Shadow AI follows the same pattern as shadow IT before it: employees find a free or personal AI tool that helps them get work done faster and start using it, often with real customer data or internal documents, without anyone in security knowing it is happening. It usually comes from a genuine gap, not bad intent, such as slow approval for sanctioned tools.
The risk is less about the AI itself and more about where company data ends up and under what terms. The response that actually works is not banning AI outright, since that pushes usage further underground, but publishing an AI acceptable use policy with approved options and a fast way to request a new tool.