RESEARCH / REPORT
Shadow AI
The AI your organisation already runs but does not yet manage
29 pages · PDFMost organisations already have AI taking part in work outside the visibility, ownership or authority built to manage it. This report sets out where Shadow AI arises, how to discover the work rather than only the applications, and where control must move from assistance to delegated execution. It closes with a practical executive checklist and three engagement pathways.
Three signals, three different measures
These figures measure different populations and different behaviours. They must not be combined into one prevalence estimate. Read each as a signal that unmanaged use is common, not as the rate in your organisation.
What Shadow AI means
Shadow AI is AI participation in organisational work outside the proportionate visibility, authorisation, accountability or controls required for that work. Eight overlapping forms help you look beyond the application list. This is an analytical framework, not a formal classification standard.
- Shadow toolsUnreviewed applications.
- Shadow accountsUnmanaged identities or tenants.
- Shadow dataUnauthorised information flows.
- Shadow workflowsUndeclared AI participation in a process.
- Shadow automationUncontrolled scripts or integrations.
- Shadow modelsUnregistered model hosting or adaptation.
- Shadow agentsUnmanaged tools, memory or authority.
- Shadow decisionsUndeclared material influence on decisions.
The execution boundary
The control requirement changes when AI moves from assistance to delegated execution. The same interface can conceal a very different level of authority.
AI assistance
AI proposes. A person assesses and acts.
Delegated execution
AI proposes or selects. Authority is checked. The system acts.
Technical access does not establish business authority. Controls must precede the consequence they govern, including disclosure of data.
The operating response
- Discover
- Authorise
- Control
- Evidence
- Improve
Find systems, accounts, workflows and information flows. Assign owners and define permitted, conditional and prohibited actions. Apply checks before consequential actions execute, link decisions to outcomes, and use the evidence to increase useful, trusted autonomy.
From assessing to acting
- Assess your exposureTake the diagnostic to see where visibility, information, authority, control and enablement are weakest.
- Map one workflowExplain the information, authority and consequence path for one material workflow.
- Start a Shadow AI DiscoveryA bounded engagement with Oorbital to establish where AI is operating, which exposure matters and what should happen next.
Get the full Shadow AI report
A practical executive guide to discovering Shadow AI, prioritising exposure and moving from unmanaged adoption to controlled AI work.
Engagement scope, available tools and integration coverage are agreed for the customer's environment. These services do not guarantee complete discovery, legal compliance or the prevention of every incident.