Why shadow AI grows fastest in regulated firms
It is reasonable to assume that a strong control environment suppresses unsanctioned technology. With AI, the reverse is closer to the truth. In a regulated firm, the sanctioned route to a new tool runs through procurement, information security review, data protection assessment and, increasingly, model governance. That process exists for good reason — and it takes months. The unsanctioned route takes minutes: open a browser tab, or click “try the new AI features” inside a product the firm already licenses. The tighter the approved path, the steeper the incentive gradient towards the unapproved one.
Demand does the rest. Financial services work is exactly the kind AI is good at helping with — document-heavy, precedent-driven, full of drafting, summarising and reconciliation. Staff who use these tools at home feel the productivity difference every day. Where firms respond with outright bans, usage does not stop; it moves to personal devices and personal accounts, where corporate visibility is zero and client data leaves the perimeter entirely.
None of this is a staff-integrity problem. Most shadow AI is adopted in good faith by people trying to do their jobs well. It becomes a governance problem because nobody can risk-assess what nobody has recorded — and in a regulated firm, unrecorded processing of client data is not a neutral state.
Why traditional controls miss it
Traditional software controls assume that software arrives through a doorway: an installer that endpoint controls can block, a purchase that procurement can see, a network connection the proxy can flag. Modern AI rarely uses the doorway. Three blind spots recur.
- Browser-based tools. Nothing is installed, so endpoint controls see nothing. Traffic is ordinary HTTPS to widely used domains, often under a personal account. Web filtering can categorise known AI services, but new tools appear faster than block-lists update, and many sit inside domains the firm cannot block without breaking legitimate work.
- OAuth grants. A staff member connects an AI notetaker, scheduling assistant or plug-in to the corporate Microsoft 365 or Google Workspace tenancy. From that point, data flows server-to-server through granted API permissions — no download, no expense claim, no proxy event. The evidence sits in the tenancy’s permission graph, which few firms review with AI in mind.
- Embedded vendor AI. Suppliers that cleared procurement years ago are switching on AI features inside products already in use: copilots in the CRM, transcription in the meeting platform, document analysis in the e-signature tool. An inventory built from procurement records is out of date the moment a vendor ships a feature, and broad processing clauses in the original contract mean nobody is prompted to re-assess.
What it costs when it goes unreviewed
The gap between what a firm believes it runs and what it actually runs is its unmanaged exposure — and in a regulated business, that exposure is regulatory before it is technical.
Client personal data flowing to a processor with no data-processing agreement engages UK GDPR and the ICO’s expectations on impact assessments. Under the FCA and PRA’s Senior Managers regime, accountability attaches to risks in a Senior Manager’s area whether or not those risks were ever written down. The PRA’s model risk expectations for banks start from knowing the model estate. And the EU AI Act reaches UK firms serving EU clients, with credit scoring and creditworthiness assessment classified as high risk — our EU AI Act guide covers the scope question in detail. ISO 42001 and the NIST AI RMF both begin from the same place: an inventory. You cannot certify, or manage, what has never been mapped.
This is what happens when unreviewed systems touching regulated decisions are counted and priced, rather than left as an unknown on nobody’s register.
What discovery actually requires
The standard response — circulate a questionnaire asking teams what AI they use — measures willingness and ability to disclose, not actual usage. People forget browser tools, do not think of embedded features as “AI” at all, and stay quiet where policy has been punitive. Surveys produce the curated inventory. Governance needs the complete one.
Completeness requires telemetry first: identity and SSO logs, the OAuth permission graph of the corporate tenancy, cloud and API gateway traffic, SaaS admin consoles, and expense data as a weak secondary signal. This is the ground our Lab’s shadow AI detection research works on — testing detection rates across cloud platforms, API gateways and OAuth permission graphs. Interviews then validate and extend what the telemetry surfaces. People disclose considerably more when shown what has already been found, and when the framing is amnesty rather than audit.
The output that matters is not a list of tool names. It is an inventory classified by data sensitivity, decision impact and regulatory relevance: which systems touch client personal data, which feed credit or underwriting decisions, which fall within EU AI Act risk tiers. That classification determines everything that should happen in the next 30 days.
The first 30 days after you find it
The instinct is to ban everything the discovery exercise surfaced. Resist it. A ban executed on day one punishes exactly the people who could tell you the most, and guarantees that the next discovery exercise finds nothing. The first month is about triage, stabilisation and reporting — not enforcement.
In week one, triage by data sensitivity and decision impact: anything touching client personal data, or feeding credit, underwriting or other regulated decisions, comes first. In weeks two and three, stabilise rather than punish — offer a sanctioned alternative alongside a disclosure amnesty, move the highest-risk systems into formal review or supervised use, and put data-processing agreements in place wherever processing will continue. In week four, report: put the classified inventory in front of the risk committee with monetary framing attached, because the accountable Senior Managers should hear about it from you rather than from a regulator or an incident.
Then treat the snapshot as the start of a standing control, not the end of a project. An inventory decays quickly — new OAuth grants appear weekly and vendors ship AI features monthly. This is why a Sentinel engagement closes into the Citadel platform: discovery becomes continuous rather than a one-off exercise, and the register the board saw in month one is still true in month twelve.