Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release
Platform Overview
Shadow AI

Shadow AI Governance
Govern what you didn't approve

Employees use AI tools no one approved, vendors add AI to software you already bought, and agents act without sign-off. Modulos brings all of it into one AI registry, mapped to the EU AI Act, ISO 42001, NIST AI RMF, NIS2, and DORA.

Request a Demo
49%

of workers at organizations with 500+ employees admit to using AI tools without employer approval.

BlackFog Shadow AI Research, 2026 ↗
47%

of organizations surveyed had an AI agent security incident in the past twelve months.

Cloud Security Alliance, 2026 ↗
70%

of employee AI interactions were forecast to run through features embedded in approved SaaS applications by 2026.

Gartner prediction, 2023, via JumpCloud ↗
Definition

What is shadow AI?

Shadow AI is any AI system, tool, or capability used inside an organisation without being formally registered, assessed, or governed by the people responsible for compliance and risk.

It spans employees pasting confidential data into consumer chatbots, autonomous agents running production workloads no one signed off on, and AI quietly embedded in software that was originally approved as something else. Under the EU AI Act, ISO/IEC 42001, and NIST AI RMF, an incomplete AI inventory makes compliance impossible: you cannot demonstrate what you cannot see.

Discovery and AI registry

How Modulos governs shadow AI

Three layers feed one AI registry: people who know the rules, the AI you build, and the AI you use. Each layer catches a kind of shadow AI the others miss.

LAYER 1AI literacyLAYER 2AI discoveryLAYER 3AI usage control
  1. Layer 1 · Train the people · EU AI Act Art. 4

    AI literacy training

    Since February 2025 the EU AI Act (Art. 4) requires providers and deployers to make sure the people who operate and use their AI systems have sufficient AI literacy. Modulos Learn gives role-based courses for general staff, technical teams and AI owners. Staff who know the rules declare the AI they use, and each completed course is evidence the AI registry can point to.

    Open Modulos Learn →
  2. Layer 2 · Find the AI you build · Modulos platform

    Discovery with Scout

    Inside the Modulos platform, Scout scans the sources and connectors you plug in: GitHub, Azure, Atlassian and Microsoft Copilot Studio. Every agent built in Copilot Studio is found, described and proposed as a registry entry with its owner, so agents do not go live unregistered.

    See AI discovery →
  3. Layer 3 · Govern the AI you use · Third-party integrations

    Usage and control via partners

    Where a partner already sees AI usage, Modulos takes the signal from there. Partners such as SentraGuard detect AI apps in use from SSO logs, network egress and expense data, and the Claude Console and OpenAI Platform report who calls which model. Sanctioned tools are checked against the inventory. An unsanctioned one becomes a registry entry for onboarding review.

    See the integrations →

Modulos AI registry

One entry per AI system and agent, with owner, risk classification and controls. Each entry goes through onboarding review and approval, then on to lifecycle governance. A single control maps to the EU AI Act, ISO 42001, NIST AI RMF, NIS2 and DORA at the same time.

The six levels of shadow AI

Where each kind of shadow AI is caught

Shadow AI ranges from a curious employee to a vendor that adds AI to your data pipeline. Training stops the first kind, but senior staff who bypass the policy only show up in usage signals.

LevelWhat it looks likeCaught by
01 NaiveStaff use consumer chatbots because no one told them the rules.AI literacy
02 ConvenienceAn approved tool exists, but the consumer tool is faster.AI literacy, AI usage control
03 DefiantSenior staff know the policy and bypass it anyway.AI usage control
04 EmbeddedApproved software adds AI features that no one assessed.AI usage control
05 AgenticTeams build agents that act on systems and data without sign-off.AI discovery
06 Supply chainA vendor uses AI on your data.Third-party review in the registry
Frequently Asked Questions

Shadow AI, answered

The questions compliance officers, CISOs, and AI leads ask most when shadow AI moves from an edge case to a standing item on the risk agenda.

Q01What is shadow AI?

Shadow AI is any AI system, tool, or capability used inside an organisation without being formally registered, assessed, or governed by the people responsible for compliance and risk. It spans employees pasting confidential data into consumer chatbots, autonomous agents running production workloads no one signed off on, and AI quietly embedded in software that was originally approved as something else.

Q02How is shadow AI different from shadow IT?

Shadow IT historically meant unapproved SaaS, cloud services, or hardware that bypassed procurement. Shadow AI is structurally different: AI systems make autonomous decisions, learn from inputs that often include sensitive data, and increasingly run inside tools that were approved as non-AI software. Traditional shadow IT controls miss most of the real AI risk surface.

Q03Does shadow AI violate the EU AI Act?

Shadow AI does not violate the EU AI Act by itself. It can make compliance impossible. The Act requires you to identify, classify, document, and govern every AI system in scope. Article 4 literacy and Article 50 transparency obligations require you to train your workforce on the AI that is really in use. Without a complete inventory, demonstrating compliance to an auditor is not possible.

Q04How does shadow AI affect ISO 42001 compliance?

ISO/IEC 42001 is the international management system standard for AI. Its core requirement is a documented AI Management System covering every AI system in scope. Any shadow AI sitting outside that inventory falls outside the management system, and any audit will flag the gap between what is registered and what is in use as a certification finding.

Q05Does Modulos detect shadow AI directly?

Partly. Scout, inside the Modulos platform, finds the AI you build: it scans GitHub, Azure, Atlassian and Microsoft Copilot Studio and proposes a registry entry for each AI system or agent. For the AI your staff use, Modulos takes signals from partners that already see that traffic, such as SentraGuard, and from the Claude Console and OpenAI Platform. Each unsanctioned app becomes a registry entry for review, mapped to your regulatory frameworks.

Q06What is agentic shadow AI?

Agentic shadow AI is autonomous AI agents taking actions on systems, data, or decisions without being formally governed. It spans approved agents acting outside their intended scope and fully unapproved agents running on production infrastructure. In a 2026 Cloud Security Alliance survey, nearly half of organizations reported an agent security incident in the past twelve months, because agents move faster than traditional review cycles can keep up with.

Sources
  1. BlackFog Shadow AI Research, 2026 · “of workers at organizations with 500+ employees admit to using AI tools without employer approval.”
  2. Cloud Security Alliance, 2026 · “of organizations surveyed had an AI agent security incident in the past twelve months.”
  3. Gartner prediction, 2023, via JumpCloud · “of employee AI interactions were forecast to run through features embedded in approved SaaS applications by 2026.”

See Shadow AI Governance in Action

Book a demo to see how Modulos turns shadow AI signals into a governed inventory, mapped to the EU AI Act, ISO 42001, and NIST AI RMF.