





Shadow AI is any AI in use that the organization cannot see or govern. On an endpoint that means AI agents, models, MCP servers, Skills, plugins and connectors installed or run without IT approval - plus approved tools being used in ways nobody sanctioned. It's the AI equivalent of shadow IT, with one important difference: these components can read files, execute commands and reach enterprise systems on their own.
Shadow IT is unapproved software. Shadow AI is unapproved software that acts. A spreadsheet tool someone installed without asking doesn't make decisions, invoke tools, or reach into a code repository on its own - an agent with an MCP server and a connector does. The governance question moves from what is installed to what can it do, and with whose permissions.
That's the browser half, and it's the easier half. The harder problem runs on the endpoint: agents with filesystem access, MCP servers connected to internal systems, Skills installed like browser extensions, and models running locally. None of it crosses a network gateway in a way DLP or a CASB can read, which is why most shadow AI programs see only part of the picture.
The application stays legitimate and the governance disappears. To the operating system, an employee signed into Claude with a personal account looks identical to one signed in with the corporate account - but the organization's data, activity and audit trail are no longer under enterprise control. This is the most common form of shadow AI and the hardest for conventional tooling to detect.
By inventorying the endpoint itself rather than the network. That means discovering every AI agent, model, MCP server, Skill, plugin and connector actually running, mapping who uses each one, what permissions it holds, and what data and systems it can reach - including anything installed outside security oversight. Backslash does this continuously, because the surface changes daily.
More than the inventory shows. The 2026 SANS AI Survey found that 63% of practitioners cannot see where AI is running or what it can reach, only 41% of organizations use generative AI under strict policy, and 39% report AI use with no policy at all. A first discovery pass almost always surfaces agents, models and accounts nobody had registered.
Only partially. EDR sees an approved application running as an approved process. A gateway sees traffic to a legitimate provider domain. A CASB sees a sanctioned SaaS tool. None of them evaluate which tenant the session belongs to, which MCP servers are attached, which Skills loaded, or whether the account is corporate or personal - and that is where shadow AI actually lives.
Shadow MCP is an MCP server connected to an agent without review, inventory or an owner. They install in seconds, they grant agents access to files, databases, APIs and SaaS applications, and they carry their own code and permissions. Backslash has assessed more than 81,000 public MCP servers, and the risk distribution is not reassuring.
No, it usually creates more of it. When the sanctioned path is slow or closed, people find their own, and the usage moves somewhere you can see even less - personal accounts, unmanaged installs, and workspaces outside the organization entirely. Shadow AI drops when approval becomes fast and enforcement becomes real, not when the answer becomes no.
Make visibility the first control, not the last. Once you can see every agent, MCP server and Skill in use and score what each one carries, security can allow-list quickly and deny by default instead of blocking indefinitely. That turns AI governance from a review queue into a control layer, and it's what lets a security team say yes.