By Olivia Dubois
·
March 19, 2026
Shadow AI refers to the use of artificial intelligence tools and services by employees within an organization without the approval, oversight, or even knowledge of the IT department or Chief Information Security Officer (CISO).
Shadow AI is an extension of the Shadow IT concept, but with specific characteristics that make it harder to detect and potentially more dangerous.
| Factor | Shadow IT | Shadow AI |
|---|---|---|
| Detection | Invoices, network traffic, SSO | Often invisible (free, web-based tools) |
| Data | Stored on the platform | Potentially used to train models |
| Speed of adoption | Weeks/months | Minutes |
| Regulation | GDPR, NIS2 | GDPR + EU AI Act + NIS2 + DORA |
| Irreversibility | Data can be recovered | Data potentially embedded in AI models |
Shadow AI exposes organizations to sanctions under multiple regulations:
The CNIL explicitly recommends maintaining an AI processing register and conducting impact assessments for large-scale personal data processing.
Shadow AI governance rests on three pillars:
For a comprehensive guide on this topic, see our Shadow AI in the workplace guide 2026.
Shadow AI Expert & Chief AI Officer
Olivia Dubois is Shadow AI Expert and Chief AI Officer at Avanoo. An HEC Paris graduate and former BCG consultant, she helps enterprises detect and govern Shadow AI and Shadow IT.
See how Avanoo can map your SaaS and AI landscape, reduce risk, and optimize costs. A reliable platform with dedicated human support.