By Olivia Dubois
·
March 20, 2026
Shadow IT refers to all technologies, software, applications, and IT services used within an organization without the approval, knowledge, or oversight of the IT department.
The term covers everything from SaaS applications subscribed to directly by business units (bypassing IT procurement), to free tools used by individual employees, to cloud resources provisioned outside of official processes.
Shadow IT takes many forms in everyday work:
Shadow IT is not an act of malice. It stems from legitimate needs:
Sensitive data (customer records, contracts, source code, financial data) flows through unaudited platforms, outside the company's security perimeter. In the event of a breach, the organization has no leverage to respond.
GDPR requires organizations to identify and document all personal data processing activities. NIS2 and DORA regulations demand a complete mapping of ICT suppliers. Shadow IT makes meeting these obligations impossible.
Decentralized SaaS subscriptions lead to redundancies (multiple tools for the same purpose), unused licenses, and suboptimal contract negotiations. According to Avanoo data, companies discover on average 8.65 times more tools than they thought they were using.
Unmanaged tools don't receive security updates, backups, or IT support. A tool abandoned by its vendor can cripple a critical business process.
The first step is to make the invisible visible. Platforms like Avanoo combine multiple detection sources (SSO, proxy, browser extension, billing data) to provide a complete inventory of applications in use.
Each discovered application must be evaluated: type of data processed, hosting location, privacy policy, and risk level. Classification helps prioritize actions.
Rather than banning tools outright, establish a framework. Three categories: approved, restricted (limited use with conditions), and prohibited (with an approved alternative offered). Policy transparency reduces workarounds.
If employees bypass official tools, it's often because those tools don't meet their needs. Providing validated, fit-for-purpose alternatives naturally reduces Shadow IT.
Shadow IT is not a problem you solve once. New tools appear every week. Continuous analytical monitoring is essential.
Shadow AI is a specific and emerging form of Shadow IT that involves artificial intelligence tools. It stands out due to its rapid adoption, the difficulty of detection (free, web-based tools), and the unique risks tied to AI models potentially being trained on the data entered by users.
Shadow AI Expert & Chief AI Officer
Olivia Dubois is Shadow AI Expert and Chief AI Officer at Avanoo. An HEC Paris graduate and former BCG consultant, she helps enterprises detect and govern Shadow AI and Shadow IT.
See how Avanoo can map your SaaS and AI landscape, reduce risk, and optimize costs. A reliable platform with dedicated human support.