# Shadow AI Source: https://customlabs.io/glossary/shadow-ai/ Updated: 2026-09-13 Security & governance # Shadow AI Also known as shadow use Shadow AI is a model or tool used without going through the sanctioned path. Examples include a personal account, an unapproved extension, or a script someone wrote over a weekend. Treating every instance purely as a compliance problem misses what it usually reveals. It usually reveals that the sanctioned path is missing something the workaround supplies. The durable fix closes that gap in the golden path, rather than only banning the workaround. [AI Security Review](https://customlabs.io/security-review/)[The Agent Adoption Playbook](https://customlabs.io/adoption/) [← Back to the full glossary](https://customlabs.io/glossary/) ## Related terms [Golden Path A golden path is the single sanctioned way to do a common piece of work.](https://customlabs.io/glossary/golden-path/)[AI Register An AI register is a current list of every system that touches a model.](https://customlabs.io/glossary/ai-register/) ## More in Security & governance [Data Processing Agreement (DPA) A DPA is the contract naming a vendor as a processor of personal data.](https://customlabs.io/glossary/data-processing-agreement/)[Data Residency Data residency is where data is physically processed and stored, not where users are located.](https://customlabs.io/glossary/data-residency/)[Red Teaming Red teaming is deliberately attacking your own AI system to find what breaks first.](https://customlabs.io/glossary/red-teaming/)[High-Risk AI System A high-risk AI system is one classified as carrying enough decision impact to trigger heavier compliance.](https://customlabs.io/glossary/high-risk-ai-system/)