Third-party risk assumes vendors come through a front door: a request, a review, a DPA, a line on your subprocessor list. The AI tool an employee opened this morning skipped all of it, and it is already processing your data.
The 60-second version
Every vendor process you run has a front door. Someone requests a tool, security reviews it, legal signs a data processing agreement, the vendor lands on your subprocessor register, and monitoring picks it up. Shadow AI walks in through the browser tab instead. When an engineer pastes source code or customer records into an unapproved model, that model becomes a data processor with none of the controls attached: no DPA, no retention terms, no training opt-out, no entry on the list your own customers are entitled to see.
The scale is not small. LayerX puts 89% of enterprise AI usage outside any organizational visibility, with 71% of GenAI access running through personal, non-corporate accounts. Netskope's 2026 telemetry finds 47% of workplace GenAI users on personal, unmanaged accounts. IBM's 2025 breach data ties it to real losses: one in five breaches involved shadow AI, adding about $670,000 to the average cost.
This is the same trust-boundary failure the MCP post described. The boundary here is an employee with a text box, not a server.
Same destination, a live data processor. One path runs every control. The other runs none of them.
Same destination, a live data processor. One path runs every control. The other runs none of them.
The riskiest third party was never onboarded.
Third-party risk management is built on an assumption: that third parties announce themselves. A vendor is requested, assessed, contracted, and listed, and the whole apparatus of review hangs off that first request. Shadow AI breaks the assumption at step one. Nobody files a request to paste a customer list into a chatbot.
So the model receiving that data becomes a subprocessor with zero governance attached. You did not assess it, so you do not know its retention policy. You did not contract it, so there is no DPA and no training opt-out. You did not list it, so the subprocessor register you owe your customers under their DPAs is now wrong. The tool works exactly as designed. The failure is that your vendor process never saw it.
Auditors have caught up. SOC 2 assessors in 2026 treat shadow AI as one of the most common AI-related findings, described plainly as engineers piping company data into unapproved tools that never passed change management, access review, or vendor oversight. The finding is not that the AI tool is bad. It is that an unvetted subprocessor is inside the boundary your report claims to describe.
The AI already inside your approved tools.
There is a second form of shadow AI that no browser-monitoring dashboard flags, because it lives inside software you already trust. A sanctioned SaaS vendor ships an AI feature, someone enables it, and a new model subprocessor is now reading the data in that tool. Microsoft 365 Copilot, Notion AI, Slack AI, and Salesforce Einstein all sit inside products that already passed your review, under contracts written before those features existed.
The vendor cleared your process. The embedded model behind its new AI feature did not. Your original assessment covered the tool as it was, not the model it quietly added. Auditors now ask for a complete AI inventory that includes embedded features precisely because this is where the subprocessor hides.
The vendor passed review. The model its AI feature added did not. The subprocessor register still shows only the vendor.
See it, then govern it.
You cannot govern a vendor you cannot see, and you cannot claim a subprocessor list is complete while shadow AI is unlisted. Work both tracks. Discovery makes the vendor visible; onboarding decides its fate.
ASee it
Make every AI use visible
1Discover shadow AI in the browser and network
Egress monitoring and browser telemetry surface which AI tools are in use and by whom. With 89% of AI usage invisible today, discovery is the control that unlocks every other one.
Closes data egress
2Inventory embedded AI in approved SaaS
Walk your sanctioned tools and list every AI feature they added after your last review, Copilot, Einstein, Notion AI, Slack AI. Each is a subprocessor question you have not answered.
Closes embedded-AI creep
3Classify what data reached each tool
Source code, PII, customer records, and credentials carry different obligations. Netskope finds 54% of GenAI policy violations involve regulated data, so the data class sets the priority.
Closes data egress
4Reconcile against your subprocessor register
Line up discovered AI processors against the list you publish to customers. Every gap is a DPA commitment you are currently missing.
Closes subprocessor gap
BGovern it
Onboard it or off-board it
1Fast-path a real review for the keepers
The useful tools get the front-door treatment on a compressed timeline: DPA, retention terms, and a training opt-out in writing before more data flows.
Closes subprocessor gap
2Block or replace the rest
Tools that cannot meet the bar get blocked at the network edge and swapped for a sanctioned equivalent, so the workflow survives without the exposure.
Closesdata egress
3Pin retention and training-opt-out terms
For every AI subprocessor you keep, get retention limits and a no-training-on-our-data commitment in the contract, not the marketing page.
Closes no deletion path
4Add it to the register and monitor for change
Approved AI processors go on the subprocessor list, and embedded-AI features get watched, so a vendor cannot add a model to your environment after you signed.
Closes embedded-AI creep
Shadow AI is third-party risk that skipped intake.
The tool an employee opened this morning is a data processor doing exactly what processors do, minus the DPA, the retention terms, and the line on the list your customers are owed. The teams that get ahead of it will treat an unapproved model the way they already treat an unapproved vendor: find it, review it, and either onboard it properly or shut the door.
Sources
01Cost of a Data Breach Report 2025, IBM
02IBM report: 97% of AI-breached orgs lacked proper AI access controls, IBM Newsroom (July 30, 2025)
03Navigating the AI rush without sidelining security, IBM Think
04Cloud and Threat Report 2026, Netskope Threat Labs
05Generative AI drives surge in workplace data breaches (Netskope 2026 figures), SecurityBrief
06State of AI Usage Report 2026, LayerX
0789% of enterprise AI usage is invisible to the organization (LayerX findings), Help Net Security
08SOC 2 for AI Companies (2026): What Auditors Test First, soc2auditors.org
09Shadow AI and SOC 2: How It Creates Audit Gaps, Linford & Company
Share






