Skip to content
Introducing Managed AI: governed AI for financial servicesRead moreAttend our webinar
/11 min read

What Is Shadow AI, and How Should Your Firm Govern It?

By Bill Ercolano, Chief Technology Officer, RFA

Somewhere in your firm this morning, someone used an AI tool that no one reviewed. They were not being reckless, and it would not have occurred to them that they were creating an exposure. They found something that made a slow part of their job faster, so they used it and did not think to mention it. That is shadow AI, and most of the firms we work with have considerably more of it than they realize. This article explains what shadow AI actually covers, why banning it tends to fail, what a regulated firm has at stake when it does not have visibility into AI usage, and how to build governance that is sustainable and enforceable.

Quick answer: Shadow AI is any use of AI tools, models, assistants, agents, or product features outside the environment a firm approves, monitors, and governs. It includes AI features inside already-approved software, personal accounts, browser extensions, coding assistants, and automations that act on firm data. A firm has shadow AI whenever it cannot establish what data went in, what the model did with it, what came back out, and who is accountable for the result.

What Shadow AI Covers Beyond the Public Chatbot

When people hear the term shadow AI, they may picture an employee with a public chatbot in a second window. While that does happen, it is easy to catch and a small part of a bigger problem.

The instances of shadow AI that create real exposure are harder to see:

  • AI features inside software you already approved, including productivity suites, CRMs, and document management. Many programs have those features on by default, so there is no trigger for a security review
  • Personal accounts and unmanaged devices, where your corporate policy has no reach or visibility
  • Browser extensions and desktop applications that send page content to a model in a way that is not obvious to the user
  • Coding assistants wired into source code or production systems, and API usage funded by individual teams
  • Vendor products that add AI functionality mid-contract, so procurement does not catch it
  • Copy and paste behavior, which is close to invisible without data loss prevention and endpoint controls
  • Agents and automations that reach across systems, touch client data, and are able to take action

The assessment of an AI tool has four parts:

  1. Where the data went
  2. What the model did with it
  3. What came back out
  4. Who is accountable for the output

When a firm cannot answer any one of these four questions, it is dealing with shadow AI, regardless of the tool's pedigree.

Why Shadow AI Is Not a Repeat of Shadow IT

Anyone who lived through shadow IT will recognize the repeated pattern of people adopting tools faster than the firm can approve them. For years, people purchased individual file sharing accounts because the sanctioned options were slow to arrive or annoying to use. When you do not give people an approved way to do something they genuinely need to do, they tend to find their own solution and will rarely tell you about it. The lesson carries over for AI: the problem only ends when an approved solution is good enough for people to stop looking elsewhere.

What makes AI a different conversation is what happens after the data moves. A model can absorb a hundred pages of confidential material and reshape it in seconds. Most users have no sense of where that material sits afterward, whether it is retained, or what it might train. The output arrives looking finished and authoritative even when it is incomplete, biased, or fully hallucinated.

Firms also underestimate the speed at which AI is developing. The same system that drafts a client email this quarter will be sending it the next, along with updating records and approving transactions. Shadow IT exposed you to data leakage. Shadow AI exposes you to data leakage alongside decision integrity, regulatory scrutiny, intellectual property risk, and reputational damage. We have written separately about how the threat model itself has changed.

The governance lessons transfer, but they have to run on much faster cycles. Annual policy reviews were thin coverage for shadow IT; for AI they are not coverage at all.

Why Banning AI Fails, and What Works Instead

If we told you to ban Excel, you would laugh. Spreadsheets carry risk and firms have lost deals and reputation to bad formulas, but no one believes the answer is to ban Excel. The value of the tool is clear and the risk is understood and managed. The value of AI is just as real, but the risk is less familiar.

Very few firms outright ban AI, but we often see de facto bans that result from the absence of clear policy. A tool gets blocked at the network and no one revisits it. An approval request sits with a risk committee for a quarter. No one says no, and no one quite says yes. The effect is the same and produces three foreseeable outcomes.

  1. Usage continues and becomes invisible.
  2. You lose ground against competitors who were early adopters.
  3. And individual teams begin deciding which data is safe to paste into which tool.

The firm did not eliminate the risk, but instead handed decision-making to individual users.

A ban has a narrow and legitimate place, covering specific tools whose terms are unacceptable. What does not hold is a general posture of restraint with no visible timeline for adoption.

The better approach is a short set of rules people can follow. Here are the approved tools. Here is what you can use them for. Here is what data is prohibited. Here is the fast path to request a new use case. What it takes to stand that up is covered later in this article.

Five Exposures Firms Discover Too Late

Data leakage. Sensitive client, employee, and financial information reach an external provider and get retained under terms your firm never agreed to.

Incorrect or unsupported decisions. Model output can be both confident and wrong. When it incorrectly informs advice, pricing, or financial reporting, there is reputational risk for your firm.

Actions without approval. AI can now send communications, update records, or approve transactions on its own. A bad draft can be fixed; a sent email cannot be recalled.

Lack of auditability. When you cannot reconstruct the data, model, or controls used, defending that decision to an auditor becomes considerably harder. The SEC named AI directly in its fiscal year 2026 examination priorities and will assess if firms have adequate policies and procedures to supervise their use.

Third party risk. Core processes and sensitive data can end up inside a provider that was never assessed for contract terms, security posture, or resilience.

We see these exposures across our client base. We have caught employees uploading company data into unapproved AI tools and stopped them before anything left the environment. In more than one case, had the upload gone through, the firm would have needed to notify regulators that client data had leaked. The distance between a blocked attempt and a reportable incident came down to visibility, and very little else.

What a Well-Governed AI Program Requires

A well-governed AI program does three jobs: it explicitly defines accountability, maintains an accurate inventory of tools, and applies controls to decision-making. Eight components support those three jobs.

Ownership, which defines clear roles and responsibilities. Name executive sponsors and business owners for your use cases and map a cross-functional structure with decision rights across technology, security, legal, compliance, and operations.

Product inventory to define a clear scope. Keep a current record of approved tools, models, vendors, use cases, data types, and owners. Record which programs can act without human approval.

Risk tiers, which decide where review effort and resources go.

  • Low: brainstorming and drafting internal content; should clear in days
  • Medium: knowledge retrieval, code assistance, and controlled workflow automation
  • High: client-facing communications, regulated decisions, and anything autonomous; requires heavier testing, documented approvals, and human review

Data governance that defines which data can enter which environments. Classification, data loss prevention, access controls, encryption, retention limits, and approved connectors enforce those rules.

Vendor and model controls that hold providers to your standards. Contracts should contain data-use terms, restrictions on training against your data, security review, resilience expectations, and an exit plan if the provider changes direction.

Human accountability to maintain responsibility. AI can augment processes but does not transfer ownership, and someone must be responsible for material outcomes.

Testing and ongoing monitoring to catch issues before and after deployment. Evaluate accuracy, bias, hallucination risk, security, privacy, prompt injection, drift, and business impact on an ongoing basis.

A quick and approved path for people to experiment. A lightweight intake process and a working sandbox allows promising ideas to be tested quickly.

A Practical, Phased Approach

Most firms are not starting from zero. AI is already in use somewhere, and the work is to bring it inside a governed path. To create a program with proper controls in place, a phased approach ensures the right safeguards are set up at each step.

  1. Establish an AI governance baseline immediately. Create a cross-functional AI steering group with explicit decision rights. Define policies for approved tools, acceptable use, restricted data, human oversight, records, vendors, and incident reporting.
  2. Discover current AI usage. Identify sanctioned and unsanctioned AI tools through procurement records, software discovery, endpoint and browser visibility, network signals, developer tooling, and business interviews. Approach this as discovery rather than a punitive exercise, so people are honest about how they are working.
  3. Publish approved, usable alternatives. Provide secure enterprise AI tools with appropriate contractual protections, identity controls, data settings, logging, and role-based access. If the approved experience is poor, shadow AI will persist.
  4. Create a data-and-use-case risk framework. Classify use cases on data sensitivity, client or regulatory impact, level of automation, ability to explain and audit results, consequences of error, and third-party risk. Assign controls and required approval for each tier.
  5. Start with high-value, lower-risk use cases. Knowledge search on internal content, document summarization in a controlled environment, meeting preparation, and software development assistance all qualify. Prove value and mature controls before moving to high-impact decisions or autonomous agents.
  6. Add controls for agents. For any AI that can access systems or take action, require least-privilege access, limits on the actions it can perform, approvals for sensitive actions, logs and audit trails, spending and transaction limits, kill switches, and rollback procedures.
  7. Design for auditability. For material use cases, retain the records a regulator or auditor will ask for: model and provider, version, decision context, source data lineage, approvals, human review, outputs, and actions taken.
  8. Train people in practical judgment. Provide employees with clear guidance: what they can use, what they cannot paste into AI, how to identify sensitive data, when to seek approval, how to challenge AI output, and how to report a suspected issue.
  9. Monitor continuously and adjust. AI governance should evolve with the technology and the firm's usage. Review tool inventory, incidents, exceptions, model changes, control effectiveness, and high-risk use cases on a regular cadence.

No firm can eliminate AI risk. The goal is to make responsible AI easier to use than unsanctioned AI, while maintaining visibility, accountability, and controls.

Frequently Asked Questions

How does a firm discover AI usage that is already happening?

Firms can find AI use through several paths. Check procurement and expense records for tools bought on a card. Use software discovery and endpoint visibility to see which features are enabled inside approved applications. Review network signals and developer tooling for coding assistants and API usage, then interview the business to fill the remaining gaps. Run this as a discovery process so people answer honestly.

What data should never be entered into an unapproved AI tool?

Any data that identifies a person, exposes a confidential relationship, creates a regulatory obligation, or materially affects a decision is off limits. For an investment firm that covers:

  • Client data: names, addresses, government identifiers, account numbers, balances, transactions, tax records, and payment data
  • Confidential information: nonpublic personal information, client communications, and material nonpublic information such as earnings, deal activity, research, and trading strategy
  • Legal and HR records: privileged advice, litigation material, health and biometric data, compensation, and performance reviews
  • Technical material: credentials, API keys, system configuration, source code, architecture diagrams, and vulnerability findings
  • Regulated decisions: any data feeding a decision on credit, insurance, employment, underwriting, or suitability

Should a firm delay AI adoption until security concerns are resolved?

Security concerns are valid, but delaying indefinitely is a risk of its own. If the firm does not offer a safe path, employees will find their own, which costs the firm both competitiveness and control. Start smaller instead. Select a limited number of approved enterprise tools, begin with low-risk and high-value use cases, keep people accountable for material outputs, and use data classification to define what can and cannot be used. Bring legal, privacy, security, compliance, and business owners into the design early, then measure adoption, value, incidents, and control effectiveness.

Does the SEC examine how investment firms use AI?

Yes, the SEC examines how registrants use AI. The Division of Examinations named AI in its fiscal year 2026 examination priorities and will review the accuracy of what firms claim about their AI capabilities. It will also assess whether they have adequate policies and procedures to supervise AI use, including in fraud prevention and detection, back-office operations, anti-money laundering, and trading. Cybersecurity governance, data loss prevention, and access controls appear separately in the same document.

Let's talk about your
technology needs.

Speak with an RFA advisor about IT, cybersecurity,
AI, and compliance for financial services.