Every enterprise now runs two AI stacks: the one IT approved, and the one employees actually use. Security researchers call the second one shadow AI, personal ChatGPT accounts wired to work documents, unsanctioned agents connected to CRM data, browser extensions with standing access to email, and it has quietly become one of the defining SaaS security risks of 2026.
The mechanics are mundane, which is why they are everywhere. An employee connects a personal AI tool to a work account to move faster; the tool retains tokens, context and sometimes training rights over whatever passes through; and none of it appears in the software asset inventory, because nobody procured it.
Why the usual playbook fails
Blocking does not work: AI tools deliver too much personal productivity for bans to hold, and blanket bans simply push usage to personal devices where visibility is zero. The problem also compounds the permission sprawl that already plagues SaaS estates, where most users hold more privileges than their role requires; an AI tool inherits every privilege of the account that connects it.
The buyer’s counter-move
Three controls beat prohibition. Offer a sanctioned path: an approved AI workspace with enterprise data terms removes the main reason people go around IT. Interrogate vendors with the same questions from our agentic procurement guide: where does memory live, who trains on what, what leaves on exit. And instrument OAuth grants, the connection layer between AI tools and SaaS accounts is where shadow AI becomes visible, and where it can be governed without theater. Orchid Security’s own research puts a number on the blind spot: 67 percent of nonhuman accounts are unmanaged, the same gap that lets shadow AI agents inherit access nobody tracked.
The uncomfortable math for security teams
The reason shadow AI is harder than shadow IT is speed of connection. A rogue SaaS app still took a signup and often a credit card; a shadow AI integration is one OAuth consent screen away, and the employee clicking through it rarely reads what scopes they are granting. A single approval can hand a third party standing read access to an entire mailbox or CRM, and because the grant lives in the connected account rather than on a managed device, endpoint tooling never sees it.
That is why the durable fix is architectural rather than punitive. The organizations getting ahead of this treat the OAuth grant layer as the control point: continuous inventory of which third parties hold which scopes, automatic revocation of dormant or over-privileged grants, and alerting when a new AI tool connects to a sensitive system. It is the same principle behind the nonhuman-identity governance in Orchid’s identity-gap work and the machine-identity capital behind Keyfactor’s billion-dollar raise: you cannot govern what you cannot see, and the connection layer is where AI access finally becomes visible.
What to watch
Watch for the first major breach publicly attributed to an unsanctioned AI integration, the moment this moves from risk-register line item to board topic, and for SaaS platforms shipping native AI-grant dashboards, which will mark the market accepting that shadow AI is permanent.
AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.
