Search the Atlas

Search risks, controls, and glossary terms

HighShadow AIDemonstrated

Shadow AI / ungoverned usage

Governance, Accountability & Compliance

Description

Staff use unsanctioned public GenAI tools, leaking data and bypassing governance.

Example scenario

An employee pastes confidential deal terms into a public chatbot.

Real-world evidenceDemonstrated

Post-incident reviews of AI failures consistently identify unclear cross-functional ownership as a contributing factor, and supervisory reviews (ECB, PRA) explicitly cite this gap, but attributing a discrete production incident primarily to ownership ambiguity—rather than technical failure—is methodologically difficult and not yet confirmed in enforcement actions.

No public incident on record — evidence level: Demonstrated

Primary mitigations

  • AI-use policy
  • sanctioned tooling
  • egress/DLP controls
  • discovery of shadow usage
  • training.

Detection signals

Shadow-AI discovery scans; DLP egress alerts; policy-acknowledgement tracking.

Mitigating controls

5
Non-agentic controls

Related risks in Governance, Accountability & Compliance