
Shadow AI begins because of pressure. These AI tools don't arrive through procurement. They arrive through a pressure on people to deliver. Those moments where someone clicks yes in a browser tab, sets up a personal account, or a free tier, signed up for on a Tuesday afternoon to get a summary done faster. Perhaps a developer hits an API directly with a personal key, bypassing the approved gateway entirely. Or another favorite: a SAAS platform your organisation already approved bundles an AI feature in an update.
So this just looks like someone just getting their job done, rather than a security incident. That's why it doesn't get caught: Single sign-on sees what's been onboarded, Cloud Access Security Brokers see the known cloud domains. Neither was built to see a personal ChatGPT login on a managed device, or Gemini enabled inside a Google Workspace.
In most industries, an untracked SaaS subscription is an efficiency issue, but for an organisation operating under SOC2, ISO27001, or sector-specific frameworks like DORA, it's failure with repercussions.
SOC2 auditors are seeking access logs for AI tools, evidence of who reviewed that access, and documentation of how unsanctioned tools get identified and handled. A written acceptable use policy doesn't satisfy this.
An auditor doesn't want to know what your policy says should happen. They want to see the record of what did happen. The Shadow AI looms large.
IBM's 2025 Cost of a Data Breach report found that 20% of organisations studied experienced a breach linked to shadow AI, unsanctioned AI tools adopted without IT or security oversight. Where shadow AI was a factor, it added an average of $670,000 to the cost of the breach, and those breaches took 247 days to detect.
Shadow AI incidents also disproportionately exposed customer PII and intellectual property. Breaches also have implications depending on severity; see our previous post on the EU-AI Act compliance for more here.
You don't need a six-month intervention to get a clear picture. Instead we propose that you need just four sources of information:
- Network and firewall logs: The single most reliable source for tools actually being used, regardless of whether IT approved them. This is what can catch unsanctioned tool usage.
- SaaS and expense audit: Pull credit card statements and expense reports for AI-adjacent line items. Self-funded subscriptions rarely touch SSO and rarely show up anywhere else.
- Browser extension review: A significant share of AI tool usage happens through browser extensions and plug-ins that never require a login your identity provider would see.
- A plain-language staff survey: Something more like an amnesty than a compliance questionnaire... Which AI tools do you actually use to get your work done? People will tell you, if the survey doesn't feel like it's building a case against them.
Cross-referencing results across these four sources, provides actionable information.
Every governance step that follows, risk-tiering your AI use cases, building decision logs, producing evidence for a board or an auditor... it all depends on first knowing what's actually running. You cannot govern what we cannot see. Your policy may have a 20-tool inventory when the real number is far higher…
It's a tough and potentially thankless start. But discovering the truth about Shadow AI is the starting evidence base every other governance step is built on. The unfortunate reality is that once Shadow AI is shut down, a safety mandate is met, but other mandates (commercial, operational, strategic) may be compromised... in future blog posts we'll explore the answer: AI enablement with governance built in.
---
This is the first post in Marino Software's AI Governance Scenarios series. At Marino Software, we help high-compliance clients to both deal with the here-and-now, and to look ahead.
We find that a lot of the thinking out there is based on planning for a perfect future. We would rather ground our advice in the honesty of the messy reality. Get in touch if you’d like to learn more about how Marino Software can work with you as a partner.

Have a project in mind, or just starting to think one through? We’re good at both.
Get in touch