Skip to content
Noxys
Shadow AICISOEuropean Enterprise

The blind spot no one talks about: shadow AI is already in your company

Gartner is unambiguous: 69% of organisations suspect, or have evidence, that employees are using prohibited public GenAI. This isn't a future trend — it's your network, today.

A number that should keep you up at night

In a survey of 302 cybersecurity leaders run between March and May 2025, Gartner found that 69% of organisations suspect or have evidence of prohibited public GenAI use. Employees turn to ChatGPT, Claude, Gemini or Perplexity for work tasks — with no IT visibility, no data controls, no audit trail.

And that number understates reality. It doesn't count AI browser extensions, unsanctioned Microsoft 365 plug-ins, or AI agents embedded in third-party SaaS tools your teams already use. The actual exposure surface is significantly larger.

For a CISO at a mid-market European company, this means confidential data — intellectual property, client data, HR records, legal files — is flowing to US servers without any governance. Every week.

5 personas: who is using Shadow AI in your organisation?

Shadow AI isn't the work of a rogue employee. It's your best people — productive, motivated, trying to move faster. Here are the profiles we see most often.

The Infrastructure Engineer

Pastes AWS CloudFormation templates into ChatGPT to debug deployments. Thinks it's harmless. Your cloud architecture just left the building.

The Marketing Manager

Uses Claude to draft campaign briefs — including unreleased product roadmaps and competitive positioning. Fast and effective. Also a data leak.

The CEO

Dictates board presentation bullet points to Gemini on his phone between meetings. M&A target names, revenue forecasts, strategic pivots. All cached on Google servers.

The Developer with Copilot

Has GitHub Copilot installed — not the enterprise-licensed version, his personal free tier. Your proprietary algorithms are training someone else's model.

The HR Business Partner

Uses Perplexity to summarise 360° feedback for performance reviews. Names, salaries, manager comments, PIP details — all processed on a US server, potentially retained.

Why your current controls fall short

Most security teams respond to Shadow AI with tools designed for a pre-AI world. Traditional DLP inspects file transfers and email — not HTTPS prompts sent to an OpenAI API. The network proxy sees a domain (api.openai.com) but not the content. Domain blocking pushes employees to their personal phones.

The EU AI Act adds another layer of complexity. From August 2026, AI deployers must document their usage, assess risks, and train their employees (Article 4). Without visibility into what your teams actually use, you cannot meet these obligations.

The answer isn't to block everything. It's to see everything, assess it, and control it — with tools built for AI.

The 5 enforcement layers: how defence-in-depth works

No single layer is sufficient. An employee who bypasses the browser extension on their phone must be stopped at the network proxy layer. A personal VPN bypasses the proxy — the DNS sinkhole takes over. Defence-in-depth is the only viable strategy.

01

Browser Extension

Chrome, Firefox, Edge

Inspects prompts at the point of entry — before they leave the browser. Real-time classification of PII, secrets, IP, and confidential data. User coaching at the moment of risk.

02

Network Proxy

All AI APIs, all apps

Intercepts all outbound AI API traffic — approved and unapproved. Provides full audit trail, policy enforcement, and anomaly detection regardless of which app made the call.

03

DNS Sinkhole

All DNS-resolving devices

Resolves unsanctioned AI service domains to a Noxys-controlled endpoint. Catches traffic that bypasses the proxy — VPNs, split-tunnel edge cases, mobile devices on corp WiFi.

04

Endpoint Agent

Windows, macOS, Linux

Monitors AI process activity at OS level — local LLMs, desktop apps, native binaries. The only layer that catches on-device AI usage not visible from the network.

05

NetFlow Analysis

East-west + north-south

Passive traffic fingerprinting. No decryption required. Detects AI API call patterns from volume, timing, and destination — even for encrypted traffic to unknown endpoints.

Full architecture detail on the <Link to="/protection-layers" className="text-noxys-400 hover:text-noxys-300 transition-colors">5 protection layers</Link> page.

5 concrete actions to start this week

You don't need to solve everything at once. Here's what you can do right now, with or without additional budget.

1.

Run a Shadow AI discovery scan

Deploy a read-only network proxy or browser extension on a sample of 20–50 users for 2 weeks. You will be surprised by what you find. No policy enforcement — just visibility.

2.

Map your AI tool landscape

Ask every team lead: which AI tools do your people use? Compile the list. You will discover tools your IT procurement team never saw. This is your Shadow AI inventory baseline.

3.

Classify your data before classifying your tools

The risk isn't the AI tool — it's what data goes into it. Define your top 5 data categories (PII, financial forecasts, IP, legal, M&A) and build policies around those, not around tool names.

4.

Run a Shadow AI awareness campaign

Most employees don't know they're doing something risky. A 5-day awareness campaign changes behaviour faster than any technical control. We've built a free kit to help you.

Get the free CISO campaign kit →
5.

Start your EU AI Act Article 4 documentation

Enforcement starts August 2026. Article 4 requires AI literacy measures for all staff. Document what tools you allow, what training you provide, and who is accountable. A 2-page policy now saves a €15M fine later.

Discover your Shadow AI in 15 minutes

Deploy Noxys in read-only mode on 10 machines. Get a full report of your unsanctioned AI usage in under a week. Free, no commitment.

JS

Jérôme Soyer

CEO & co-founder, Noxys · Ex-Varonis

Related articles