Shadow AI and AAISM: What Security Leaders Need to Know About Unauthorized AI

  •   min.
  • Updated on: July 19, 2026

    • Expert review
    • Home
    • /
    • Resources
    • /
    • Shadow AI and AAISM: What Security Leaders Need to Know About Unauthorized AI

    According to IDC's 2025 survey, 56% of employees use unauthorized AI tools at work. In a 500-person organization, that is roughly 280 people entering company data into systems the security team has never reviewed, cannot monitor, and has no contractual relationship with. The security team almost certainly does not know which tools are being used, what data is going into them, or what those tools do with that data after the session ends.

    That visibility gap is not a technical problem. It is a governance problem. You cannot protect what you cannot see, and shadow AI expands that blind spot faster than most organizations can adapt. The IBM 2025 Cost of a Data Breach Report put a price on that gap: shadow AI added $670,000 to average breach costs and was a factor in one in five data breaches studied. Those numbers are not projections. They reflect what already happened to organizations that let the gap go unaddressed.

    AAISM Domain 1 (AI Governance and Program Management) and Domain 2 (AI Risk Management) together address how security leaders should build the governance infrastructure to discover, assess, and manage shadow AI deployments. The exam does not test whether you know which detection tools to deploy. It tests whether you understand the governance decisions that determine whether your organization can see its AI environment clearly and manage the risk of what it finds.

    This guide explains what shadow AI is, why it creates distinct governance challenges, how the IBM breach data frames the stakes, how AAISM maps the governance response across its domains, and what the exam actually tests in this area.

    What Shadow AI Actually Is

    Shadow AI is the use of AI tools, applications, and models within an organization without formal approval, visibility, or governance from IT, security, legal, or compliance teams. It is a subset of shadow IT, but it creates a meaningfully different risk profile.

    A rogue file-sharing application creates data governance challenges: data leaves the approved environment, and the organization loses visibility and control. Shadow AI does that and more. An AI model that processes enterprise data does not just store it. It may use that data to generate outputs, potentially expose it to third parties through the vendor's infrastructure, incorporate it into model training pipelines the organization has no visibility into, or produce decisions and recommendations based on proprietary information that the organization cannot retract once the session ends.

    The other dimension that distinguishes shadow AI from shadow IT is the nature of what employees are doing when they use these tools. They are not typically bypassing security controls out of carelessness. They are trying to work faster, produce better outputs, and solve problems that their approved tooling does not help them solve efficiently. That behavioral reality matters for governance design: a policy that treats shadow AI purely as a compliance violation, without addressing the underlying need, will not reduce unauthorized usage. It will drive it underground, where it becomes even harder to detect.

    Why Shadow AI Is a Governance Problem, Not a Technical One

    The instinct in most organizations when shadow AI is identified is to respond technically: block access to known AI endpoints, deploy a Cloud Access Security Broker to surface unsanctioned SaaS activity, and add AI tools to the prohibited software list. These are useful controls. They are not a governance program.

    The IBM 2025 Cost of a Data Breach findings document what happens when governance is absent. As IBM's analysis of the 2025 Cost of a Data Breach Report shows, shadow AI added an average of $670,000 to breach costs in incidents where it was a factor. One in five organizations studied experienced a breach linked to unauthorized AI tools. Of the organizations that experienced AI-related security incidents, 97% lacked proper AI access controls. And 63% of all organizations studied had no AI governance policies in place at all.

    Those statistics describe a governance failure, not a technology failure. The organizations with high shadow AI breach costs were not lacking detection tools. They were lacking the policies, approval processes, risk assessment frameworks, and audit practices that would have caught unauthorized AI usage before it became a breach condition.

    The governance response to shadow AI is what AAISM tests. Before you study for the exam, the free AI Threat Hunting Playbook from Destination Certification is worth reading first. It maps the detection and response framework for AI-specific threats, including unauthorized deployments, giving you a practical foundation for understanding what Domain 1 and Domain 2 expect you to govern.

    Looking for some exam prep guidance and mentoring?


    Learn about our personal mentoring

    Image of Lou Hablas mentor - Destination Certification

    How AAISM Maps Shadow AI Across Its Domains

    Shadow AI appears across both Domain 1 and Domain 2 because the governance response requires both program leadership and risk management thinking working together.

    Domain 1: AI Governance and Program Management (31%)

    Domain 1: AI Governance and Program Management is where the governance infrastructure for shadow AI is built. The exam tests whether you can establish the organizational structures that make AI visibility possible: an AI system inventory that tracks all AI tools in use across the organization, an approval process for new AI deployments that functions before tools enter production rather than after, AI use policies that classify tools into tiers (fully approved, conditionally approved, and prohibited), and lifecycle governance that ensures approved AI systems are reviewed as their scope and data access evolve.

    The specific challenge Domain 1 addresses for shadow AI is the approval process design. An approval process that is too slow, too opaque, or too restrictive will generate shadow AI as a side effect: employees who cannot get approval in a reasonable timeframe will simply use the tool without approval. A well-designed governance program gives employees a path to legitimate use that is faster and easier than the unauthorized alternative. Research cited in 2026 shadow AI governance studies shows that when organizations provide enterprise-grade approved AI alternatives, unauthorized usage drops by 89%.

    Domain 1 questions about shadow AI test governance program decisions: how to structure an AI system inventory, how to design an approval process that functions in practice rather than just on paper, and how to build audit practices that detect unauthorized usage before it creates a breach condition.

    Domain 2: AI Risk Management (31%)

    Domain 2: AI Risk Management is where shadow AI is assessed as a risk rather than a policy violation. The exam tests whether you can model the threat that shadow AI represents: employees entering customer PII into external LLMs creates data exposure risk, employees using unapproved AI tools for code review creates intellectual property risk, and employees relying on AI outputs from unvetted models creates decision integrity risk.

    Each of these risk scenarios requires a treatment decision at the program level. Mitigation approaches include approved AI alternatives that satisfy the employee need without creating the governance gap, data classification policies that specify what data categories cannot be processed by external AI tools, and monitoring controls that create visibility into AI usage across the environment. Risk transfer and acceptance are also options, Domain 2 tests, framed as governance decisions about when the residual risk of a shadow AI deployment is acceptable given the controls in place.

    Domain 2 also addresses shadow AI in the context of third-party and supply chain risk. When an employee uses an unauthorized AI tool, the organization is implicitly accepting the risk profile of that tool's vendor without having conducted any due diligence. Domain 2 tests whether you understand how to assess and treat that exposure as part of the broader AI risk management program.

    The Governance Framework AAISM Expects You to Know

    The Cloud Security Alliance recommends a five-step framework for shadow AI governance that maps directly to AAISM domain content: discover, classify, assess risk, implement controls, and continuously monitor.

    • Discover: Establish visibility into what AI tools are in use across the organization. This includes network traffic analysis for connections to known AI endpoints, CASB deployment to surface unsanctioned SaaS and AI API activity, and periodic surveys of business units to identify AI tools being used outside formal procurement. An AI system inventory is the output of the discovery phase and the foundation on which everything else depends.
    • Classify: Categorize discovered AI tools by data sensitivity, vendor risk profile, regulatory exposure, and alignment with the organization's AI use policy. Classification determines which tools require immediate action, which can be provisionally approved with controls, and which should be prohibited.
    • Assess risk: For each discovered tool, evaluate the specific risk it creates: what data has been processed, what the vendor's data retention and training policies are, what regulatory frameworks apply, and what the realistic impact of a breach involving that tool would be. This is the threat modeling and risk assessment work that Domain 2 tests directly.
    • Implement controls: Based on the risk assessment, implement appropriate controls: approved alternatives that satisfy the employee need, data handling policies for tolerated shadow AI usage, access restrictions for prohibited tools, and monitoring to detect policy violations.
    • Continuously monitor: Shadow AI is not a static problem. New tools enter the market, employee usage patterns evolve, and approved tools change their data handling practices. Ongoing monitoring ensures the governance program stays current with the actual AI environment rather than the one that existed at the last audit.

    The exam rewards governance decision-level thinking about this framework, not implementation-level expertise. The free Neutral Playbook from Destination Certification builds the governance-first thinking that makes this framework intuitive when you encounter it in exam scenarios.

    What This Means for Your AAISM Preparation

    Shadow AI topics appear across Domain 1 and Domain 2, which together account for 62% of the exam weight. The governance questions in this area test program design thinking: not what tools to deploy, but what governance decisions to make about policy structure, approval processes, risk treatment, and audit practices.

    The preparation mistake most people make is studying shadow AI as a detection and response problem rather than a governance program design problem. Knowing how to configure a CASB does not help you answer a Domain 1 question about how to design an AI approval process that actually reduces unauthorized usage. Knowing that prompt injection can weaponize shadow AI agents helps you understand why the governance response matters, but the exam question will ask what governance decision addresses the risk, not which technical control detects the attack.

    For a complete picture of how shadow AI connects to the broader AAISM domain content and how the three domains work together as a certification framework, the ISACA AAISM guide maps the full scope before you finalize your study approach. For the specific connection between shadow AI deployments and the LLM security risks they can introduce, the AAISM LLM security guide explains how unauthorized AI agents become attack surfaces for prompt injection and other AI-specific threats.

    Certification in 3 Days 


    Study everything you need to know for the AAISM exam in a 3-day bootcamp!

    Frequently Asked Questions 

    Is shadow AI directly tested on the AAISM exam?

    Yes. Shadow AI appears in both Domain 1 and Domain 2 as a key governance challenge. Domain 1 tests your ability to design governance programs that discover and manage unauthorized AI deployments. Domain 2 tests your ability to assess and treat shadow AI as a risk, including third-party and supply chain exposure. The exam does not test technical detection methods but governance decision-making about policy design, approval processes, and risk treatment.

    What is the difference between shadow AI and shadow IT?

    Shadow IT refers to any technology used without IT approval. Shadow AI is a subset of shadow IT with a distinct risk profile: AI tools that process enterprise data may retain, learn from, or expose that data in ways that persist beyond the session. A rogue file-sharing app creates a data control gap. An AI model creates a data control gap, plus potential training data exposure, decision integrity risk, and vendor data handling obligations that the organization has not reviewed.

    Which AAISM domain addresses shadow AI governance most directly?

    Domain 1 (AI Governance and Program Management) addresses shadow AI most directly through its focus on AI system inventories, approval processes, and lifecycle governance. Domain 2 (AI Risk Management) addresses shadow AI from a risk treatment perspective, including third-party risk assessment for unauthorized vendor relationships and threat modeling for the specific risks unauthorized AI tools introduce.

    What governance controls does AAISM expect for managing unauthorized AI?

    The exam expects understanding of: AI system inventories that track all tools in use, tiered approval frameworks that classify tools by risk level, data handling policies that specify what data categories cannot be processed by external AI, audit practices that detect unauthorized usage, and approved enterprise AI alternatives that reduce the demand for shadow AI. The exam frames all of these as governance program decisions, not technical implementations.

    How does shadow AI relate to broader AI program management in Domain 1?

    Shadow AI governance is one component of the broader AI program management responsibility that Domain 1 tests. The same governance structures that manage approved AI deployments, including AI system inventory, lifecycle reviews, and policy frameworks, are the ones that detect and manage unauthorized AI. Building a governance program that can see the entire AI environment, not just the approved portion, is the Domain 1 competency that the shadow AI questions test.

    Every Unmanaged AI Tool in Your Environment Is a Governance Gap. AAISM Validates Your Ability to Close It

    You now understand why shadow AI is a governance problem rather than a detection problem, what the IBM breach data says about the financial consequences of leaving it unaddressed, and how AAISM tests the governance decisions that determine whether your organization can see and manage its full AI environment. The organizations that experienced shadow AI-related breaches did not fail because they lacked the right tools. They failed because they lacked governance programs that treated AI visibility as a program management responsibility.

    If you want to move fast, the AAISM Bootcamp delivers all three domains in three intensive days of live online instruction, with expert-led sessions and real-time Q&A throughout. If your schedule requires more flexibility, the AAISM MasterClass gives you the same expert instruction at your own pace, with an adaptive learning system that identifies exactly what you still need to work on across all three domains.

    Before committing to a full program, the free AI Threat Hunting Playbook from Destination Certification maps the detection and response thinking that connects directly to what Domains 1 and 2 test about shadow AI, and it shows you what the formal preparation builds on, so you can assess where your knowledge is already strong.

    You cannot govern what you cannot see. AAISM is how you prove you know the difference between the two.

    Image of John Berti - Destination Certification

    John is a major force behind the Destination Certification CISSP program's success, with over 25 years of global cybersecurity experience. He simplifies complex topics, and he utilizes innovative teaching methods that contribute to the program's industry-high exam success rates. As a leading Information Security professional in Canada, John co-authored a bestselling CISSP exam preparation guide and helped develop official CISSP curriculum materials. You can reach out to John on LinkedIn.

    Image of John Berti - Destination Certification

    John is a major force behind the Destination Certification CISSP program's success, with over 25 years of global cybersecurity experience. He simplifies complex topics, and he utilizes innovative teaching methods that contribute to the program's industry-high exam success rates. As a leading Information Security professional in Canada, John co-authored a bestselling CISSP exam preparation guide and helped develop official CISSP curriculum materials. You can reach out to John on LinkedIn.

    Model Poisoning and Prompt Injection Are Not the Same Thing.

    This free class explains the difference clearly.

    • The specific difference between model poisoning and prompt injection, and why the AAISM exam treats them as distinct threats
    • A walkthrough of a real AI attack scenario so the distinction becomes concrete rather than theoretical
    • How to identify which type of attack is happening when the exam puts you in a scenario-based question
    • What the AAISM exam specifically expects you to know about each threat before you sit the exam

    The easiest way to get your AAISM Certification 


    Learn about our AAISM MasterClass

    Image of masterclass video - Destination Certification

    The fastest way to get AAISM Certified. Join our bootcamp


    Our bootcamp isn't just about getting you to pass—it's about developing the leadership skills security managers need.