Abdolmadjid Masoomi

The Hidden Infrastructure of Shadow AI

An unapproved tool inherits the reach of the systems it sits upstream of

Signed
Abdolmadjid Masoomi
Published
2026-09-12
Length
3 min read · 548 words
Status
opinion

Staff paste sensitive material into endpoints nobody approved. The exposure is not the pasting — it is that those endpoints sit upstream of pipelines the organisation does control, so an unsanctioned tool acquires reach it was never granted.

This is a product failure first

Nobody bypasses the sanctioned tool out of malice. They bypass it because it is slower, or narrower, or behind an approval that takes three days for an answer they need this afternoon.

The organisation built a wall without building a gate that opens at the speed of the work. What follows is not indiscipline. It is people routing around an obstacle, which is what people do.

Treating it as a training problem misreads the cause, and every remedy that follows from that misreading fails for the same reason.

What actually leaves

Less obvious than the text, and more useful to somebody else.

The file names. A document called Q3-restructure-legal-review discloses its contents without being opened.

The client names. Often in the first line, because that is how the question makes sense.

The shape of the thing. Headings, section counts, the order of an argument. Enough to reconstruct what is being planned without a single sentence of it.

The pasted paragraph is the part people worry about. The surrounding metadata is the part that generalises.

Why it is hard to see

It is ordinary HTTPS to an ordinary domain.

The destination is not on any block list, because it is a popular consumer service that most of the workforce has a legitimate personal reason to visit. The payload is encrypted. The volume is unremarkable.

Nothing about the traffic distinguishes an employee reading an article from an employee pasting a contract into a text box. A perimeter built to spot known-bad destinations has no opinion about this at all.

The reach it inherits

Here is the part that makes this structural rather than careless.

Once a tool is in the habit of being used, it acquires connections. Somebody wires it to a shared drive to save the copy-paste. Somebody grants it a calendar scope so it can schedule. Somebody gives it a token because a workflow needed one.

Each grant is small and locally reasonable. Together they mean an endpoint outside the organisation's control now reads from systems inside it, on credentials issued for a different purpose.

The paste was never the exposure. It was the introduction.

What helps, and what only sounds like it does

Egress inspection at the boundary works, because it acts on what leaves rather than on where it is going. It is also the expensive answer, and it does not see a phone camera pointed at a screen.

Auditing token grants works, and is the measure most often skipped. The connections above are enumerable, and almost nobody enumerates them.

Making the approved path faster is the only measure that removes the incentive rather than fighting it. It is also the one that requires budget rather than a memo.

A policy document changes nothing, because the incentive is unchanged. So does training, on its own. Both are cheap, both are visible to an auditor, and neither addresses why the behaviour exists.

That last pairing is the tell. A control that is easy to evidence tends to outlive a control that is effective.

Close

The question is not which tools people are using without permission.

It is what those tools have quietly been given access to since, and whether anybody has written that list down.