Issue Shadow AI puts autonomous decision-making outside any governance perimeter
Summary
Deloitte warns that many of the most pressing AI risks now originate inside the organisation, and names shadow AI as a leading example. Shadow AI refers to unsanctioned AI deployed by individual teams across an enterprise. It creates governance blind spots and brings in autonomous decision-making systems that can reach sensitive data, make consequential choices and interact with other systems. Each such deployment is a potential source of data leakage, model manipulation, model drift or unauthorised access. The report suggests that approaches developed for shadow IT, such as monitoring the network to discover all applications and setting policies so new deployments meet privacy and security standards, can be adapted. It pairs shadow AI with inadequate controls on agentic AI as the two main internal threats.
Classification
Evidence 1
- Tech Trends 2026: As technology innovation and adoption accelerate, five trends reveal how successful organizations are moving from experimentation to impact Deloitte Insights (Deloitte Development LLC, US Office of the CTO) page=55;section=The AI dilemma: Securing and leveraging AI for cyber defense / The enemy within 2025-12 accessed 2026-07-26
Constituent trends 1
Directly linked signals 0
No objects.
Relation types: constitutes
Public id: fm-bb48fc27e3a3
