Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Practice · 2 min read · Updated 16 August 2026

Shadow IT

In shortShadow IT is rarely disobedience. It shows where the official tool fails to do a job.

At a glance

What it is
Use of services or devices without approval, contract or an entry in the record of processing activities
Typical triggers
A missing feature, no route for external partners, slow approval processes, migration without a needs analysis
Legal consequence
Processing without a data processing agreement and without a record entry
Most common places
Messaging, large file transfer, translation, AI assistants, scheduling
Best moment to find it
A new colleague's first day — that is when the accounts appear in plain sight
What does not work
A ban with no replacement; it moves usage to where you can no longer see it

Shadow IT means tools used inside a company without being approved, contractually governed and recorded in the register of processing activities. The term sounds like a rule breach, so it usually gets treated as a discipline problem.

The opposite reading is more useful: shadow IT is the most precise feedback a company can get. It points exactly at where the official tool fails to do a job that has to be done.

How it forms

The sequence is always similar. A feature is missing — voice messages, a quick route for external partners, a large file transfer, a translation. The official path takes too long or does not exist. Someone solves it themselves, it works, and within two weeks the solution is standard in that department.

It forms especially reliably after migrations. Anyone who did not ask, before cut-over, which five tasks come up most often finds out afterwards — this way.

The discovery day

The most honest test costs half a day of attention: sit with a new colleague on their first day and write down which accounts appear in the first four hours.

The official account is set up. Then comes a meeting on a different video service. Then a file that is too large. Then something to design, sign or translate. By the end of the day, data sits in four to six services and none of them is in the register.

That is not misconduct. It is a needs analysis somebody handed you for free.

What to do with the findings

One of three decisions per item: make it official, replace it, or drop it. Making it official means a contract, a record entry and access management — the requirements are under Data processing agreement.

What does not help is a ban with no replacement. It moves usage onto private devices and accounts, turning a usability problem into a data protection problem nobody can see any more.

The current hotspot

Right now shadow IT forms most often around AI tools. The reflex to ban them fails against their usefulness. More effective is a one-page rule on which data categories never go into an external tool, together with an approved tool that is good enough — and an understanding of which duties the EU AI Act triggers anyway.

Common questions

How do I find shadow IT without creating mistrust?
Sit with a new colleague on their first day and note which accounts appear in four hours. Card spending and network logs help as a supplement. The first route finds more and damages nothing.
What is the actual risk?
Not the tool but the missing foundation: no processing agreement, no record entry, no deletion concept, no control over access when someone leaves.
What do you do with the findings?
One of three decisions per item: make it official, replace it, or drop it because the need does not exist. The result belongs in the onboarding plan, so the next new colleague starts in a landscape somebody decided on.
And AI tools?
They are currently the most frequent addition. Instead of a ban, a one-page rule on which data categories never go into an external tool works better — plus an approved tool good enough that nobody works around it.

Sources

See also

Related terms