Skip to content

Shadow AI

Shadow AI is AI in use that nobody is tracking or paying for centrally. It appears in the spend report on Costs → Analytics.

Shield360 decides it per vendor and per person. Use is sanctioned when the person holds a seat on a subscription from the same vendor. Anything else is shadow.

Each source catches what the others miss:

KindEvidenceNeeds
Plan with no subscription on recordA coding tool reported a paid plan that no tracked seat covers. Usually a personal subscription.Collector
API key, billed per tokenReal per-token spend on a key that may or may not be the company’s. Marked Review, not Shadow.Collector
WebsiteTime on an AI website.Browsing domains or full
Desktop appTime in an AI desktop application.Collector
Direct API trafficA non-browser process (a script, an app or an agent) talking to an AI provider directly, with a masked hint of the key it used if one was seen.Network observation (+ key fingerprints)

Browser traffic to a provider isn’t counted as direct API traffic. The same visit is already listed as a website, and counting it twice would inflate it.

StatusMeaning
ShadowNo one using it holds a seat from this vendor.
ReviewPer-token spend. It may be a sanctioned company key, so it needs a human to confirm.
SanctionedEveryone using it holds a seat. Hidden by default; use Show sanctioned to include it.

Each item lists who is using it (people with a seat are marked “has a seat”), on which machines, usage and value at list API rates, masked key hints, and first and last seen. Web and app use have no token count, so they carry no value.

Use Add subscription on a shadow item to record the subscription and give those people seats. From then on, their use counts as covered and moves out of Shadow AI.