Shadow AI
Shadow AI is AI in use that nobody is tracking or paying for centrally. It appears in the spend report on Costs → Analytics.
Shield360 decides it per vendor and per person. Use is sanctioned when the person holds a seat on a subscription from the same vendor. Anything else is shadow.
Evidence
Section titled “Evidence”Each source catches what the others miss:
| Kind | Evidence | Needs |
|---|---|---|
| Plan with no subscription on record | A coding tool reported a paid plan that no tracked seat covers. Usually a personal subscription. | Collector |
| API key, billed per token | Real per-token spend on a key that may or may not be the company’s. Marked Review, not Shadow. | Collector |
| Website | Time on an AI website. | Browsing domains or full |
| Desktop app | Time in an AI desktop application. | Collector |
| Direct API traffic | A non-browser process (a script, an app or an agent) talking to an AI provider directly, with a masked hint of the key it used if one was seen. | Network observation (+ key fingerprints) |
Browser traffic to a provider isn’t counted as direct API traffic. The same visit is already listed as a website, and counting it twice would inflate it.
Status
Section titled “Status”| Status | Meaning |
|---|---|
| Shadow | No one using it holds a seat from this vendor. |
| Review | Per-token spend. It may be a sanctioned company key, so it needs a human to confirm. |
| Sanctioned | Everyone using it holds a seat. Hidden by default; use Show sanctioned to include it. |
Each item lists who is using it (people with a seat are marked “has a seat”), on which machines, usage and value at list API rates, masked key hints, and first and last seen. Web and app use have no token count, so they carry no value.
Bringing it under management
Section titled “Bringing it under management”Use Add subscription on a shadow item to record the subscription and give those people seats. From then on, their use counts as covered and moves out of Shadow AI.