Shadow AI – The Hidden Threat to Governance & Compliance


By Collin Miller, Structured Director of Cloud Security —

AI is everywhere… and that’s the problem.

AI adoption is exploding in enterprises. Employees are using GenAI tools like ChatGPT, Copilot, and Bard to automate tasks, boost efficiency, and generate insights. But there’s a major problem—IT teams often have no idea how AI is being used inside their organizations.

This phenomenon, known as Shadow AI, represents one of the fastest growing compliance and security risks today. While Shadow IT was about employees using unapproved SaaS apps, Shadow AI is about employees feeding sensitive data into AI systems in violation of policy and outside of IT controls.

Some Key Risks of Shadow AI

Data leakage – Employees may unknowingly share confidential corporate data, source code, or customer PII with external AI models.

Compliance violations – If AI tools train on user inputs, this may violate GDPR, HIPAA, SOC 2, or other regulations.

AI model bias & inaccuracy – AI-generated outputs could be incomplete, misleading, or even legally risky, especially in regulated industries.

Case Study: Samsung’s ChatGPT Data Leak

In 2023, Samsung engineers used ChatGPT to debug code—by pasting proprietary source code into the AI.  Since OpenAI retains inputs for training, Samsung’s intellectual property was effectively leaked to an external AI provider.  Samsung quickly banned ChatGPT, but the damage was already done. Samsung learned the hard way, when you chat with an AI, you’re not just talking, you’re teaching.

🔍 Key Lesson:
If employees don’t have enterprise-approved AI tools, they’ll find workarounds—putting the organization at risk.

How to Enforce AI Governance & Compliance in 3 Easy Steps

Step 1: Implement AI Activity Monitoring
📊 Solution: Use monitoring tools (Glasswing.ai, Splunk, XSIAM) to track who is using AI and for what purpose.
✔️ Example: If a user uploads files to an AI chatbot, security teams get an alert and can investigate.

Step 2: Deploy Private AI Environments
🔐 Solution: Instead of blocking AI outright, organizations should offer secure AI services where employees can safely use AI.

✔️ Example: Provide employees with enterprise AI models such as Copilot for M365 and ChatGPT Enterprise or private models hosted in Azure OpenAI, AWS Bedrock, or Google Vertex AI.

Step 3: Block Unapproved AI Tools
🚫 Solution: Use security technologies such as Next-Gen Firewalls (NGFW), Secure Access Service Edge (SASE), and Cloud Access Security Brokers (CASB) to prevent data from being sent to unsanctioned AI systems.

✔️ Example: AI Access Security from Palo Alto Networks can enable safe AI usage and enforce DLP (Data Loss Prevention) rules.


Don’t live in the shadow. Contact your account manager or email @info@structured.com if you would like to discuss effective ways to deal with Shadow AI at your organization.

About the Author

Collin Miller has more than 20 years’ experience designing secure and sustainable IT infrastructures that protect data, users, and organizational resources. As cloud computing gained traction, Collin dedicated himself to the practice of cloud security. His expertise extends to securing data and workloads in all the large public cloud providers, as well as the best practices, platforms and tools required to secure SaaS applications and the data traversing them.

With a strong background in cybersecurity, Collin brings a disciplined approach and deep knowledge of zero trust practices and secure access service edge (SASE) architectures to cloud environments. He is adept with cloud security posture management (CSPM), cloud native application protection platforms (CNAPP), cloud access security broker (CASB) platforms, and more.