Shadow AI
Shadow AI consists of unvetted AI tools used within an organization without IT approval.
“Shadow AI is the modern equivalent of shadow IT, but with the added risk of permanent data leakage into public foundation models.”
Shadow AI introduces significant data exfiltration risks and bypasses enterprise compliance boundaries. When employees use unvetted AI tools, they unknowingly feed proprietary data into public model training pipelines.
Reverse Citations: Implemented & Audited Across Platform
Richard Ewing’s Research Thesis
We cannot secure what we cannot observe. Enterprises must transition from blocking AI adoption to orchestrating it through deterministic governance and centralized agent registries.
Latest Publications & Research Activity
How to Prevent Memory Loss in AI Applications
Giving an AI a bigger memory window is like giving a confused worker a bigger inbox.
Claude Search Fails: Prompting Kills Adoption
Frequently Asked Questions
Q:What is Shadow AI?
The unmonitored use of AI applications by employees without IT approval.
Inspectable Evidence Ledger
Classified evidence items supporting, extending, or refining this canonical research specification.
| Evidence Item | Publisher | Evidence Type | Strength | Role | Action |
|---|---|---|---|---|---|
| Data Exfiltration via AI Tools | Security Weekly | Report | ★★★★ | Supports | Inspect ↗ |
Recommended Citation
Ewing, R. (2026). "Shadow AI." Richard Ewing Research Canon. Available at: https://www.richardewing.io/concepts/shadow-ai
@article{ewing_shadow_ai,
author = {Ewing, Richard},
title = {Shadow AI},
journal = {Richard Ewing Research Canon},
year = {2026},
url = {https://www.richardewing.io/concepts/shadow-ai}
}