Risk & governance
Shadow AI
AI tools or usage operating outside approved technology and governance processes.
Definition
Shadow AI includes employees, teams or applications using models and agents without formal security, procurement, data or model-risk approval.
Why it matters
It obscures sensitive-data flows, cost, vendor concentration and accountability across a financial institution.
Related concepts
- Data leakage
Sensitive information reaching an unauthorised model, user or output.
- Vendor lock-in
Difficulty moving a system away from a provider without major cost or disruption.
- AI and model inventory
A controlled record of models, AI systems, owners, uses and risk status.