Shadow AI
Navigate real workplace scenarios where colleagues want to use AI tools with company data. Make the call — some uses are safe, some need safeguards, and some should never happen. Learn where the lines are between productivity and data exposure.
Ready to play?
Put your awareness to the test. See if you can spot the threats before it's too late.
Launch GameWhy This Matters
Shadow AI is the fastest-growing category of shadow IT. A 2026 SANS survey found that 78% of organizations report employees using AI tools that haven't been evaluated by security, while only 36% have AI governance policies in place.
The risk isn't the AI tools themselves — it's what data employees share with them. Free-tier AI services typically use inputs for model training, meaning your customer PII, source code, financial data, and trade secrets could end up in a model that serves millions of other users.
The challenge is nuance: not every AI use case is risky. Brainstorming with public information is safe. Pasting customer records into ChatGPT is a privacy violation. The difference isn't the tool — it's the data. Employees need to understand where the lines are, not just receive a blanket 'don't use AI' policy that gets ignored.
What You'll Learn
Evaluate whether specific data is safe to share with external AI tools
Distinguish between safe AI use cases (public data, generic tasks) and dangerous ones (PII, credentials, IP)
Practice redacting sensitive information before using AI assistants
Understand the governance implications of unapproved AI tool adoption