On this page
If your business hasn’t officially rolled out AI tools, there’s a very good chance your staff have done it for you.
That’s shadow AI — the use of generative AI tools, browser extensions, plug-ins, and third-party integrations inside a business without the knowledge, review, or approval of IT, security, or leadership. Like shadow IT before it, it’s happening whether you acknowledge it or not.
And in Northern Ontario SMBs, the pattern is nearly universal.
How Shadow AI Actually Looks in a Real Business
It’s rarely dramatic. It looks like this:
- An account manager copies a signed client contract into a free AI summarizer to save 20 minutes of reading.
- A marketing coordinator subscribes to a $20/month AI image generator on her personal credit card and expenses it under “subscriptions.”
- A developer installs a browser extension that promises to “paste AI responses into any textbox” — and unknowingly grants that extension access to every webpage they visit, including internal portals.
- An office administrator connects a third-party AI meeting-notes tool to the company Microsoft 365 calendar and mailbox via OAuth. Nobody reviews the permissions being granted.
- A salesperson uploads the customer pipeline as a CSV to a new AI tool promising “automatic lead scoring.”
- A non-profit program coordinator pastes a beneficiary case note into ChatGPT to “rewrite it professionally” for a funder report.
None of these people would describe what they did as risky. They’d describe it as resourceful — which is exactly why shadow AI spreads faster than shadow IT ever did.
Why Shadow AI Is a Bigger Problem Than Shadow IT Was
Shadow IT in the 2010s was mostly about data at rest — a file sitting in a personal Dropbox, a contact list inside a personal Gmail account. Bad, but bounded.
Shadow AI is about data in motion into a learning system. Four properties make it much harder to contain:
1. The data leaves, and often trains something. Consumer-tier AI tools commonly retain prompts. Many free tools use submitted content to improve their models. Your confidential data doesn’t just sit in a vendor’s database — it becomes part of a training corpus. This is not hypothetical. In a widely reported 2023 incident, Samsung employees submitted proprietary source code and internal meeting notes to ChatGPT — data that was ingested into OpenAI’s training pipeline with no way to retrieve or delete it.
2. OAuth grants quietly compound. Every time an employee clicks “Connect to Google / Microsoft / Slack” on an AI tool, a new third-party integration gains persistent access to corporate data. Those grants often outlive the employee’s tenure — we’ve audited environments where former staff had OAuth tokens still actively pulling data from Microsoft 365 months after departure.
3. The output gets trusted too much. Shadow AI output gets pasted into emails, contracts, and reports with no human review step, because there’s no policy requiring one. Hallucinated facts, fabricated citations, and confidently wrong numbers end up in front of clients.
4. You cannot audit what you cannot see. Shadow AI usage doesn’t show up in your MDM, your SaaS inventory, or your licence reports. It shows up in browser history and credit card statements — if it shows up at all.
The Specific Risks, in Plain Language
Data exposure. Confidential, personal, or regulated data ends up in a system outside your control. Depending on the data type — PHI under PHIPA, personal information under PIPEDA, financial records — this may constitute a reportable breach that triggers notification obligations and regulator involvement.
Intellectual property erosion. Your proprietary processes, templates, project plans, code, quoting logic, or strategy documents become training signal for a vendor you have no contract with. You lose exclusivity without even knowing it.
Regulatory exposure. Industries with specific data rules — healthcare, legal, financial services, nonprofits receiving government funding — can trigger compliance violations through a single unauthorized prompt. In some cases, a single staff member’s shadow AI use has invalidated a funding agreement.
Vendor lock-in by accident. Staff build entire workflows around unauthorized tools. By the time IT catches up, ripping it out is expensive, disruptive, and fought against.
Reputational risk. Client-facing output generated by shadow AI may include hallucinations, plagiarized content, or language that contradicts your contracts’ confidentiality clauses. In professional services especially, this is a trust-and-liability issue, not a tech issue.
Supply chain attack surface. AI browser extensions are a known and actively exploited attack vector. A compromised extension can exfiltrate every keystroke and page the user interacts with — including banking portals, cloud admin consoles, and customer records.
Cyber insurance exposure. Increasingly, insurers expect businesses to have AI governance in place. Undisclosed shadow AI usage can complicate — or invalidate — a claim after an incident.
Why Prohibition Doesn’t Work
The instinct is to ban it. Write a policy saying “no AI tools without approval,” send the email, move on.
It doesn’t work, for the same reason banning personal cloud storage didn’t work in 2014: the productivity gap is real. If the approved workflow takes 40 minutes and the shadow tool takes four, people will use the shadow tool and not tell you. They won’t tell you because they’ll worry they’ll be disciplined. So the behaviour goes underground instead of going away.
Prohibition plus an inadequate alternative is the worst combination — all the risk, none of the visibility.
What Actually Works
Six things. In order of impact.
1. Give your team a sanctioned alternative that’s genuinely good. Microsoft 365 Copilot inside your tenant, ChatGPT Enterprise, or Gemini for Google Workspace Business — configured, accessible, and trained on. If the sanctioned tool is worse than the shadow tool, people will keep using the shadow tool. The enterprise versions of these platforms contractually do not train on your data, inherit your Microsoft 365 or Workspace permissions, and are supportable by your MSP.
2. Publish a short, named approved-tool list. Not “use AI responsibly.” Actual tool names, actual approved data tiers, actual examples. Update it quarterly. Ambiguity is what drives shadow adoption.
3. Make “request a new tool” fast. A 48-hour turnaround on AI tool review requests is realistic and prevents most shadow adoption. A six-week review process guarantees workarounds.
4. Audit OAuth grants regularly. Most identity platforms — Microsoft Entra ID, Google Workspace Admin — expose a list of third-party app grants. Review the list monthly. Revoke anything you don’t recognize. Most Northern Ontario businesses we onboard discover at least five unexpected OAuth grants in their first audit.
5. Block known consumer AI endpoints on managed devices and company networks. You can’t block “all AI.” You can block specific known-risky consumer endpoints through your firewall, DNS filtering, or browser management on company devices. Combined with a good sanctioned alternative, this is usually enough to shift the behaviour.
6. Hold an amnesty conversation. Once a year, bring the team together and ask: “What AI tools are you actually using that you haven’t told us about? No consequences. Help us understand so we can give you a better, safer version.” This conversation surfaces more shadow AI in one hour than any audit.
The Role of an MSP in Shadow AI
Your managed IT partner should be actively reducing shadow AI exposure. At DVG Systems, this shows up in several places across the services we deliver for Northern Ontario clients:
- OAuth and third-party app audits as part of our Microsoft 365 security baseline — identifying what has access to your tenant and removing what shouldn’t
- Network and DNS-level filtering of known high-risk consumer AI endpoints on managed devices
- Microsoft 365 Copilot rollout with a proper approved-tool list, sensitivity labels, and staff training — so there’s a sanctioned alternative worth using
- Quarterly AI tool reviews where we evaluate emerging tools clients are asking about and add them to (or exclude them from) the approved list
- Incident response support if shadow AI use has resulted in exposed data
- Cyber insurance alignment so your AI governance posture matches what your underwriter expects to see
Shadow AI isn’t a single project — it’s an ongoing operational concern that sits at the intersection of security, compliance, and productivity. That’s MSP territory.
A Practical Starting Point: The 30-Minute Audit
If you want to get a read on your own exposure before bringing in help, three quick checks will tell you a lot.
1. Check OAuth grants. In Microsoft 365, go to Entra ID → Enterprise Applications. Look at every app your users have granted access to. Unfamiliar app names? That’s shadow AI.
2. Check browser extensions on company devices. On a sample of laptops, open the extensions list. Anything with “AI,” “GPT,” “Copilot” (not the real one), “summarize,” or “write” in the name deserves scrutiny.
3. Ask the team. Literally ask. “If I gave you amnesty, what AI tools would you admit to using for work?” The answers will surprise you.
The Bottom Line
Shadow AI isn’t a security problem to be stamped out. It’s a signal — it tells you your team has found tools that make them faster than the tools you gave them.
The right response isn’t discipline. It’s to give them a better, safer, sanctioned version of the same capability, make the policy clear enough that nobody has to guess, and audit the edges regularly.
Ignore it, and you’re absorbing risk you can’t quantify. Address it, and your shadow AI inventory becomes the roadmap for what to deploy officially.
DVG Systems provides managed IT services to small and mid-sized businesses across Northern Ontario, including Thunder Bay, Timmins, and the surrounding region. If you’d like a confidential AI and SaaS usage assessment for your organization, book a free assessment or reach us at (807) 700-0061 or solutions@dvgsystems.com.