Shadow AI: The AI Tools Already Running on Your Clients’ Machines

I was testing an inventory tool on a Windows 11 workstation recently, and the report came back with 358 pieces of software on that one machine. A handful of them were AI apps, Copilot and Claude among them. There was nothing alarming about that, however it got me thinking about all the machines I have supported over the years that I did not build and did not watch every day. If one workstation can hold that much, what is sitting on your clients’ machines right now?

That question has a name, and the name is Shadow AI.

What Shadow AI is

Shadow AI is any AI tool being used for work without the knowledge or approval of whoever is responsible for IT. It is the same idea as shadow IT, which those of us who have been around for a while remember as the file sharing account nobody told us about, but what goes into it is different. People paste things into an AI tool. Customer emails, contracts, spreadsheets, meeting notes, and sometimes a password or two, and once it is pasted it has left the building.

How common it is

It is more common than most owners want to hear. UpGuard surveyed 1,000 employees and 500 security leaders for its State of Shadow AI report, and 81 percent of the employees said they use AI tools that were never approved. The part that got my attention is that 88 percent of the security leaders said the same thing. The people who write the rules are doing it too.

IBM’s 2026 Cost of a Data Breach report shows where that leads. Security incidents involving shadow AI more than doubled in a year, to 43 percent from 20 percent, and roughly one in five of those incidents ended with the organization paying a fine. IBM also found that most of the breached organizations had nothing in place to manage AI use or to detect shadow AI. IBM studies larger organizations, and a ten person office is not going to see an enterprise sized bill, but the pattern holds at every size, the tools show up first and the oversight shows up later, if it shows up at all.

Where it hides

When I say AI tools, most people picture one chatbot in one browser tab. It is wider than that, and these are the places I would look.

  • Desktop apps — ChatGPT, Claude, Copilot and others install like any other program, and some arrive with the operating system or the office suite.

  • Browser extensions — writing assistants, summarizers and AI sidebars that can read every page the user opens, including the client portal and the webmail.

  • Meeting notetakers — bots that join a call, record it and keep the transcript in somebody’s personal account.

  • AI features inside approved software — the tool was approved two years ago and the AI button showed up in an update last month.

  • Personal accounts on web chatbots — nothing is installed at all, it is a browser tab and a free account tied to a personal email address.

  • Agents and connectors — the newest one and the one I would watch closest, an AI tool that has been granted access to a mailbox, a shared drive or a CRM and can act on its own.

Why it matters to an MSP and to the owner

If you are an MSP, your client assumes you know what is on their machines. When something leaks, the first call is going to be to you, and “I did not know that was installed” is a hard thing to say to a client. It is also a fair bet that the next cyber insurance questionnaire or compliance audit your client fills out will ask how AI use is being managed, and they will be looking to you for the answer.

If you are the business owner, it is your customers’ data that is leaving. I do not believe the staff are being careless on purpose. They found something that saves them an hour a day and they are using it, and nobody gave them an approved way to do the same thing.

What to do about it this month

  1. Take an inventory. List the installed software on every machine, the browser extensions, and the third party apps that have been granted access in Microsoft 365 or Google Workspace. You cannot make a decision about something you cannot see.

  2. Ask the staff. No penalties, just a simple question, “what AI tools are you using and what are you using them for?” This is how you find the browser tab usage that an inventory will never show you.

  3. Sort what you find into three piles. Approve it, restrict it, or remove it.

  4. Give people an approved option. I would not start with a blanket ban. If the only answer is no, the usage does not stop, it just moves somewhere you cannot see it.

  5. Write it down on one page. What is approved, what never goes into an AI tool (customer data, credentials, financials), and who to ask when something new comes along.

  6. Do it again next quarter. New AI tools and new AI features show up every month, so a one time cleanup will not hold.

Where to start

I have a tool in development at OpStacks that handles the first part of step one, the installed software on Windows and Linux machines, and I will share more about it in the OpStacks Weekly Digest as it gets closer. However, none of the steps above require you to buy anything. Start with the inventory and the conversation with the staff, and let me know what you find.

If this was useful, subscribe to the OpStacks Weekly Digest at OpStacks.net, where I share a practical tip like this one every week.

Sources

UpGuard, The State of Shadow AI (November 2025)

IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (July 2026)

Previous
Previous

Where AI Helps in Vulnerability Triage, and Where It Guesses

Next
Next

Your Cyber Insurance Renewal Is Going to Ask for Proof. Do You Have It?