What Is Shadow AI, and How Should Your Firm Govern It?
By Bill Ercolano, Chief Technology Officer, RFA
By Bill Ercolano, Chief Technology Officer, RFA
Somewhere in your firm this morning, someone used an AI tool that no one reviewed. They were not being reckless, and it would not have occurred to them that they were creating an exposure. They found something that made a slow part of their job faster, so they used it and did not think to mention it. That is shadow AI, and most of the firms we work with have considerably more of it than they realize. This article explains what shadow AI actually covers, why banning it tends to fail, what a regulated firm has at stake when it does not have visibility into AI usage, and how to build governance that is sustainable and enforceable.
Quick answer: Shadow AI is any use of AI tools, models, assistants, agents, or product features outside the environment a firm approves, monitors, and governs. It includes AI features inside already-approved software, personal accounts, browser extensions, coding assistants, and automations that act on firm data. A firm has shadow AI whenever it cannot establish what data went in, what the model did with it, what came back out, and who is accountable for the result.
When people hear the term shadow AI, they may picture an employee with a public chatbot in a second window. While that does happen, it is easy to catch and a small part of a bigger problem.
The instances of shadow AI that create real exposure are harder to see:
The assessment of an AI tool has four parts:
When a firm cannot answer any one of these four questions, it is dealing with shadow AI, regardless of the tool's pedigree.
Anyone who lived through shadow IT will recognize the repeated pattern of people adopting tools faster than the firm can approve them. For years, people purchased individual file sharing accounts because the sanctioned options were slow to arrive or annoying to use. When you do not give people an approved way to do something they genuinely need to do, they tend to find their own solution and will rarely tell you about it. The lesson carries over for AI: the problem only ends when an approved solution is good enough for people to stop looking elsewhere.
What makes AI a different conversation is what happens after the data moves. A model can absorb a hundred pages of confidential material and reshape it in seconds. Most users have no sense of where that material sits afterward, whether it is retained, or what it might train. The output arrives looking finished and authoritative even when it is incomplete, biased, or fully hallucinated.
Firms also underestimate the speed at which AI is developing. The same system that drafts a client email this quarter will be sending it the next, along with updating records and approving transactions. Shadow IT exposed you to data leakage. Shadow AI exposes you to data leakage alongside decision integrity, regulatory scrutiny, intellectual property risk, and reputational damage. We have written separately about how the threat model itself has changed.
The governance lessons transfer, but they have to run on much faster cycles. Annual policy reviews were thin coverage for shadow IT; for AI they are not coverage at all.
If we told you to ban Excel, you would laugh. Spreadsheets carry risk and firms have lost deals and reputation to bad formulas, but no one believes the answer is to ban Excel. The value of the tool is clear and the risk is understood and managed. The value of AI is just as real, but the risk is less familiar.
Very few firms outright ban AI, but we often see de facto bans that result from the absence of clear policy. A tool gets blocked at the network and no one revisits it. An approval request sits with a risk committee for a quarter. No one says no, and no one quite says yes. The effect is the same and produces three foreseeable outcomes.
The firm did not eliminate the risk, but instead handed decision-making to individual users.
A ban has a narrow and legitimate place, covering specific tools whose terms are unacceptable. What does not hold is a general posture of restraint with no visible timeline for adoption.
The better approach is a short set of rules people can follow. Here are the approved tools. Here is what you can use them for. Here is what data is prohibited. Here is the fast path to request a new use case. What it takes to stand that up is covered later in this article.
Data leakage. Sensitive client, employee, and financial information reach an external provider and get retained under terms your firm never agreed to.
Incorrect or unsupported decisions. Model output can be both confident and wrong. When it incorrectly informs advice, pricing, or financial reporting, there is reputational risk for your firm.
Actions without approval. AI can now send communications, update records, or approve transactions on its own. A bad draft can be fixed; a sent email cannot be recalled.
Lack of auditability. When you cannot reconstruct the data, model, or controls used, defending that decision to an auditor becomes considerably harder. The SEC named AI directly in its fiscal year 2026 examination priorities and will assess if firms have adequate policies and procedures to supervise their use.
Third party risk. Core processes and sensitive data can end up inside a provider that was never assessed for contract terms, security posture, or resilience.
We see these exposures across our client base. We have caught employees uploading company data into unapproved AI tools and stopped them before anything left the environment. In more than one case, had the upload gone through, the firm would have needed to notify regulators that client data had leaked. The distance between a blocked attempt and a reportable incident came down to visibility, and very little else.
A well-governed AI program does three jobs: it explicitly defines accountability, maintains an accurate inventory of tools, and applies controls to decision-making. Eight components support those three jobs.
Ownership, which defines clear roles and responsibilities. Name executive sponsors and business owners for your use cases and map a cross-functional structure with decision rights across technology, security, legal, compliance, and operations.
Product inventory to define a clear scope. Keep a current record of approved tools, models, vendors, use cases, data types, and owners. Record which programs can act without human approval.
Risk tiers, which decide where review effort and resources go.
Data governance that defines which data can enter which environments. Classification, data loss prevention, access controls, encryption, retention limits, and approved connectors enforce those rules.
Vendor and model controls that hold providers to your standards. Contracts should contain data-use terms, restrictions on training against your data, security review, resilience expectations, and an exit plan if the provider changes direction.
Human accountability to maintain responsibility. AI can augment processes but does not transfer ownership, and someone must be responsible for material outcomes.
Testing and ongoing monitoring to catch issues before and after deployment. Evaluate accuracy, bias, hallucination risk, security, privacy, prompt injection, drift, and business impact on an ongoing basis.
A quick and approved path for people to experiment. A lightweight intake process and a working sandbox allows promising ideas to be tested quickly.
Most firms are not starting from zero. AI is already in use somewhere, and the work is to bring it inside a governed path. To create a program with proper controls in place, a phased approach ensures the right safeguards are set up at each step.
No firm can eliminate AI risk. The goal is to make responsible AI easier to use than unsanctioned AI, while maintaining visibility, accountability, and controls.
Firms can find AI use through several paths. Check procurement and expense records for tools bought on a card. Use software discovery and endpoint visibility to see which features are enabled inside approved applications. Review network signals and developer tooling for coding assistants and API usage, then interview the business to fill the remaining gaps. Run this as a discovery process so people answer honestly.
Any data that identifies a person, exposes a confidential relationship, creates a regulatory obligation, or materially affects a decision is off limits. For an investment firm that covers:
Security concerns are valid, but delaying indefinitely is a risk of its own. If the firm does not offer a safe path, employees will find their own, which costs the firm both competitiveness and control. Start smaller instead. Select a limited number of approved enterprise tools, begin with low-risk and high-value use cases, keep people accountable for material outputs, and use data classification to define what can and cannot be used. Bring legal, privacy, security, compliance, and business owners into the design early, then measure adoption, value, incidents, and control effectiveness.
Yes, the SEC examines how registrants use AI. The Division of Examinations named AI in its fiscal year 2026 examination priorities and will review the accuracy of what firms claim about their AI capabilities. It will also assess whether they have adequate policies and procedures to supervise AI use, including in fraud prevention and detection, back-office operations, anti-money laundering, and trading. Cybersecurity governance, data loss prevention, and access controls appear separately in the same document.
Speak with an RFA advisor about IT, cybersecurity,
AI, and compliance for financial services.