Shadow AI

Updated

Discover, control, and govern unsanctioned AI app usage across your organisation — from building visibility into shadow AI activity to blocking risky destinations, preventing data loss, and governing sanctioned use.

Shadow AI is the use of generative AI apps and agents outside of IT visibility and governance. Employees adopt consumer AI tools to be productive, but in doing so they can expose sensitive data, bypass compliance controls, and create unmonitored risk. Addressing it is a motion, not a single control: first discover what is actually being used, then layer protection to block unsanctioned destinations and prevent data leaving to AI apps, govern the apps you do sanction by bringing them under Microsoft Purview through enterprise AI app connectors or Entra registration, and respond as user risk changes.

How to address Shadow AI

  1. Discover Shadow AI Usage

    Builds visibility into which AI apps users are accessing, who is using them, and whether sensitive data is flowing into AI prompts — before taking any blocking action.
  2. Block Unsanctioned AI Destinations

    Blocks access to unsanctioned AI apps at the network layer — enforcing org-wide blocking through Defender for Cloud Apps and applying user and group-level restrictions through Entra Internet Access.
  3. Control AI Apps on Managed Devices

    Prevents installation and execution of unsanctioned AI apps and local AI agents on managed devices using Intune app control policies and Microsoft 365 admin center shadow AI governance across Windows, iOS/iPadOS, Android, and macOS.
  4. Govern Sanctioned Enterprise AI

    Bring the AI that runs outside Microsoft's Copilot family — custom apps you build and sanctioned SaaS such as ChatGPT Enterprise and Anthropic Claude — under Microsoft Purview, so their interactions are discovered, audited, and governed like the rest of your estate rather than remaining a blind spot.

Control coverage

Control coverage for Shadow AI — where its 16 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Monitoring
10
Discovery
8
Governance
7
Compliance
6
Agent Security
2

Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.

Data Protection
2

Mechanisms that protect data confidentiality and integrity at rest, in transit, and during processing within AI workloads — including encryption, sensitivity labeling, and data loss prevention.

Network Protection
2

Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.

Threat Detection
1

Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.