¿Qué es la TI en la sombra? Conozca los conceptos básicos

The fundamentals on why unauthorized technology can be bad, and sometimes useful, for an organization.

¿Qué es la TI en la sombra?

Shadow IT refers to IT devices, software, and services used within an organization without the knowledge, approval, or oversight of the IT department. These are any technology projects or tools adopted outside of and without the explicit approval of your organization’s IT function.

If you’re thinking “well, my employees know better than that,” think again. Shadow IT remains a persistent and widespread reality inside most organizations, and its newest and fastest-growing form, shadow AI, is expanding the problem rather than replacing it.

  1. What Is Shadow IT?
  2. Why Does Shadow IT Happen?
  3. Shadow AI: The New Face of Shadow IT
  4. Shadow IT Examples
  5. The Business Benefits of Shadow IT
  6. Shadow IT: The Risks and Challenges
  7. What Can You Do to Reduce Risk?
  8. Preguntas frecuentes

Why Does Shadow IT Happen?

As boards and management take a greater interest in security and risk management, particularly as third-party and vendor-related breaches remain a leading cause of incidents, there’s growing pressure on security teams to translate their work into business terms employees actually feel day to day. It’s when there’s a lack of, or a breakdown in, communication between security and the rest of the organization that shadow IT gains traction.

There are a few main reasons that continue to drive shadow IT in most organizations:

  • Everyone now has access to data and technology tools. From marketing to sales, anyone can access data and use it as they see fit, often without routing through IT first.
  • IT teams are overwhelmed. When IT moves too slowly for other departments, those departments take matters into their own hands. Technologically capable teams are less likely to wait for IT and more inclined to find and roll out their own solutions.
  • IT employees themselves are frequent users of shadow IT and shadow AI, often because they feel best equipped to judge and manage the risk involved personally.
  • Third-party services and cloud providers make it easier than ever to adopt new tools. As the complexity around advanced technology such as AI and machine learning continues to drop, these tools become more appealing to employees both inside and outside the IT department.
  • Distributed and hybrid work are now the operating norm, not a temporary pandemic-era exception. With employees routinely working across home offices, co-working spaces, and multiple devices, the number of unmanaged apps, personal accounts, and unsanctioned tools in daily use naturally increases. Organizations planning around this reality should treat hybrid and remote work as a permanent feature of their risk management strategy rather than a phase to plan around.

Shadow AI: The New Face of Shadow IT

Shadow AI is shadow IT’s newest and fastest-growing category: employees using generative AI tools such as ChatGPT, Copilot, Gemini, or AI-powered browser extensions and plug-ins for work tasks without approval, visibility, or governance from IT or security teams.

The scale of shadow AI adoption has moved quickly from a minor concern to a board-level risk:

  • Roughly 8 in 10 employees use unauthorized AI tools at work, and 68% of security leaders, including CISOs, admit to using unauthorized AI in their own daily workflows, according to UpGuard’s November 2025 State of Shadow AI report.
  • Two-thirds of office professionals report having used AI tools or services at work that weren’t sanctioned by their employer, per PagerDuty’s 2026 Shadow AI Survey
  • The financial impact is measurable and specific: one in five breached organizations studied experienced a breach linked to shadow AI, and these incidents added as much as USD 670,000 to the average breach cost, according to IBM’s 2025 Cost of a Data Breach Report. Intellectual property carried the highest cost per record in shadow AI-related breaches, even though it was exposed less frequently than other data types.

Why shadow AI is riskier than traditional shadow IT

Traditional shadow IT tools, like an unapproved cloud storage account or productivity app, mostly create visibility and access-control problems. Shadow AI compounds that risk because generative AI tools don’t just store data; they ingest it. When an employee pastes contract terms, source code, customer records, or strategic plans into an AI chat interface, that information can leave the organization’s control entirely and enter a third-party model provider’s systems, often with no audit trail and no way to retrieve or delete it after the fact.

This is a natural extension of the End User Computing (EUC) risk organizations have long managed in spreadsheets and databases, just with a much larger and faster-moving surface area. If you’re new to the concept, What Is End User Computing (EUC) Risk? covers the fundamentals of how spreadsheets and other user-built applications create hidden risk in the first place. Addressing shadow AI typically requires the same discovery-and-governance approach organizations already use for shadow IT and EUC risk, extended to cover AI governance specifically: knowing which AI tools are in use, what data flows through them, and where policy and technical controls need to close the gap.

Shadow IT Examples

Most shadow IT examples will sound familiar, and include End User Computing assets and applications, meaning any system where individuals build working tools outside the design, build, test, and release process a professional software engineering team would normally follow. Common categories include:

  • Online cloud storage. Services like Dropbox or Google Drive offer a fast, simple way to store and share files online, but these tools may not have been vetted or approved by IT.
  • Productivity apps. Slack, Asana, Trello, and similar tools become shadow IT the moment they’re adopted without IT’s knowledge or administration.
  • Physical devices. Flash drives and external drives may feel secure simply because they’re in an employee’s physical possession, but they still require approval and oversight.
  • Communication applications. Tools like Zoom, Skype, or other VoIP services fall under shadow IT when deployed outside IT’s visibility.
  • Generative AI tools and AI browser extensions. ChatGPT, Copilot, Gemini, and unsanctioned AI plug-ins are now one of the largest and fastest-growing shadow IT categories, as detailed above.

Bottom line: while it can feel like everyone is already using these tools, they should first be reviewed and approved as secure and company-standard by the IT department.

The Business Benefits of Shadow IT

The same conditions that cause shadow IT to flourish also explain the benefits it can offer an organization:

  • Avoiding bottlenecks. When employees are frustrated with the speed of IT, shadow IT lets them route around delays that would otherwise stall their work.
  • Empowering employees. Shadow IT solutions let employees act on ideas and needs they may not otherwise have had the technical means to address.
  • Decreased technology costs. Distributing solutions across employees can take pressure off IT, freeing the department to focus on higher-value work, and shadow IT tools are often cheaper than IT-procured alternatives.
  • Surfacing employee insight. Higher shadow IT usage often signals unmet needs. Understanding what employees are reaching for outside official channels gives IT and security teams real visibility into where processes need to improve.

Shadow IT: The Risks and Challenges

Shadow IT presents real risks and challenges to any organization. The major ones include:

  • Decreased security. Shadow IT and shadow AI tools aren’t vetted by IT, so they don’t go through the same security review as approved technologies. These tools may not follow best practices around data access controls, backup, and recovery, which increases the risk of data loss, including sensitive customer data.
  • Poor collaboration. When different departments rely on different, unapproved tools for the same function, such as one team using Trello and another using Asana, the result is typically less collaboration and more miscommunication.
  • More work for IT. Shadow IT applications tend to look simple until something breaks. As more unsanctioned tools spread across teams, IT ends up fielding support requests for systems it may have no visibility, documentation, or ownership over.
  • Regulatory and compliance exposure. Unsanctioned tools, especially AI tools processing regulated data, can create compliance gaps under frameworks like GDPR, HIPAA, and the EU AI Act, since the organization often can’t demonstrate what data went where or under what safeguards.

What Can You Do to Reduce Risk?

Whether shadow IT and shadow AI applications are welcome in your organization is a decision to make based on risk and reward, not an outright ban that’s unlikely to hold. The reality is that regardless of policy, some unsanctioned tools will always be in use. The most effective response is to implement a means of identifying, inventorying, and monitoring these applications rather than relying on prohibition alone.

Take Control of Your Shadow IT

Mitratech ClusterSeven helps you discover, inventory, and govern the spreadsheets, databases, and other EUC assets hidden across your enterprise that create hidden risk.

SABER MÁS

Find and Govern Shadow AI Before It Becomes a Breach

Mitratech’s AI Governance solution extends that same discovery-and-governance approach to shadow AI, helping you find unsanctioned AI usage and apply consistent policy and technical controls across the organization.

SOLICITAR UNA DEMOSTRACIÓN

Preguntas frecuentes

What is shadow IT?
Shadow IT is any IT device, software, service, or application used inside an organization without the knowledge, review, or approval of the IT department.
What is shadow AI?
Shadow AI is a subset of shadow IT specific to artificial intelligence: employees using generative AI tools, AI-powered plug-ins, or AI browser extensions for work purposes without IT or security team approval and oversight.
Is shadow AI more dangerous than traditional shadow IT?
Shadow AI carries additional risk because generative AI tools process and transform the data fed into them, often sending it to a third-party model provider outside the organization’s control. Traditional shadow IT tools, like an unapproved storage or productivity app, typically create access and visibility gaps but don’t process data the way AI systems do.
How common is shadow AI in the workplace?
Very common. Independent 2025 and 2026 surveys from UpGuard, PagerDuty, and Verizon each report that a majority of employees have used AI tools their employer did not formally approve, with figures ranging from roughly two-thirds to eight in ten depending on the survey and region.
Can shadow IT and shadow AI be eliminated entirely?
Not realistically. Employees will generally find a way to use the tools they believe help them work faster, regardless of policy. The more effective approach is proactive discovery and governance, identifying what’s in use, assessing the risk it carries, and either sanctioning it, replacing it with an approved alternative, or actively remediating it, rather than relying on a ban alone.
How does an organization start discovering its shadow IT and shadow AI footprint?
Start with an inventory: identify EUC assets like spreadsheets and databases operating outside IT’s formal processes, and separately identify AI tools in active use across departments. See What Is End User Computing (EUC) Risk? for a closer look at how EUC risk specifically is identified and managed. From there, apply risk-based governance, prioritizing the assets and tools with the greatest access to sensitive data or business-critical processes for closer review first.