Shadow AI Is the New Shadow IT, Only Faster
Stacked Zero Trust: Post 10 of 13
Every architectural conversation about AI in the enterprise eventually runs into a quieter, uglier conversation about what is actually happening on the network. The three-layer model is useful for thinking about the AI an organisation has deliberately deployed and consciously decided to govern. It is less comfortable when confronted with the AI that arrived without anyone deploying it at all: pasted into a personal-account chatbot by a marketing manager racing a deadline, embedded as a feature in a SaaS application no one realised had AI underneath it, or downloaded as a copilot extension by a developer trying to get a release out the door.
This is shadow AI, and it occupies much the same place in Stacked Zero Trust that shadow IT occupied in the older perimeter model. It is the part of the estate the architecture cannot see, and therefore cannot meaningfully govern.
The similarity is real, but it only goes so far.
The shadow IT problem unfolded over years. SaaS adoption spread at a pace that allowed discovery tools, governance programmes and security teams to adapt alongside it. Shadow AI is moving on a fundamentally different timescale. Capabilities that were research previews eighteen months ago are now being used daily by a large majority of employees, often through personal accounts and often with sensitive corporate information. The discovery problem, the data-exfiltration problem and the governance problem all look familiar, but the velocity does not, and that difference in velocity changes what an effective response looks like.
What the numbers actually say
Before getting into the architecture, it is worth spending a moment on the scale of the problem, because this is where many strategy discussions still understate what is happening.
The industry surveys vary in methodology, but they increasingly converge around numbers that would have sounded alarmist only a few years ago. Roughly 80 percent of workers report using unapproved AI tools in some form. Around 45 percent of US workers admit to using AI at work without disclosing it, while public AI traffic inside enterprises continues to grow at extraordinary rates. Significant proportions of users report entering company information into public AI tools, and many acknowledge doing so without formal approval. At the same time, governance remains immature, with a minority of organisations having comprehensive AI-governance frameworks in place.
The most important number, however, is not necessarily the most dramatic one.
By 2026, the majority of employee interactions with AI are expected to occur through capabilities embedded within existing business applications rather than through standalone AI products. That changes the nature of the discovery challenge. Most shadow AI is no longer someone deliberately bypassing policy to use a prohibited tool. Increasingly it is someone using a sanctioned application that quietly acquired AI functionality after the security review was completed.
The “shadow” is no longer necessarily outside the estate. It is increasingly hidden inside it.
That distinction matters because the controls developed to manage shadow IT were largely built around identifying unsanctioned applications. The harder problem now is identifying sanctioned applications whose capabilities have changed since they were approved.
There is another finding that deserves attention. Organisations that attempt outright prohibition generally discover that prohibition and adoption are not inversely related. Employees continue using the tools because the underlying need does not disappear. The effect is often to push usage further away from visibility rather than eliminate it altogether, making the problem harder to observe and therefore harder to govern.
Why it isn’t quite the same problem as shadow IT
The instinctive response is to treat shadow AI as shadow IT version two, apply the traditional playbook, and expect broadly similar results. Discover what exists. Categorise it. Approve some of it. Block the rest. Educate users and repeat.
That instinct is half-right. The discovery challenge is familiar. The governance challenge is familiar. Even the user behaviour has echoes of the same pattern security teams have dealt with for years. The danger lies in assuming that familiarity means equivalence, because the characteristics that made shadow IT difficult have all returned in altered form.
The first difference is the rate at which the landscape changes. Shadow IT grew on the cadence of SaaS launches and adoption cycles. New services appeared, users found them useful, and organisations gradually became aware of their existence. Shadow AI operates on a different timetable altogether. Model releases arrive continuously. Plugin ecosystems evolve weekly. AI capabilities appear inside applications that have already passed procurement and security review. A CASB designed to discover previously unknown applications does not automatically tell you when an approved platform quietly acquires generative-AI functionality in its next release. The problem is no longer confined to discovering products. Increasingly it is about discovering capabilities inside products whose risk profile has changed since they were last assessed.
The second difference is the nature of the data-exfiltration path. With shadow IT, information was often moving somewhere it should not have gone, but the destination was usually a storage platform of some sort. The data might have been exposed, copied or retained, yet it still existed within a relatively familiar model of movement and retention. Shadow AI changes that picture. Information entered into an AI platform may be retained, processed, incorporated into training pipelines, used for model improvement or used to influence future outputs in ways the user neither understands nor intends. The concern is no longer simply where the data went. It is what the receiving system may subsequently do with it.
The third difference is arguably the most difficult because it sits with the user rather than the technology. Shadow IT was often driven by frustration. Employees adopted unsanctioned tools because approved ones were slow, cumbersome or lacked features they genuinely needed. Shadow AI inherits some of that motivation, but it also benefits from something shadow IT rarely possessed to the same degree: visible and immediate productivity gains. The employee who pastes a confidential document into a public AI service in order to summarise it, rewrite it or analyse it is often doing so because the tool genuinely helps them perform their work more efficiently.
That does not make the behaviour acceptable, but it does make it understandable. Security teams therefore find themselves facing a problem that is harder to argue against than traditional shadow IT. The user is not just bypassing a policy. They are often experiencing a measurable improvement in productivity, quality or speed. Any governance approach that ignores that reality usually discovers that users ignore the governance approach in return.
Taken together, those differences explain why shadow AI feels familiar and unfamiliar at the same time. The shape of the problem resembles shadow IT closely enough that many of the lessons still apply. The pace of change, the nature of the data flows and the strength of the user incentives ensure that applying the old playbook unchanged is unlikely to produce the same results. The organisations handling the problem most effectively are generally not the ones treating shadow AI as a simple compliance issue. They are the ones recognising that the demand is genuine, the technology is moving faster than previous adoption cycles, and the challenge is therefore as much about channelling behaviour as suppressing it.
The architectural reading
Stacked Zero Trust gives shadow AI a place to sit within the architecture rather than treating it as a separate category of disaster.
The substrate carries the discovery problem because shadow AI cannot be governed until it can be seen, and seeing it requires familiar layer-one disciplines applied with a degree of rigour most organisations have not previously needed. Visibility into AI-bound traffic, identity controls capable of distinguishing sanctioned from personal accounts, and data-classification mechanisms that recognise sensitive information leaving the boundary regardless of destination are all substrate functions. None of those ideas are particularly new. What is new is the scale and rate of change involved when there may be thousands of relevant services, many of which either did not exist a year ago or have acquired AI capabilities since they were last assessed. This is really the substrate-amplification argument from Post 4 appearing in a different form. The layer-one work was never fully finished, and the agentic generation of tooling has a habit of exposing unfinished work with very little sympathy.
The mediator carries the behavioural dimension of the problem. Recognising that a user has developed a pattern of AI-tool engagement that warrants intervention is fundamentally a behavioural exercise, requiring conclusions to be drawn from large volumes of telemetry, contextual information and historical activity. That is exactly the sort of problem layer two was introduced to solve. What is interesting is that the more mature implementations increasingly focus on routing rather than blocking. A user attempting to use a personal AI account is redirected towards a sanctioned enterprise equivalent, while substrate controls enforce the distinction if the guidance is ignored. Organisations that immediately block often discover they lose visibility along with control; organisations that successfully redirect usage towards approved options frequently retain both, which means governance remains possible because observation remains possible.
The conversation becomes considerably more interesting once autonomous agents start appearing inside the estate. Today, much of shadow AI still consists of humans using AI tools, but that distinction is becoming less useful as browser extensions, workflow automations, embedded copilot’s and autonomous agents begin acting on behalf of users. At that point the problem stops being solely about people interacting with AI and starts becoming a layer-three problem. These agents inherit privileges, perform actions, and increasingly exercise judgement inside processes that were originally designed for human participants. In many cases no one formally approved their existence because they arrived as features, plugins or convenience tooling rather than as consciously deployed systems.
The shadow-AI conversation is therefore evolving from a discussion about data leaving the organisation into a discussion about autonomous subjects operating inside it. Those subjects may never have been risk-assessed, may not appear in any architecture diagram, and may be carrying privileges inherited from the users who installed them. That is where shadow AI begins to intersect directly with the problems explored in Posts 6, 7 and 8. The challenge is no longer simply discovering tools. It is discovering subjects, understanding how they behave, and governing them as members of the trust algorithm whether they arrived through the front door or not.
What a working approach actually looks like
The practices that appear repeatedly in successful programmes are remarkably consistent.
Discovery starts at the network and identity layers rather than at the application inventory. Looking for a definitive list of AI tools is increasingly an exercise in chasing a moving target. Looking instead for AI-bound traffic patterns, unusual authentication behaviours and personal-account usage provides a much more durable signal. The tooling required is often already present in the form of CASB, SASE and related visibility platforms. The difference is that these tools have to be configured to discover AI usage rather than simply SaaS sprawl.
A second pattern is that organisations provide sanctioned alternatives that are genuinely competitive. Bans fail because users are solving real problems. The most successful programmes tend to offer enterprise-approved alternatives that are integrated cleanly enough into daily workflows that the approved path becomes the convenient path. That requires cooperation between security, technology and business teams in ways that are not always natural but are increasingly necessary.
A third pattern is treating sanctioned SaaS as a moving target rather than a static inventory. The security assessment carried out during procurement becomes progressively less valuable if the platform has subsequently acquired AI capabilities that did not exist when the review was completed. Mature organisations increasingly incorporate AI-capability reviews into vendor lifecycle management rather than treating approval as a one-time event.
The routing principle appears again as well. Where possible, mature implementations redirect rather than immediately deny. The difference between a user employing a personal AI account and the same user employing a sanctioned enterprise account may be no more than a single click, yet that click often determines whether visibility and governance are maintained or lost.
Finally, organisations increasingly need to look explicitly for autonomous agents that no one approved. Browser extensions acting on behalf of users, workflow platforms embedding autonomous decision-making, and copilot’s operating across multiple systems are all examples of layer-three subjects entering the environment through routes that traditional governance rarely anticipated. Identifying those agents and governing them as subjects rather than software is the next stage of the shadow-AI problem, and it is precisely the scenario the preceding posts have been preparing us for.
A line to sit with
The most useful framing I have found for shadow AI is also the simplest.
It is shadow IT with the rate of change increased dramatically, the data-exfiltration path made more consequential, and the user motivation made harder to argue against.
Any one of those differences would require a meaningful response. Taken together, they demand a different posture. The objective is no longer eradication in the way many organisations approached shadow IT. It is channelisation. The underlying demand is real. People are trying to work more effectively, and the architectural challenge is to convert ungoverned use into governed use without losing the people in the process.
The architecture does not solve shadow AI on its own, but it does give the problem somewhere to sit. Discovery belongs in the substrate. Behavioural detection and routing belong in the mediator. The autonomous agents arriving without an invitation belong in the subject layer. Holding all three perspectives in view simultaneously is the change in mindset the agentic generation demands.
One thing to take from this
Shadow AI is shadow IT moving faster, sending data into systems that may incorporate it rather than merely store it, and driven by productivity gains that prohibition alone cannot realistically overcome.
The three-layer architecture maps the problem surprisingly cleanly. Discovery remains layer-one work. Behavioural detection, visibility and routing sit naturally in layer two. The autonomous agents appearing throughout the estate without assessment or approval become layer-three subjects, whether the organisation recognises them as such or not.
The organisations handling this best are rarely the ones trying hardest to eliminate AI usage. They are usually the ones creating approved paths that are good enough to compete with the unapproved alternatives, maintaining visibility into how AI is actually being used, and continuously reassessing both their applications and their assumptions as new capabilities appear.
That closes Act III. The next post moves into the operational payoff of the series: a maturity model for Stacked Zero Trust, and the first appearance of the composite case study that carries through the remainder of Act IV.
Post 10 of 13 in Stacked Zero Trust.
Previously: Post 9 - Stacked Zero Trust Meets the Regulators.
*Next: Post 11 - A Maturity Model for Stacked Zero Trust.
The reference document at the end of the series includes a fuller treatment of shadow AI discovery patterns and a checklist for assessing the AI capability drift of sanctioned SaaS estates.
References drawn on in this post: industry surveys on shadow AI adoption from 2025-2026 including JumpCloud, Microsoft & LinkedIn Work Trend Index, Awareways Trend Report, Netskope, IBM, McKinsey, Gartner, and others; specific figures cited are from publicly available sources and are summary rather than precise (precise citations appear in the reference document). The “70% of AI interactions through sanctioned SaaS by 2026” projection appears in multiple analyst sources during 2025-2026.


