On-demand Webinar: Third-Party Risk in the Agentic Era

On-demand Webinar: Third-Party Risk in the Agentic Era

On-demand Webinar: Third-Party Risk in the Agentic Era

Blog

Blog

Shadow AI is a subprocessor you never onboarded.

Zania

Third-party risk assumes vendors come through a front door: a request, a review, a DPA, a line on your subprocessor list. The AI tool an employee opened this morning skipped all of it, and it is already processing your data.


The 60-second version

Every vendor process you run has a front door. Someone requests a tool, security reviews it, legal signs a data processing agreement, the vendor lands on your subprocessor register, and monitoring picks it up. Shadow AI walks in through the browser tab instead. When an engineer pastes source code or customer records into an unapproved model, that model becomes a data processor with none of the controls attached: no DPA, no retention terms, no training opt-out, no entry on the list your own customers are entitled to see.

The scale is not small. LayerX puts 89% of enterprise AI usage outside any organizational visibility, with 71% of GenAI access running through personal, non-corporate accounts. Netskope's 2026 telemetry finds 47% of workplace GenAI users on personal, unmanaged accounts. IBM's 2025 breach data ties it to real losses: one in five breaches involved shadow AI, adding about $670,000 to the average cost.

This is the same trust-boundary failure the MCP post described. The boundary here is an employee with a text box, not a server.

Same destination, a live data processor. One path runs every control. The other runs none of them.

Same destination, a live data processor. One path runs every control. The other runs none of them.


The riskiest third party was never onboarded.

Third-party risk management is built on an assumption: that third parties announce themselves. A vendor is requested, assessed, contracted, and listed, and the whole apparatus of review hangs off that first request. Shadow AI breaks the assumption at step one. Nobody files a request to paste a customer list into a chatbot.

So the model receiving that data becomes a subprocessor with zero governance attached. You did not assess it, so you do not know its retention policy. You did not contract it, so there is no DPA and no training opt-out. You did not list it, so the subprocessor register you owe your customers under their DPAs is now wrong. The tool works exactly as designed. The failure is that your vendor process never saw it.

Auditors have caught up. SOC 2 assessors in 2026 treat shadow AI as one of the most common AI-related findings, described plainly as engineers piping company data into unapproved tools that never passed change management, access review, or vendor oversight. The finding is not that the AI tool is bad. It is that an unvetted subprocessor is inside the boundary your report claims to describe.





The AI already inside your approved tools.

There is a second form of shadow AI that no browser-monitoring dashboard flags, because it lives inside software you already trust. A sanctioned SaaS vendor ships an AI feature, someone enables it, and a new model subprocessor is now reading the data in that tool. Microsoft 365 Copilot, Notion AI, Slack AI, and Salesforce Einstein all sit inside products that already passed your review, under contracts written before those features existed.

The vendor cleared your process. The embedded model behind its new AI feature did not. Your original assessment covered the tool as it was, not the model it quietly added. Auditors now ask for a complete AI inventory that includes embedded features precisely because this is where the subprocessor hides.


The vendor passed review. The model its AI feature added did not. The subprocessor register still shows only the vendor.


See it, then govern it.

You cannot govern a vendor you cannot see, and you cannot claim a subprocessor list is complete while shadow AI is unlisted. Work both tracks. Discovery makes the vendor visible; onboarding decides its fate.


ASee it

Make every AI use visible


1Discover shadow AI in the browser and network

Egress monitoring and browser telemetry surface which AI tools are in use and by whom. With 89% of AI usage invisible today, discovery is the control that unlocks every other one.

Closes data egress


2Inventory embedded AI in approved SaaS

Walk your sanctioned tools and list every AI feature they added after your last review, Copilot, Einstein, Notion AI, Slack AI. Each is a subprocessor question you have not answered.

Closes embedded-AI creep


3Classify what data reached each tool

Source code, PII, customer records, and credentials carry different obligations. Netskope finds 54% of GenAI policy violations involve regulated data, so the data class sets the priority.

Closes data egress


4Reconcile against your subprocessor register

Line up discovered AI processors against the list you publish to customers. Every gap is a DPA commitment you are currently missing.

Closes subprocessor gap


BGovern it

Onboard it or off-board it


1Fast-path a real review for the keepers

The useful tools get the front-door treatment on a compressed timeline: DPA, retention terms, and a training opt-out in writing before more data flows.

Closes subprocessor gap


2Block or replace the rest

Tools that cannot meet the bar get blocked at the network edge and swapped for a sanctioned equivalent, so the workflow survives without the exposure.

Closesdata egress


3Pin retention and training-opt-out terms

For every AI subprocessor you keep, get retention limits and a no-training-on-our-data commitment in the contract, not the marketing page.

Closes no deletion path


4Add it to the register and monitor for change

Approved AI processors go on the subprocessor list, and embedded-AI features get watched, so a vendor cannot add a model to your environment after you signed.

Closes embedded-AI creep


Shadow AI is third-party risk that skipped intake.

The tool an employee opened this morning is a data processor doing exactly what processors do, minus the DPA, the retention terms, and the line on the list your customers are owed. The teams that get ahead of it will treat an unapproved model the way they already treat an unapproved vendor: find it, review it, and either onboard it properly or shut the door.



Sources

01Cost of a Data Breach Report 2025, IBM

02IBM report: 97% of AI-breached orgs lacked proper AI access controls, IBM Newsroom (July 30, 2025)

03Navigating the AI rush without sidelining security, IBM Think

04Cloud and Threat Report 2026, Netskope Threat Labs

05Generative AI drives surge in workplace data breaches (Netskope 2026 figures), SecurityBrief

06State of AI Usage Report 2026, LayerX

0789% of enterprise AI usage is invisible to the organization (LayerX findings), Help Net Security

08SOC 2 for AI Companies (2026): What Auditors Test First, soc2auditors.org

09Shadow AI and SOC 2: How It Creates Audit Gaps, Linford & Company

Share