Shadow IT
In shortWhat nobody approved, nobody can secure. Bans make it worse.
Shadow IT is not a security problem caused by careless people. It appears wherever the approved tool is worse than the freely available one — and that is the most common situation there is.
Why it is growing now
Because AI tools run in a browser: no installation, no procurement, no ticket. An employee who wants a contract clause summarised is thirty seconds away from a US service, with the contract in the input box. No network filter catches that when it happens on a personal phone.
It is also why the AI Act turns into a sovereignty question indirectly: it requires documentation of what is deployed. A company that does not know cannot meet the duty. See EU AI Act.
What does not work
Bans. We have yet to see a ban policy that lowered usage; they lower visibility. Afterwards the same usage is there, without a log and without a contract.
What does work
Measure first, decide second. An afternoon with the proxy logs and the departmental card statements shows what is actually running. The result surprises people in every company.
Provide an endpoint that is good enough. If the approved option does the same job just as fast, nobody uses the other one. That is the only reliable enforcement there is.
Speed procurement up rather than tightening it. A tool costing fifteen euros a month whose approval takes six weeks does not get requested. It gets bought privately.
The side effect for sovereignty
The list of services actually in use is the same list NIS2 wants as a supplier overview and the same one any dependency assessment needs. Uncover shadow IT and you have the most unpleasant part of the inventory behind you. See Data processing agreements and sub-processors.
Sources
See also
Related terms
- EU AI ActRegulates AI risk and transparency, not location. Location becomes an issue anyway.
- Digital sovereigntyNot self-sufficiency, but the ability to decide: you can leave if you have to.
- Data processing agreements and sub-processorsYour vendor's sub-processor list is the most honest dependency map you can get for free.