Shadow AI is the use of artificial intelligence tools, such as public chatbots, AI browser extensions, or AI features switched on inside everyday apps, without the knowledge or approval of IT, security, or compliance teams. It is the AI version of shadow IT, and its central risk is sensitive data leaving the organization's control.
The problem is no longer hypothetical. IBM's 2025 Cost of a Data Breach Report, based on Ponemon Institute research across 600 organizations, found that 63% had no AI governance policies in place to manage AI or prevent employees from using shadow AI. It also found that a high level of shadow AI added USD 670,000 to the global average breach cost.
For proposal, due diligence, and security questionnaire teams in regulated industries, the exposure is specific. The content they handle every day includes client names, pricing, control descriptions, and security architecture details. Below is how shadow AI differs from shadow IT, why it shows up in response work, and how to reduce it without banning AI outright.
Shadow AI vs. shadow IT vs. sanctioned private AI
Shadow AI inherits the core problem of shadow IT, which is unapproved technology operating outside security's view. It adds a second problem: depending on the provider's terms, the tool may retain what users type into it, and the output it returns can be wrong in ways that are hard to spot.
| DIMENSION | SHADOW IT | SHADOW AI | SANCTIONED PRIVATE AI |
|---|---|---|---|
| What it is | Unapproved apps, devices, or cloud services | Unapproved AI tools or AI features used for work | AI that the organization has approved, configured, and monitors |
| Typical example | A team shares files through a personal cloud storage account | A writer pastes questionnaire answers into a public chatbot | A response platform drafts answers from an approved content library |
| Where data goes | A third-party service outside the IT inventory | A third-party AI provider, under that provider's terms | An environment the organization has vetted and contracted for |
| Main risk | Unmanaged access and data sprawl | Data exposure plus unverified, untraceable output | Residual model error, managed through human review |
| Audit trail | Usually none | Usually none | Logged edits and approvals |
| Who approves use | No one | No one | IT, security, and compliance |
Why shadow AI shows up in RFP and questionnaire work
Response teams work under hard deadlines with large volumes of repetitive questions. A long security questionnaire or an investor due diligence questionnaire can arrive with the deadline only days away. When the approved tools feel slow, a public chatbot looks like the fastest way to draft, summarize, or rewrite an answer.
In this setting, shadow AI usually takes one of a few forms:
- Pasting RFP questions and past answers into a consumer chatbot to generate a first draft.
- Uploading a full questionnaire spreadsheet to an AI tool to summarize it or fill it in.
- Installing an AI writing extension that can read what is typed in the browser.
- Turning on new AI features in an existing SaaS tool before security has reviewed them.
None of these start with bad intent. They start with a workload problem that the sanctioned toolset does not solve, which is why the fix has to address speed as well as policy.

Shadow AI risks in regulated industries
Confidential data leaves your control
RFP and questionnaire answers often describe encryption practices, incident response procedures, subprocessors, client lists, and pricing. Once that content goes into an unapproved AI tool, the organization may not know where it is stored, how long it is kept, or whether it is used to improve the provider's models. IBM's research also found that 97% of breached organizations that experienced an AI-related security incident lacked proper AI access controls.
Answers nobody can verify
Generative models can produce fluent, confident text that is wrong. NIST's Generative AI Profile (NIST AI 600-1), released in July 2024, lists confabulation among the risks that generative AI creates or makes worse, alongside data privacy, information security, and intellectual property. In a proposal or due diligence response, an invented control or an overstated capability can become a contractual representation.
No audit trail when regulators or clients ask
Regulated firms are expected to show who wrote an answer, what source it came from, and who approved it. Work done in a personal chatbot session leaves no record inside the firm's systems, so the team cannot reconstruct how a submitted answer was produced when an auditor, examiner, or client asks.
How to manage shadow AI without banning AI
Bans tend to push usage further out of sight. A more durable approach gives people a sanctioned path that is faster than the workaround, then governs it. The four functions of the NIST AI Risk Management Framework (Govern, Map, Measure, and Manage) offer a useful structure for the program.
- Find out what is already in use. Survey teams and review software and network data for AI tools and AI features, and frame the exercise as discovery rather than discipline so people answer honestly.
- Write an AI acceptable use policy. Define which data classes can never go into external AI tools, which tools are approved, and who signs off on new ones.
- Offer a sanctioned alternative that is faster. For response teams, that means AI that drafts from approved content inside a vetted environment, such as a private AI engine built for regulated work.
- Govern the knowledge the AI draws from. AI output is only as reliable as its source. Knowledge-Centered Success (KCS), the methodology from the Consortium for Service Innovation, treats knowledge as an asset that is captured, reused, and improved in the flow of work. The same discipline applies to a governed content library with named owners and review dates.
- Keep humans in the loop and log everything. Flag AI-generated text for review, route answers through approvals, and keep a record of who changed what and when.
- Train people and revisit the policy. AI features change quickly, so review the approved tool list and the policy on a set schedule.

What sanctioned AI looks like for response teams
The goal is to make the approved path the easiest one. RocketDocs was built with that in mind. Astro, its private generative AI engine, runs inside the RocketDocs environment, drafts responses using only a customer's approved knowledge base, and does not send customer data to a third-party model provider. Every AI-generated response is flagged for human review, and each change and approval is logged in the audit trail.
That combination removes the main reason people turn to public chatbots, which is speed, while keeping every answer traceable. It applies across RFP response, DDQs, and security questionnaires. For a closer look at the last of these, see our security questionnaire response playbook.
If your team is working out how to bring AI into response work without creating shadow AI, book a demo to see how private AI and a governed content library work together.
Looking for the platform behind this? See the RocketDocs platform or book a demo.