Somewhere in your company this week, an employee closed a gap the modern way. A client spreadsheet needed cleaning before a 4 p.m. deadline, so it went into a free AI chatbot with the prompt "fix the formatting." A delicate email to an unhappy customer got drafted by a bot that read the whole thread first. Meeting notes, a pricing proposal, a paragraph of a contract — pasted, polished, returned. Nobody asked permission, because nobody thought of it as a security decision. It was just the fastest way to get the work done.
That is shadow AI: artificial intelligence tools in active business use without IT's knowledge, approval, or controls. It's the fastest-spreading form of shadow IT we've ever watched, because the tools are free, they live in a browser tab, and — unlike most rogue software — they are genuinely, immediately useful.
The problem isn't the chatbot. It's the paste.
Employees almost never leak data out of malice. They leak it out of helpfulness, one prompt at a time. The moment business data leaves your environment for a consumer AI service, several things happen at once — and none of them are visible to you:
- You may have just fed someone else's product. Consumer tiers of many AI services reserve the right, in their terms, to retain prompts and use them to improve their models. What goes in does not reliably come back out.
- The data now lives under someone else's breach. Even when a provider doesn't train on your prompts, it stores them — chat history is a feature. Your client list is now part of another company's attack surface, held under a consumer account with no contract protecting you.
- It happened under a personal account. No single sign-on, no offboarding. When the employee leaves, the chat history — and everything ever pasted into it — walks out the door with them.
- You may have breached a contract without being breached. If the pasted data was covered by an NDA, HIPAA, CMMC, or a client security addendum, the violation happened at the moment of the paste. No hacker required.
And chatbots are only the visible edge. Browser extensions with AI features can read every page an employee views — including webmail and the CRM. AI meeting notetakers join calls, record them, and mail transcripts to lists nobody reviews. "Connect your inbox" integrations request standing access that survives password resets — the same consent problem we flagged in our Microsoft 365 hardening guide.