Home Services About Blog Contact 📞 1-800-890-6133

Shadow AI Is Now an Identity Problem

By Brian Shad  ·  Pro Link Systems  ·  August 09, 2026

There is one screen in Microsoft Entra that tells an executive more about AI use inside their company than any employee survey will. Sign in to the admin center, open Enterprise Applications, filter to third-party apps, and read the list. Note-takers. Browser assistants. Resume screeners. Sales assistants. Applications nobody in finance ever saw an invoice for, holding standing permission to read mail and files.

Most executives have never looked at it. They asked their IT lead whether staff were using AI with company data, and received an honest answer assembled from what people admit to. The list in Entra is not assembled from what people admit to. It records what they clicked.

That gap is the subject. Shadow AI has largely stopped being a story about text pasted into a chat window. It is now a story about delegated access, and delegated access behaves nothing like a leaked paragraph.

Blocking the domain moved the exposure rather than shrinking it

Plenty of companies met the first AI wave the way they met consumer file sharing a decade earlier: block the domain, issue a policy, consider the matter closed. Defensible at the time. Much weaker now, for a structural reason.

AI is no longer a destination employees visit. It is a feature inside software the company already bought and already trusts. In the browser. In the CRM. In the PDF editor, the design tool, the recruiting platform, the conferencing client. When someone switches on an AI feature inside a sanctioned application, no firewall rule fires, no exception is requested, and the feature inherits whatever access that application already holds.

Our read, offered as analysis rather than fact: a ban without a sanctioned alternative made the exposure harder to see rather than smaller. Blocked domains create an internal story that the risk was handled, and that story suppresses exactly the reporting that would show where AI actually entered the business. People kept using it. They stopped mentioning it.

A consent grant is a key, not a click

The mechanic deserving executive attention is the consent screen. When an employee connects a third-party AI tool to Microsoft 365 or Google Workspace, they are usually not uploading anything. They are approving a permission request from the vendor's application — permission to read mail, read files, read calendar, sometimes to send messages on their behalf. Scopes with names like Mail.Read and Files.Read.All are not one-time favors.

Three consequences follow, and together they explain why this belongs to identity rather than data handling:

So the governance question changes shape. You are not policing sentences. You are managing a population of non-human identities that nobody onboarded, nobody reviews and nobody offboards — the same category of risk that IT security teams already spend real money on for service accounts and API keys. Entra ID includes an admin consent workflow that converts each of these grants from a click into a request that someone approves. Turning it on is a configuration task, not a project. The obstacle is rarely technical.

The notetaker on the call is a subprocessor your contracts never named

Meeting assistants spread faster than most categories because they spread by invitation. One participant adds a bot to a calendar invite, and everyone else on the call has been recorded and transcribed by a vendor they did not select and probably cannot name.

For much of the Los Angeles mid-market, that lands on legal ground before it lands on security ground. Entertainment and post-production work runs on confidentiality terms written into every deal. Law firms owe privilege. Healthcare organizations carry patient confidentiality obligations that come with HIPAA compliance and do not pause for a helpful transcription tool. Apparel, logistics and manufacturing companies sign customer NDAs specifying who may hold data and where it may live.

None of those obligations were drafted with a third-party transcription vendor in mind, and none of them care that the tool was free. An uninvited recorder on a client call is, in substance, a subprocessor nobody approved. That is a defensible reading rather than a legal opinion — but it is the reading a counterparty's lawyer will reach for, and it is cheaper to write your own rule than to answer theirs.

Copilot does not leak data, it finds what was already overshared

The sanctioned path carries its own trap, and it catches companies that did everything else right.

Microsoft is explicit that Microsoft 365 Copilot honors existing permissions: it surfaces what a given user already had the right to open. The difficulty is that in a tenant with years of accumulated sharing, what people technically have the right to open is far wider than anyone intended. The legacy company-wide sharing link. The SharePoint site inherited from a project that ended two reorganizations ago. The HR folder opened up once for convenience and never closed.

Nobody found those files before, because finding them required knowing they existed. A capable retrieval engine removes that friction. The compensation spreadsheet, the acquisition model, the disciplinary record — each becomes one plain-language question away from someone who was never meant to see it.

Permissions hygiene is therefore a precondition for AI adoption, not a follow-up task. Sensitivity labels, restricted sites, oversharing reports, and a genuine review of who inherited access to what. Unglamorous work. It is also the difference between an assistant that compounds your advantage and an incident you explain to your board.

What this should change before your next leadership meeting

The strategic error is treating shadow AI as a discipline problem. Employees are not being reckless. They found tools that made their work faster, and their employer offered nothing better. Prediction, labeled as such: enforcement-first approaches will keep losing, because shadow AI lives in the gap between the tool people are allowed to use and the tool that is available to them, and only one side of that gap is under your control.

Four moves, in order. Read the connected applications list yourself rather than hearing it summarized. Enable admin consent workflow so future grants become decisions instead of accidents. Set a standing rule on recording bots in client meetings before a client sets one for you. Remediate oversharing before switching on Copilot, not after. Then give people a fast, approved, well-supported AI path, because a good tool with governance beats a policy everyone routes around.

Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999, and identity, access and AI governance now sit together in how we run managed IT services. If you want to know what is actually connected to your tenant, that list is the place to start.

Ready to talk to a real IT engineer?

Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.