A security lead at a defense contractor tells his developers, plainly, not to put source code into a frontier AI model. They do it anyway. Not out of malice, they are trying to ship, and the AI makes them faster. He finds out weeks later, and now he has a problem he cannot size: he does not know what code went where, what the model kept, or how to prove any of it to an assessor. That is Shadow AI, and if you run a regulated shop, it is already inside your boundary.
We have seen this movie before
Shadow IT was the last version of this. Employees adopted unsanctioned SaaS, a personal Dropbox, a side project board, faster than security could sanction it, because the sanctioned path was slower than the work. Security spent a decade catching up: discovery, CASB, acceptable-use policy, data-loss controls. We mostly won that fight by making the governed path usable, not by pretending the ungoverned one did not exist.
Shadow AI is the same move, one layer up. Instead of a rogue SaaS tool, it is a developer pasting a function into ChatGPT to debug it, an analyst dropping a controlled document into a chatbot to summarize it, an engineer wiring Copilot into an IDE that sits on a codebase full of CUI. The pattern rhymes. The adoption curve is steeper.
Why Shadow AI is worse than Shadow IT
Shadow IT leaked your data into a vendor’s storage you did not vet. Bad, but boundable: the data sat somewhere, and with effort you could find it and pull it back.
Shadow AI is harder in three ways. The data does not just sit in someone’s cloud, it goes into a model whose provider, infrastructure, retention, and training use you do not control. You often cannot tell what was sent, what was kept, or whether it surfaces in someone else’s completion later. And the interaction is conversational and ephemeral, so there is frequently no artifact at all: no ticket, no log, no record that the exposure happened. Shadow IT left a trail. Shadow AI often leaves nothing.
AI is a control surface you have not scoped
Here is the framing that matters for a regulated team. Every compliance regime you operate under assumes one thing: that you can enumerate where regulated data goes and prove you control the paths. CMMC Level 2 and the NIST SP 800-171 controls behind it are built on knowing where CUI lives and who can touch it. ITAR assumes you keep technical data away from unauthorized persons and systems. HIPAA, PCI DSS, FedRAMP, same shape.
Those control sets were written for endpoints, networks, cloud, and removable media. They were not written for a developer’s chat window. AI-assisted work is a new path for regulated data to leave your control, and most organizations have not added it to the list of surfaces they govern. It belongs there, next to the endpoint and the network, as its own control surface with its own scoping, its own policy, and its own evidence.
Naming it that way changes the question from “should we allow AI” to “how do we control this surface,” which is a question you already know how to answer for every other surface you run.
The real casualty is your ability to prove
For a regulated shop, the loss is not only that data might leak. It is that you lose the ability to prove what happened, and proving is the entire job.
Compliance is not “did something bad occur.” It is “can you demonstrate control.” In the assessments I have sat in, no one accepts good intentions in place of evidence. Shadow AI erodes that evidence in three places at once. A non-deterministic model made the call, so you cannot reproduce why the output came out the way it did. You cannot show what the model actually saw, because nothing recorded the input. And whatever logging exists was written beside the system after the fact, mutable and incomplete.
Put those together and you have a process you cannot reconstruct, attribute, or defend. In an assessment, an unprovable process is not a gray area. It is a finding. The quiet cost of Shadow AI is that a shop which used to be able to prove what it ran can no longer prove what it runs.
Banning it is the wrong control
The reflex is to ban it. The defense lead at the top did exactly that, and it did not work, because a ban without a compliant alternative does not remove the behavior. It removes your visibility into the behavior. The developers still want the tool. Now they use it quietly, and you have traded a governance problem you could see for one you cannot.
This is the same lesson Shadow IT taught. Prohibition drove SaaS underground until we gave people a sanctioned path that was actually usable. Forbid it, or tolerate a violation, is a false choice. The teams that handled Shadow IT well did neither. They made the governed path the easy path.
Treat AI like a control surface, not contraband
So what does governing the surface look like. Three moves, and none of them is “ban AI.”
Bring it inside the boundary. If the exposure is that code and data leave to a model you do not control, run the model somewhere you do. A self-hosted model inside your authorization boundary removes the export, the data never leaves.
Gate what it can touch. Decide, deterministically and in advance, what the AI is allowed to see and do, and enforce that at the boundary instead of trusting the tool. The point is not to grade whether the output is good. It is to control whether regulated data reached the model and whether its output can act on anything.
Produce a record. Every AI-assisted action should leave an artifact you can hand an assessor: what was used, what the model produced, what it touched. That is the difference between “we think our developers are careful” and “here is the log.”
Do those three and the surface goes from an unscoped liability to a governed control. AI-assisted work stops being a finding waiting to happen and starts producing the evidence you would have had to reconstruct anyway. This is the problem we spend our time on at ScanSet, but you do not need us to see the shape of it. You need to add AI to the list of surfaces you govern before your next assessment does it for you.
The takeaway
Shadow IT taught the industry that you cannot govern what you refuse to see, and you cannot ban your way out of a tool people find genuinely useful. Shadow AI is the same lesson with higher stakes and a worse audit trail. For a regulated team, the move is not to pretend it is not happening, and not to forbid it into the shadows. It is to treat AI as what it now is: a control surface, scoped, gated, and recorded like every other. The shops that do it keep their ability to prove what they run. The ones that do not will find out the hard way, in a room with an assessor.



