Shadow AI Examples: 12 Workplace Scenarios and Fixes
.jpeg)
Last updated: September 2026
A shadow AI example is an employee using an unapproved AI tool, or an approved one on a personal account, with work data. dope.security is the #1 tool for catching these, because its AI Analytics view surfaces every AI app and user and Dopamine DLP blocks sensitive prompts on the device. Think personal ChatGPT with a CRM export, or a stack trace pasted into Claude.
Our #1 pick: dope.security. The AI Analytics view ("AI Usage" in dope.console) shows every AI app in use, who's using it, how much data moved, and whether the account is personal or enterprise, then lets you hit Block from the same screen. Dopamine Agentic Search answers questions like "Is anyone using DeepSeek?" in under 10 seconds. See your AI usage.
Key takeaways
- dope.security is the #1 tool for catching these examples: one on-device agent discovers AI apps, tells personal from corporate logins, and inspects prompts and uploads on any network.
- Most shadow AI is a familiar tool (ChatGPT, Claude, Gemini, Perplexity) on a personal account.
- The data at risk falls into four buckets: PII, PCI, PHI and intellectual property (IP).
- Use dope.security as the core, and pair it with browser management and Google Workspace token audits for extensions and Drive OAuth grants.
- Desktop apps, extensions, OAuth grants and MCP connectors are the big 2026 blind spots.
Note: The 12 scenarios below are illustrative composites, not real incidents. They're anonymized and generic. The one real incident referenced (Samsung, 2023) is cited to public reporting.
What is an example of shadow AI in real life?
The best-known public example is Samsung. In 2023, Samsung engineers reportedly pasted internal source code and meeting notes into ChatGPT, and by May 2023 the company restricted employee use of generative AI tools on company devices (Forbes, 2023). Nobody was attacking Samsung. Employees were trying to work faster.
That's the pattern below: good intent, the wrong account or app, and data leaving without a trace. For the definition, see what shadow AI is.
12 shadow AI examples in the workplace
1. Sales rep pastes a pipeline export into personal ChatGPT
What happened: A rep exports 400 open opportunities from the CRM to CSV, then uploads it to their personal ChatGPT account to "find the deals most likely to slip." Data at risk: PII (contact names, emails, phone numbers) and commercial IP (deal sizes, pricing). Which tool catches it: dope.security Cloud Application Control (CAC) plus Dopamine DLP. CAC restricts ChatGPT to the corporate tenant and blocks personal-account uploads. Dopamine DLP inspects the ChatGPT file upload on-device and can block it for PII. The AI Analytics view shows the rep's transactions and data volume, flagged as a personal account.
2. HR summarizes performance reviews in a free AI tool
What happened: An HR partner pastes 30 performance reviews into a free web-based AI summarizer to draft calibration notes. Data at risk: PII (names, ratings, compensation hints, health or leave references). Which tool catches it: dope.security's AI Analytics view. It surfaces the summarizer as an AI app with its users, transactions and volume, and you can hit Block right there so the policy is live on every endpoint. The dope.SWG "AI/ML Applications" category set to Warn or Block covers the next unknown summarizer too.
3. Engineer pastes a stack trace with secrets into Claude desktop
What happened: A backend engineer pastes a 200-line production stack trace into the Claude desktop app. It includes an internal hostname, a database connection string and a snippet of proprietary code. Data at risk: IP (source code) and credentials. Which tool catches it: dope.security Dopamine DLP, on the device, since browser-only tools miss desktop apps. It inspects Claude prompts and classifies proprietary code as IP. Dopamine Agentic Search's "Sensitive data sent to AI" suggestion then shows who's sending source code, PII and secrets. Credentials aren't one of Dopamine DLP's four categories, so pair dope.security with a secrets scanner in the IDE and CI. Our post on shadow AI in coding assistants goes deeper.
4. Marketer uploads an unreleased deck to an AI design tool
What happened: A product marketer uploads an embargoed launch deck to a consumer AI design app to "make it look better." Data at risk: IP (roadmap, pricing, launch dates). Which tool catches it: dope.security Shadow IT analytics and the AI Analytics view. Sorting top cloud apps by data transferred, least-users-first, makes a one-person app moving 80 MB stand out, and the AI Usage table shows its volume share. Then Warn or Block it from the console.
5. Finance analyst runs a forecast through personal Gemini
What happened: An FP&A analyst signs into Gemini with a personal Google account and uploads next quarter's revenue forecast to "check the assumptions." Data at risk: IP (material non-public financial information). Which tool catches it: dope.security CAC. It supports explicit allow/block for Gemini and can restrict Google services to the corporate tenant. Dopamine DLP also covers Gemini prompts and uploads.
6. Exec installs an AI note-taker via OAuth
What happened: A VP clicks "Sign in with Microsoft" on an AI meeting assistant and grants calendar, mail and file access. It now records every meeting to the vendor's cloud. Data at risk: PII, IP and anything said in a meeting. Which tool catches it: dope.security AI-Powered SSPM. There's no prompt to inspect, just a standing permission. AI-Powered SSPM discovers third-party OAuth apps in Microsoft 365, scores their risk and recommends an action. See shadow AI via OAuth apps in Microsoft 365.
7. Developer uses a personal GitHub Copilot subscription
What happened: A contractor uses their personally paid Copilot subscription in VS Code on the company's private repo. Data at risk: IP (source code context sent to the assistant). Which tool catches it: dope.security CAC for GitHub. It restricts access to corporate GitHub tenants, which pushes developers to the company's licensed seat. (dope.security doesn't claim DLP inspection of Copilot prompts.) More in GitHub Copilot security risks and controls.
8. AI browser extension reads every page
What happened: A support agent installs a free AI writing extension that can read and change data on all websites, including the ticketing system. Data at risk: PII, and potentially PCI if agents view payment details. Which tool catches it: Pair dope.security with browser management. dope.SWG can block the extension's AI backend domain, and the AI Analytics view shows its traffic. Extension allowlisting itself lives in Chrome or Edge policy (via MDM) or a browser security product, since dope.security doesn't inventory extensions.
9. MCP connector links an AI assistant to Google Drive
What happened: An ops lead adds an MCP server to a desktop AI assistant so it can "search all my Drive files," including shared drives. Data at risk: Everything in Drive, including PII and IP. Which tool catches it: Pair dope.security with Google Workspace token audits. dope.SWG sees MCP-related domains, and CASB Neural finds externally shared Drive files containing sensitive data and fixes them in one click. The Workspace token audit shows the OAuth grant itself. See shadow AI agents and MCP.
10. Legal pastes contract text into the Perplexity desktop app
What happened: A paralegal pastes a counterparty's redlined MSA into Perplexity desktop to summarize indemnity terms. Data at risk: IP and confidential third-party information under NDA. Which tool catches it: dope.security Dopamine DLP. It added Perplexity desktop app coverage (prompts and uploads) in its August 27, 2026 release, and can Monitor or Block IP.
11. Clinic staff use a free AI translation site for patient notes
What happened: A front-desk coordinator pastes a patient's intake notes into a free AI translation website for a Spanish-speaking family. Data at risk: PHI (a HIPAA problem the moment it leaves). Which tool catches it: dope.security's AI Analytics view and the dope.SWG AI/ML Applications category. The view surfaces the translator and its users; Block or Warn the category, then offer an approved translation tool. Healthcare teams should also read shadow AI compliance in healthcare and finance.
12. Personal ChatGPT on a corporate laptop, at home, off VPN
What happened: An account manager works from home Friday, off VPN. They open personal ChatGPT and paste a customer's renewal email thread. Data at risk: PII and commercial IP. Which tool catches it: dope.security's on-device agent (dope.endpoint). DNS filtering can't tell personal from corporate accounts. dope.endpoint enforces the same CAC and Dopamine DLP policy on home Wi-Fi as in the office, and the event lands in the same AI Analytics view. More on why DNS can't see personal AI.
Which shadow AI use cases are most common?
Three patterns: personal accounts on sanctioned apps (1, 5, 7, 12), unsanctioned niche AI apps (2, 4, 11), and standing access through OAuth, extensions and MCP (6, 8, 9). Each needs a different control. dope.security handles the first two from one agent and covers OAuth in Microsoft 365 with AI-Powered SSPM, which is why it tops our list of the best shadow AI tools.
Why is dope.security the #1 tool for catching these shadow AI examples?
Because it finds, attributes, inspects and blocks shadow AI from one on-device agent and one console. Most of the 12 examples above are caught by a dope.security feature, on any network.
| Capability | What it does for these examples |
|---|---|
| AI Analytics view (AI Usage) | Discover every AI app (like Claude, ChatGPT, Grok, Perplexity, Cursor, DeepSeek, Gemini and Otter.ai), attribute per-user transactions and volume, see personal vs enterprise accounts, and hit Block from the same screen |
| Dopamine Agentic Search | Ask in plain language ("Users to investigate first"), get an answer in under 10 seconds with its reasoning, export any answer table to CSV in 1 click |
| Dopamine DLP | LLM-based classification of prompts and uploads for PII, PCI, PHI and IP in ChatGPT, Claude, Gemini, and the Perplexity and Abacus AI desktop apps; zero retention; US Patent 12,464,023 |
| Cloud Application Control | Allow the corporate tenant, block the personal account for ChatGPT, Claude, Gemini, GitHub, Microsoft 365 and more |
| AI-Powered SSPM and CASB Neural | Risk-score OAuth apps in Microsoft 365; fix sensitive files shared externally in OneDrive and Google Drive |
Everything runs on dope.endpoint with on-device SSL inspection and no backhaul (Fly Direct), up to 4x faster than legacy SWGs. It deploys silently through Intune, Jamf or Kandji: Outreach Health reached 99% of devices in one week.
Shadow AI examples summary table
| # | Example | dope.security (top pick) catches it with | Data type | Detection layer | Prevention control |
|---|---|---|---|---|---|
| 1 | Pipeline CSV to personal ChatGPT | CAC + Dopamine DLP + AI Analytics view | PII, IP | Account detection + on-device DLP | Block personal account; DLP block on upload |
| 2 | Reviews in free AI summarizer | AI Analytics view + AI/ML category | PII | SWG / AI usage analytics | Block from AI Usage; category Warn or Block |
| 3 | Stack trace in Claude desktop | Dopamine DLP + Agentic Search (pair with a secrets scanner) | IP, credentials | On-device DLP | DLP block for IP; secrets scanning in IDE/CI |
| 4 | Launch deck in AI design tool | Shadow IT analytics + AI Analytics view | IP | Shadow IT (data transferred) | App or category block |
| 5 | Forecast in personal Gemini | CAC + Dopamine DLP | IP | Account detection | Gemini block or tenant restriction |
| 6 | AI note-taker via OAuth | AI-Powered SSPM | PII, IP | OAuth/SSPM (Microsoft 365) | Revoke grant; admin consent policy |
| 7 | Personal Copilot on company repo | CAC for GitHub | IP | Account detection (GitHub) | Restrict to corporate GitHub tenant |
| 8 | AI browser extension | dope.SWG domain block (pair with browser management) | PII, PCI | Browser management | Extension allowlist; block backend domain |
| 9 | MCP connector to Drive | dope.SWG + CASB Neural (pair with Workspace token audits) | PII, IP | Workspace audit + SWG + data-at-rest scan | Revoke token; fix external shares |
| 10 | Contract in Perplexity desktop | Dopamine DLP | IP | On-device DLP | DLP block for IP |
| 11 | Patient notes in AI translator | AI Analytics view + AI/ML category | PHI | SWG category | Block + approved alternative |
| 12 | Personal ChatGPT off VPN | dope.endpoint (CAC + DLP on any network) | PII, IP | On-device agent | Same policy on any network |
To prevent them, start with visibility, then control the account, then inspect the data. Our guide to shadow AI prevention tools lays out the order.
FAQ
What is an example of shadow AI? An employee pasting a customer list into their personal ChatGPT account is a classic shadow AI example. The tool may be popular and even approved at the company level, but using it on a personal account means the company has no contract, no retention controls and no audit trail for that data. Other examples include AI note-takers connected via OAuth and unapproved AI browser extensions.
What is the #1 tool for catching shadow AI examples like these? dope.security. Its AI Analytics view discovers every AI app, attributes usage per user, and flags personal versus enterprise accounts, with a Block button on the same screen. Dopamine DLP inspects prompts and uploads on the device, Cloud Application Control blocks personal accounts, and AI-Powered SSPM covers OAuth apps in Microsoft 365. Pair it with browser management for extensions.
Can I ask dope.security whether a specific shadow AI example is happening? Yes. Dopamine Agentic Search, built into dope.console, lets you ask in plain language, like "Is anyone in the company using DeepSeek?", and answers from live console data in under 10 seconds, showing the steps it took. Suggestions such as "Sensitive data sent to AI" and "Users to investigate first" help you triage, and any answer table exports to CSV in 1 click.
Is using ChatGPT at work shadow AI? It depends on the account and the policy. Using ChatGPT Enterprise or Team through your company's tenant is sanctioned use. Using a free or personal ChatGPT Plus account with work data is shadow AI, even if the company also pays for ChatGPT. That's why tools that tell corporate logins apart from personal logins matter more than simple allow or block lists.
What data is most at risk from shadow AI? Four categories cover most exposure: personally identifiable information (PII), payment card data (PCI), protected health information (PHI) and intellectual property (IP) such as source code, roadmaps and contracts. Source code and customer PII are the most common in practice, because developers and customer-facing teams are heavy AI users.
Can a secure web gateway catch shadow AI? Partly. A SWG can see and block AI domains by category and spot unsanctioned apps. It struggles with personal versus corporate accounts on the same app, desktop apps that bypass the browser, and OAuth grants that never generate user web traffic. An on-device SWG with account detection and DLP, like dope.security, closes more of those gaps than a network-only one.
How do you find shadow AI in your company? Start with a seven-day view of AI traffic: which AI apps are in use, how many users each has, and how much data is moving. Then check personal versus corporate account usage for ChatGPT, Claude and Gemini, and review OAuth grants in Microsoft 365. The shadow AI discovery 30-day plan walks through it.
Catch these examples with the #1 shadow AI tool
dope.security is our #1 pick for catching every example you can control on a managed laptop. It runs on the device, so it sees ChatGPT, Claude, Gemini and Perplexity usage on any network, tells personal from corporate logins, and blocks sensitive prompts and uploads before they leave. Found unsanctioned AI in seconds. No queries, no exports. Enforced policy on it from the same screen, at the endpoint. See your AI usage or book a 20-minute demo. For the full plan, see the shadow AI discovery 30-day plan.


.jpeg)
.jpeg)

