Shadow AI: How to Discover, Assess and Govern Unsanctioned AI Use
Shadow AI is the use of AI tools inside an organisation without security review or approval. Discover it through egress logs, CASB, SaaS management data and expense records, including AI features quietly added to tools you already own. Then assess each use by the data it can reach, not the tool's popularity, and govern it with a short data-boundary policy backed by sanctioned alternatives and least-privilege access.
On this page
Who this applies to: AI risk owners, DPAs, CISOs and IT managers at UAE/GCC enterprises, ship operators and maritime service providers using or considering generative AI.
Most Gulf enterprises already have shadow AI. The question is whether they can see it. Shadow AI exists in every organisation. It is rarely malicious. Most employees simply want to work faster, think better, and solve problems using AI tools they already know. The problem is that this quiet layer of usage moves sensitive data outside the boundary you can monitor — and in a regulated environment, that undermines the auditability and accountability regulators expect.
This post gives you a working method: discover, assess, govern. It maps to frameworks you can defend in an audit, and flags where UAE-specific obligations bite.
What exactly counts as shadow AI, and why is it harder to catch than shadow IT?#
Shadow AI is a close cousin of the shadow IT problem enterprises met a decade ago, but the mechanics differ in one way that matters for detection. Unlike traditional shadow IT, shadow AI interacts with sensitive information through inference, drawing conclusions or generating outputs based on user prompts and internal data patterns. This type of access doesn't involve traditional file transfers, making it difficult for standard security tools to detect or log the interaction. As a result, AI usage can slip past conventional controls, making visibility and governance more challenging.
The invisibility is the defining risk. Unlike traditional applications that require installation or provisioning, many AI tools operate through browser extensions, embedded scripts or personal cloud accounts. A single paste of regulated data into a chatbot can create an exposure your DLP never recorded.
The fastest-growing category isn't rogue chatbots — it's AI features switched on inside tools you already approved. New risks emerge constantly as approved SaaS applications quietly add AI features without change notifications, effectively creating shadow AI inside tools you already approved.
Who this hits hardest in the Gulf: any team handling personal data of UAE residents, crew records, commercial contracts, or client financial data — because that pulls the UAE PDPL and, in some free zones, additional rules into scope the moment it leaves your boundary.
How big is the problem, really?#
The reporting varies by source and methodology, so treat these as directional rather than precise. According to Vectra's synthesis of vendor reporting, UpGuard's State of Shadow AI report found more than 80% of workers use unapproved AI tools, and IBM's 2025 Cost of a Data Breach report found one in five organisations has experienced a breach linked to unsanctioned AI. Netskope's usage data, as summarised by Seimless, suggests the control gap is wide: only 56% of workplace AI users stay entirely inside organisation-managed applications; another 14% mix managed and personal tools, while 30% use personal accounts exclusively. In other words, nearly half of AI activity sits partly or wholly outside company control.
The through-line across sources is consistent even where the numbers differ: adoption is outpacing governance, and the exposure concentrates in data leakage, compliance failure and an expanded attack surface.
How do you discover shadow AI without buying new tooling?#
Start with the telemetry you already have. You do not need a new platform to build a first inventory.
1. Inventory from existing telemetry
- Pull AI-related destinations from network egress / proxy logs
- Use CASB to flag unsanctioned AI endpoints
- Review SaaS management tooling and browser-extension reports
- Mine expense and card data for AI subscriptions
- List AI features inside SaaS you already own — the biggest blind spot
2. Classify by data reach, not popularity
- Tag each use by the sensitivity of data it can touch
- Rank a niche tool touching crew/PII above a popular one touching marketing copy
- Note whether personal data of UAE residents is involved (PDPL trigger)
3. Fix access first
- Scope every AI integration to least privilege
- Use short-lived credentials; log every call
- Prioritise remediation where access controls are missing
This mirrors what practitioners recommend. Existing monitoring infrastructure can be extended before any new technology investment is made. Cloud access security brokers (CASBs) can flag unsanctioned AI endpoints, while endpoint management tools can alert security teams to unusual executables or command-line activity. On sequencing, the guidance is blunt: discover before you decide. Inventory AI usage from egress logs, SaaS management tooling, browser extension reports, and expense data. Include AI features inside tools you already own, since that category hides the most exposure.
How should you assess each use once you've found it?#
Rank by exposure, not by how well-known the vendor is. Classify by data sensitivity, not by tool popularity. A niche tool touching patient records outranks a popular one touching marketing copy. Rank by what the tool can reach. Then close the most common failure mode first — missing access control — by scoping every integration to least privilege, using short-lived credentials, and logging every call.
This is where the NIST AI RMF gives you a defensible structure. Published in January 2023, the framework gives organisations a structured way to identify, assess, measure, and manage AI-related risk across the lifecycle. It organises work into four functions: Govern, Map, Measure, and Manage. Map your discovered uses to their context and data reach; Measure them against trustworthiness characteristics; Manage the treatment; and let Govern update policy. Note its status: the framework is voluntary and non-certifiable. Nobody can audit you against it, and you can self-claim alignment, which is where ISO 42001 comes in as the certifiable counterpart.
One realistic warning from practitioners: many programmes stall at Measure. A firm adopts NIST AI RMF, writes the governance policy, produces an AI inventory and a few context documents, then quietly drops Measure because nobody has the data infrastructure to benchmark risk consistently. Budget for the measurement step, or your governance is paper.
Which frameworks and rules bind Gulf operators here?#
NIST AI RMF 1.0
ReferenceVoluntary
Govern, Map, Measure, Manage. Shared vocabulary; self-claimed, non-certifiable.
ISO/IEC 42001:2023
ActiveCertifiable
World's first AI management-system standard; the certifiable counterpart to RMF.
UAE PDPL (45/2021)
In forceMandatory
Applies where AI processes personal data of UAE residents. In force since 2 Jan 2022.
UAE AI Charter
GuidanceNon-binding
12 ethical principles; the reference procurement and regulators use to approve deployments.
EU AI Act (2024/1689)
Phasing inConditional
Extraterritorial reach possible. Phased application; verify scope with counsel.
View as table
| Regime | Who it binds | Status |
|---|---|---|
| NIST AI RMF 1.0 | Voluntary | Reference — Govern, Map, Measure, Manage. Shared vocabulary; self-claimed, non-certifiable. |
| ISO/IEC 42001:2023 | Certifiable | Active — World's first AI management-system standard; the certifiable counterpart to RMF. |
| UAE PDPL (45/2021) | Mandatory | In force — Applies where AI processes personal data of UAE residents. In force since 2 Jan 2022. |
| UAE AI Charter | Non-binding | Guidance — 12 ethical principles; the reference procurement and regulators use to approve deployments. |
| EU AI Act (2024/1689) | Conditional | Phasing in — Extraterritorial reach possible. Phased application; verify scope with counsel. |
On ISO/IEC 42001: it is the world's first AI management system standard, providing valuable guidance for this rapidly changing field. It is also structurally familiar — it is built on ISO's Harmonised Structure, ensuring smoother integration with management systems compliant with other ISO standards, such as ISO 9001 and ISO/IEC 27001. If you already run an ISO 27001 ISMS, an AIMS is an extension, not a rebuild.
For UAE operators, the PDPL is the statute that actually bites when shadow AI leaks data. The PDPL was issued on 20 September 2021 and entered into force on 2 January 2022. It covers the storage and processing of personal data belonging to UAE data subjects, regardless of where the data controller or processor is established. Verify the applicability of executive regulations and free-zone regimes with the UAE Data Office, as several areas remained in transition.
The UAE's wider AI posture is layered rather than a single statute. The UAE has chosen a different path from the EU on AI regulation. Rather than a single horizontal AI statute, it operates a layered regime of federal data protection law, financial-free-zone-specific AI rules, sectoral regulators, and high-level ethical charters. The UAE Charter for the Development and Use of Artificial Intelligence, issued in June 2024, is non-binding and outlines 12 ethical principles including safety, data privacy, transparency, human oversight, governance and accountability. Non-binding does not mean irrelevant: it is commonly the reference procurement teams use to approve or reject a deployment.
If your fleet, group or clients touch the EU, the EU AI Act may reach you. Regulation (EU) 2024/1689 was published in the Official Journal on 12 July 2024, entered into force on 1 August 2024, and the enforcement of the majority of its provisions commences on 2 August 2026. The staggered timetable matters, so confirm which obligations apply and when with counsel and the official Article 113 text rather than a summary.
What does a governance programme that survives contact look like?#
Govern data boundaries, not tools. The policy should explicitly define what data categories can and cannot be entered into AI tools, require disclosure of AI usage in business processes, establish a clear approval process for new tools, mandate regular audits, and include consequences for violations. Focus governance on data boundaries rather than tool bans.
Bans alone backfire. Operational disruption follows discovery. When organisations find shadow AI usage, they often respond with blanket bans that halt legitimate productivity gains employees had built into their daily workflows. The durable fix is to remove the incentive to go rogue: when your organisation offers vetted tools for text summarisation, code assistance, data analysis, and content generation, the incentive to seek external options drops significantly. Collaborate with business units to identify high-demand AI use cases and supply secure alternatives before employees find their own. Sanctioned sandboxes with synthetic or anonymised data give teams room to experiment without exposing regulated content.
Keep the policy readable and re-audit on a cycle, because the ground keeps shifting. A quarterly audit should review network logs for new AI-related traffic patterns, survey teams on emerging tool usage, and reassess previously approved applications for new AI capabilities. That last step catches the vendor-added AI features that quietly reopen the exposure you thought you had closed.
Two pages beat twenty. A short, readable AI policy that everyone actually reads governs behaviour better than a long one nobody opens.
Shadow AI is not a tooling problem you buy your way out of. It is a visibility-and-boundary problem you manage on a cycle: find it, rank it by what it can reach, fix access, offer a sanctioned path, and re-check quarterly. Map that work to NIST AI RMF for structure, ISO/IEC 42001 if you need certifiable assurance, and the PDPL wherever personal data is in play.
If you need help building an AI governance baseline that stands up to UAE PDPL scrutiny and maps cleanly to ISO/IEC 42001, talk to Solas about a governance engagement.
Frequently asked
What is shadow AI and how is it different from shadow IT?
Shadow AI is unsanctioned use of AI tools without IT approval or security oversight. Unlike shadow IT, it acts on data through inference rather than file transfer, so it often slips past standard controls, and the outputs can shape decisions your governance never saw.
How do we discover shadow AI in our organisation?
Inventory usage from network egress logs, cloud access security brokers, SaaS management tooling, browser-extension reports and expense data. Critically, include AI features that approved SaaS vendors add quietly, since that category tends to hide the most exposure.
Should we just ban unsanctioned AI tools?
Blanket bans tend to halt legitimate productivity and push usage further underground. Most practitioners recommend governing data boundaries rather than banning tools, and offering vetted alternatives so employees have a sanctioned path.
Which frameworks help govern shadow AI in the UAE?
The NIST AI RMF gives a shared vocabulary (Govern, Map, Measure, Manage); ISO/IEC 42001 is the certifiable AI management-system standard. In the UAE, the PDPL applies where personal data is processed, alongside the non-binding UAE AI Charter and sectoral rules such as DIFC Regulation 10.
Does the EU AI Act apply to a Gulf company?
It can, through extraterritorial reach where AI outputs are used in the EU. Confirm scope with counsel. Even where it does not apply, its risk-based structure is a useful reference for a governance baseline.

Govern AI you can defend
Map your AI estate to the EU AI Act, NIST AI RMF, and ISO 42001 — with the evidence trail attached.
