ClickCease

Something we said? Don’t leave just yet!

For more information about latest events, news and insights, leave us your email address below.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form
Dismiss

Shadow AI in financial services: why blocking doesn't work

John Denham on why blocking unapproved AI tools drives shadow AI underground, and what financial institutions should do to bring it back into view.

John Denham
September 30, 2026

Shadow AI, employees using unapproved artificial intelligence (AI) tools to do their jobs, is now one of the more uncomfortable conversations in information security. The instinct is to block, and blocking feels decisive. It rarely is. Restriction on its own treats a demand problem as a technology problem, and in financial services the demand is not going away.

‍

Why financial services is more exposed than most sectors

Financial services combines two conditions that make shadow AI almost inevitable: sustained productivity pressure and heavily regulated data environments. Employees are using AI to speed up reporting, compliance work, analysis and client communications, often faster than their organisations can put governance around it.

The scale of the gap is significant. Research found that more than 80% of workers — including nearly 90% of security professionals — use AI tools their employer has not approved. Security teams are not exempt from the behaviour they are asked to control.

When secure, approved tools are unavailable or difficult to use, people turn to public ones instead. The intent is almost always good. The outcome can still be regulated or commercially sensitive data entered into an unmanaged system. Unlike most sectors, financial institutions also carry strict audit, compliance and operational resilience obligations, which makes shadow AI a governance and regulatory risk rather than a technology inconvenience.

‍

The state of shadow AI in most organisations

The picture inside most institutions is a mix of approved and unapproved tools: generative AI assistants such as ChatGPT and Microsoft Copilot, alongside AI-powered tools for summarisation, analysis, report drafting, coding and client communications.

Common use cases are unremarkable in themselves — summarising regulatory documents, drafting emails and reports, analysing operational or financial data, automating administrative tasks and supporting software development. The difficulty is that a large proportion of these activities touch sensitive or regulated information. Without secure enterprise tooling and clear guidance, employees can unintentionally expose customer data, proprietary information or transaction-related material.

‍

How shadow AI differs from shadow IT

Shadow AI is not simply the latest version of shadow IT. Shadow IT is unauthorised technology usage. Shadow AI adds two further variables: uncontrolled data exposure through prompts, and outputs that may be wrong.

The risks compound. Sensitive data can leave the organisation in a prompt. Outputs can be inaccurate or hallucinated, biased or non-compliant. Auditability is reduced, because there is no record of what was asked, what was returned, or what informed a decision. Proprietary business logic can be exposed simply by describing it in enough detail to get a useful answer.

In financial services, strict requirements around customer communications and decision-making amplify all of this. A hallucination in a general business context is an inconvenience. In a regulated communication or a customer-facing decision, it becomes a compliance, reputational and legal problem.

‍

Why blocking AI tools does not work

Blocking AI tools tends to fail because it does not address the underlying business need. People use AI because it improves productivity and removes operational friction. If an organisation relies only on restriction, employees find workarounds through personal devices or unapproved applications — which removes the organisation's visibility of the risk without removing the risk itself.

It is worth being clear about motive. Most employees are not attempting to bypass security controls. The issue is usually the absence of a safe, practical, approved alternative. Restriction without provision converts a visible problem into an invisible one.

Bringing AI out of the shadows and into the workflows

The organisations handling this well are focused on enabling responsible adoption rather than prohibition alone. In practice that means providing secure, enterprise-approved AI tools; setting usage policies people can actually follow; training employees on safe prompting and data handling; and defining explicitly which data can and cannot be used with AI systems.

It also means monitoring usage patterns without creating a culture of fear, and maintaining human oversight for regulated communications and high-risk decisions. Encouraging employees to raise mistakes or uncertainty openly matters more than it might appear: in a regulated environment, the risk you hear about early is considerably cheaper than the one you discover in an audit.

‍

Build AI governance into what already exists

Financial institutions should extend existing security, compliance and operational risk frameworks to cover AI usage rather than treating AI governance as a separate discipline. Existing data governance and information security policies are usually the right starting point.

The National Institute of Standards and Technology (NIST) AI Risk Management Framework is a useful anchor, structured around four continuous functions — govern, map, measure and manage — rather than a one-off compliance exercise. The Cyber Risk Institute has published a financial services adaptation of it, developed with more than 100 institutions, for teams that want sector-specific control objectives.

Whichever framework is used, clear accountability, auditability and strong enterprise data controls will matter more over time. Governance must also stay practical: overly restrictive controls reliably drive more shadow behaviour, not less.

‍

The future risk of shadow AI

Shadow AI will become harder to detect, not easier. AI capability is being embedded directly into everyday workplace software, which makes the line between approved and unapproved usage progressively less visible. Add autonomous agents and multimodal tools, and the question shifts from "which tools are people using" to "what decisions are being influenced, and can we evidence them".

Regulators are moving in the same direction, with increasing emphasis on explainability, governance and operational resilience. The organisations that succeed will be those that balance innovation with visibility and control.

The goal is not to eliminate AI usage. It is to ensure adoption is transparent, governed and aligned with the organisation's risk appetite — the same standard we apply to the AI inside our compliance systems, where every output needs to be explainable and auditable to a regulator. Institutions that get this balance right will capture the productivity gains while maintaining trust, compliance and resilience.

‍

For more on why AI-ready compliance starts with the architecture rather than the algorithm, download the whitepaper: Beyond Patching

‍

John Denham is a cybersecurity executive with more than a decade of experience driving enterprise security transformation across fintech, SaaS, retail, government, and education sectors. John specialises in establishing security programmes, achieving SOC 2 Type II and ISO 27001 certifications, and enabling business growth through risk-intelligent security frameworks. John is also an expert in cloud security architecture, regulatory compliance (GDPR, PCI DSS, CCPA), and delivering measurable ROI through automated security operations and scalable governance models.