools, models or agents without the company knowing, authorising, recording or assessing them. For AI, it's the equivalent of what shadow IT was for software in the past decade: real adoption, with real value, happening outside the organisation's management perimeter.

01 o que e shadow ai

The difference from classic shadow IT is the speed and the type of exposure. Installing unapproved software took effort. Opening a browser tab, pasting in a contract and asking for a summary takes nothing at all, and it moves company information outside the business in seconds.

It doesn't start with bad intentions. It starts with a tight deadline.

The numbers are worth a close look, because they dismantle the idea that this is about a handful of reckless employees.

In the same PagerDuty survey, 89% of professionals already knew the AI tool from their personal life before using it at work, and 77% believe company restrictions are limiting their professional growth. Banning without offering an alternative doesn't eliminate the use: it pushes it into personal accounts, where the company loses all visibility.

02 o que vai para ia publica

This is where the risk stops being abstract. When 34% of professionals admit to having put customer data into a public AI tool and 31% financial information or confidential documents, what's at stake isn't just IT security. It's the GDPR: personal data processed by a processor nobody contracted, with no identified legal basis, with no idea where it's stored or whether it feeds a model's training. And it's also intellectual property – proposals, pricing, code, strategy – leaving the organisation with no record.

The gap between adopting and governing

The temptation is to treat this as a future topic. The data says otherwise: adoption has already happened, it's governance that has fallen behind.

03 adocao vs governance

In Portugal, the official picture is even more uncomfortable when set against these figures.

According to the European Commission's State of the Digital Decade 2026 report, only 11.5% of Portuguese companies say they use AI, against an EU average of 20%, with SMEs at 10.7% and large companies at 49%. But 'say' is the operative word. These surveys measure formal adoption, recognised by management. Actual use, happening in teams' browsers, is consistently higher than reported use. Shadow AI lives in precisely that gap.

From assistant to agent: the risk changes scale

So far we've talked about information going out. With the arrival of AI agents, the problem becomes what gets done. An assistant suggests a text that someone reviews before sending. An agent accesses systems, sends messages, creates records, updates spreadsheets and triggers integrations, often with the credentials of whoever set it up, without anyone having designed its limits.

04 agentes permissoes

The financial impact is already measurable. In IBM's Cost of a Data Breach 2026, the global average cost of a data breach was 4.99 million dollars, but breaches resulting from attacks in which the attackers used AI, already one in four malicious breaches, cost 6 million on average. On the other side of the equation, more than 20% of the organisations surveyed reported a breach that targeted their own AI models or applications, with the main causes being compromised APIs, applications or plug-ins (27%) and cloud misconfigurations in AI workloads (27%).

These are governance failures, not algorithm failures.

The AI Act is no longer a date in the future

A lot of people came away with the idea that the AI Act had been postponed. It was, in part, and it's important to understand what changed and what didn't. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, came into force on 27 July 2026 and pushed the technical requirements for Annex III high-risk systems back to 2 December 2027, and those for Annex I to 2 August 2028.

05 ai act calendario

What wasn't postponed: prohibited practices and the duty to support AI literacy have applied since February 2025, obligations relating to general-purpose models since August 2025, and the transparency obligations in Article 50 have applied since 2 August 2026 — in other words, if your company has a chatbot handling customers or publishes AI-generated content, the obligation to make that clear is already in force today.

06 ai act coimas

There's a nuance here worth pinning down, because it circulates badly explained: the ceiling of 35 million euros or 7% of turnover applies to prohibited practices. For the vast majority of companies, those that merely use AI systems, the relevant threshold is 15 million euros or 3%, covering breaches of deployer obligations and transparency obligations. For SMEs, startups and small mid-caps, the lower of the two figures applies, and the Omnibus reinforced the proportionality of penalties and simplified the documentation required.

In Portugal, ANACOM is the national market surveillance authority and single point of contact, and the protection of fundamental rights is spread across 14 public bodies designated under Article 77, with ANACOM ensuring cross-cutting coordination and the sector regulators issuing their own guidance. There isn't a single interlocutor: there's a map. All the more reason to get your house in order before anyone asks.

What's really at risk

Without visibility, a company loses control of five things at once:

  • Data: customer, employee and business information on platforms with no contract, no known location and no guarantees about reuse.
  • Access: tools and agents connected to email, CRM or drives through personal accounts that nobody revokes when the person changes role or leaves.
  • Decisions: recommendations that influence recruitment, credit, pricing or commercial priorities with no trace of how they were produced.
  • Compliance: AI Act and GDPR obligations that can't be demonstrated, because demonstrating requires records, and the records don't exist.
  • Continuity: critical processes that have come to depend on an automation set up by one person, in a personal account, with no documentation. It's a silent operational risk until the day that person leaves.

Where to start

The useful answer isn't a two-year project or a committee that meets quarterly to produce a manual nobody reads. It's a short, repeatable cycle that starts by making visible what already exists.

07 roteiro 4 passos

The step that changes everything is the first one, and it's simpler than it looks: ask. A five-field form sent to the teams — which tool do you use, for what task, with what data, on which account, how often — typically returns, within a week, a picture that no technical audit delivers as quickly. It's not a witch hunt; it's an inventory. And it works far better when it comes with the right message: the goal isn't to stop AI, it's to be able to authorise it safely.

From there, the rest follows: an owner for each system, a risk classification per use case, a short list of approved tools for the most common tasks, a simple channel for requesting new ones, and a quarterly review point.

Companies that do this almost always discover two things at once: risks they didn't know about, and valuable use cases that were hidden inside one team and could serve the whole organisation.

Get what we write

No fixed calendar: only when there is something worth your time.

Your email, nothing else. We do not ask for a name or a company.

You will receive it in English.

RelatedAll articles