Our Expertise

How We Help

We partner with teams from initial strategy through production delivery - across automation, AI, data, and cloud.
Icon

Intelligent Process Automation

Modernizing operations through automation-first redesign.
Frame

Platform Architecture & Governance

Custom automation, integrations, and application build-outs.
Icon

Enterprise AI & Copilot Systems

Applied AI for decision support, forecasting, and intelligence.
Icon

Data & Decision Intelligence

Data platforms, cloud automation, and scalable architecture.
Frame

Consulting

Strategy, assessments, roadmaps, and executive alignment.
Icon

Process Insights

Process discovery, bottleneck analysis, opportunity identification.

Shadow AI governance is the practice of discovering, assessing, and controlling the generative AI tools and agents your employees use without IT approval — before that unsanctioned use turns organizational data into a breach. The fastest path in Microsoft 365 is a discovery-first sequence: find the AI apps already in use with Microsoft Defender for Cloud Apps, block the ones that fail review, stop sensitive data from reaching the rest with Microsoft Purview, and then govern every prompt and response with an audit trail. You cannot govern what you cannot see, so visibility comes before any block.

This guide is written for the IT directors, security leads, and platform owners who already run Microsoft 365 and now have to answer a board-level question: what AI is touching our data, and who approved it? It maps the exact Microsoft-native controls, the order to deploy them, and the governance gaps that even a well-configured tenant leaves open in 2026.

Key takeaways

  • Shadow AI is now a measurable breach driver. IBM's Cost of a Data Breach Report 2025 found shadow AI was involved in 20% of breaches and added roughly $670,000 to the average breach cost.
  • The problem is missing controls, not the tools themselves. 97% of organizations that suffered an AI-related breach lacked proper AI access controls, and 63% had no AI governance policy or were still writing one.
  • Microsoft ships a defined four-step model. Purview's "Prevent data leak to shadow AI" blueprint runs Discover, Block unsanctioned, Block sensitive data to sanctioned, then Govern — using Defender for Cloud Apps, Entra, Intune, and Purview together.
  • Discovery must come first. Defender for Cloud Apps cloud discovery, filtered to the generative AI category, turns unknown usage into an inventory you can act on.
  • Internally built agents are shadow AI too. Citizen-developer agents in Power Platform and Copilot Studio need the same governance as consumer ChatGPT, enforced through DLP data policies and Managed Environments.
  • Governance is continuous. New AI apps appear constantly, so discovery, DSPM for AI monitoring, and audit review are ongoing operations, not a one-time cleanup.

What is shadow AI, and why is it a governance problem now?

Shadow AI is the use of AI tools — especially generative AI — by employees without the knowledge, approval, or governance of IT or security, as Microsoft defines it in its own Purview guidance. It is the AI-specific evolution of shadow IT: public chatbots, browser-based writing and research assistants, meeting-note takers, coding copilots, and unvetted third-party agents, all reachable in a browser with no procurement review.

The intent is rarely malicious — people are trying to work faster. The exposure is the problem. When an employee pastes a contract, customer record, or source code into a consumer AI tool, that data leaves your tenant and your control, potentially into a service with no data-residency guarantee and no enterprise security terms. The 2026 shift is that the numbers now quantify the risk. IBM's Cost of a Data Breach Report 2025 reported the global average breach cost at $4.44 million and a record $10.22 million in the United States, with shadow AI implicated in one in five breaches and adding about $670,000 to the bill.

The short answer: how do you govern shadow AI in Microsoft 365?

Microsoft's Prevent data leak to shadow AI deployment model breaks the work into four staged steps, each with a concrete outcome:

  1. Discover AI apps — find and monitor which AI apps are in use, who uses them, and whether sensitive data is shared. Outcome: unknown usage becomes visible.
  2. Block access to unsanctioned AI apps — remove organizational and user-level access to tools that fail review. Outcome: unsanctioned apps are blocked.
  3. Block sensitive data going to sanctioned AI apps — stop labeled or sensitive content from reaching even approved tools. Outcome: sensitive data isn't sent to sanctioned apps.
  4. Govern data sent to AI apps — audit, retain, and investigate AI interactions. Outcome: prompts are retained for future investigation.

The controls that power those steps are Microsoft Defender for Cloud Apps, Microsoft Entra, Microsoft Intune, and Microsoft Purview. The order matters: skip discovery and you will block the wrong things, frustrate users, and push shadow AI further underground.

How do you discover the AI apps already in your tenant?

Discovery runs through Defender for Cloud Apps cloud discovery. In the Microsoft security portal, open Cloud discovery, filter discovered apps to the generative AI category, and sort by users to see what is actually being accessed. Export the results, focus on external generative AI apps, and exclude Microsoft Copilot services that your tenant already governs.

Each discovered app carries a cloud app risk score built from four inputs: general vendor information, security controls such as MFA and encryption, compliance alignment such as HIPAA or PCI-DSS, and legal and privacy protections including data retention. Microsoft is explicit that these scores are indicators, not verdicts — final calls belong to security, risk, and compliance stakeholders together. For deeper data-level visibility, Microsoft Purview DSPM for AI monitors the prompts and responses themselves, including interactions that touched sensitive data, across Copilot, Copilot Studio, enterprise AI apps, and consumer tools like ChatGPT and Gemini.

You cannot write a defensible AI policy for tools you have never seen; discovery is not the first step because it is easy, but because every other control depends on it.

This is the phase where most programs stall, because it exposes uncomfortable scope. BabyBots' work on Power Platform DLP environment strategy shows the same pattern in low-code: the organizations that succeed treat discovery as a standing capability, not a one-week audit. BabyBots runs fixed-fee shadow AI discovery assessments that inventory the AI already in your tenant, score each tool against your compliance profile, and hand back a prioritized control plan — the work is available at babybots.ai.

How do you block and control shadow AI without smothering productivity?

Blocking works, but only after users have a sanctioned alternative and you understand why a tool was adopted. In Defender for Cloud Apps you mark an app as unsanctioned to prevent access, enforced through Defender for Endpoint with cloud and network protection turned on and the Defender browser extension deployed across non-Microsoft browsers. Purview then closes the data path: sensitivity labels govern what Copilot and AI can see, DLP keeps labeled content out of prompts, and Endpoint DLP can warn or block sensitive data — like credit card numbers — from being pasted into a third-party AI site in the browser.

Discover-first versus block-first, compared

Discover-first (recommended)

  • Sequence: Inventory usage, assess risk, offer alternatives, then block failing tools.
  • User impact: Low — discovery is transparent and users are guided to sanctioned tools before enforcement.
  • Result: Durable control; makers adopt safe alternatives instead of routing around IT.

Block-first (common mistake)

  • Sequence: Blanket-block AI domains, then react to complaints.
  • User impact: High — breaks legitimate work and erodes trust.
  • Result: Shadow AI migrates to personal devices and unmanaged channels you can no longer see.

What about the AI agents your own people are building?

Shadow AI is not only tools employees buy — it includes the agents they build. Power Platform and Copilot Studio let business users create agents that reach data through connectors, and an ungoverned agent is as much of an exposure as a consumer chatbot. The controls here are Power Platform data policies (DLP), which classify each connector as business, non-business, or blocked, alongside Managed Environments and the Center of Excellence Starter Kit for inventory and analytics.

Identity is the newer layer. Microsoft Agent 365 reached general availability on May 1, 2026 at $15 per user per month as the control plane that gives every agent an identity, a registry record, and oversight, with Entra Agent ID extending to Dataverse in public preview from August 2026. For a full treatment of that identity model, see BabyBots' guide on governing AI agents in Copilot Studio. The through-line is consistent: whether an agent is bought or built, it needs an owner, scoped permissions, and continuous monitoring.

Frequently asked questions

What is shadow AI in simple terms?

Shadow AI is any AI tool or agent employees use for work without IT or security approval — public chatbots, browser AI assistants, or internally built agents. It is risky because sensitive data can leave your governed environment through a service that was never reviewed for security, compliance, or data residency.

How common and costly is shadow AI?

According to IBM's Cost of a Data Breach Report 2025, shadow AI was involved in 20% of breaches and added about $670,000 to the average breach cost. The same report found 97% of AI-related breaches occurred in organizations without proper AI access controls, underlining that the gap is governance, not the technology.

Which Microsoft tools govern shadow AI?

Microsoft's blueprint combines Defender for Cloud Apps for discovery and blocking, Microsoft Purview (DSPM for AI, DLP, sensitivity labels, Insider Risk Management) for data protection and monitoring, Microsoft Entra for access, and Microsoft Intune for device-level enforcement. They work as a staged system, not as isolated point tools.

Can you just block all AI tools?

You can, but it usually backfires. Blanket blocking without a sanctioned alternative pushes employees to personal devices and channels you cannot monitor, which increases risk. A discover-first approach — inventory, assess, offer a safe alternative, then block what fails — produces durable control with far less friction.

Are Copilot Studio and Power Platform agents considered shadow AI?

They can be. An agent a business user builds and shares without governance carries the same data-exposure risk as an unsanctioned external tool. Govern them with Power Platform DLP data policies, Managed Environments, the CoE Starter Kit, and agent identity through Microsoft Agent 365 and Entra Agent ID.

Is DSPM for AI changing in 2026?

Yes. Microsoft merged DSPM and DSPM for AI into a single, generally available solution under Purview, and the classic experiences are being retired on September 30, 2026. Government clouds follow a slightly later schedule, so confirm feature availability in your specific tenant before planning.

Where this is heading

The direction of travel is clear: AI governance is converging with identity and data-security posture management rather than living as a standalone policy document. Agent identities, unified DSPM, and browser-level DLP are collapsing the gap between "we have a policy" and "we can enforce it." The organizations that treat shadow AI discovery as a continuous operating capability — not a compliance checkbox — will be the ones that can adopt AI aggressively without inheriting the breach costs that come with ungoverned use.

Get a shadow AI governance assessment

If you do not yet have a defensible inventory of the AI running in your tenant, that is the place to start. Book a BabyBots shadow AI governance assessment at babybots.ai — in a single working session we map your current AI exposure, score each tool and agent against your compliance requirements, and hand back a staged Discover-Block-Govern plan aligned to Microsoft's native controls, so your first enforcement action is the right one.

Sources

Let’s make your tech stack work together

Don't see your use case here? We've likely built it. 

cta
tick
ai-innovation-01-stroke-rounded 1
ai-brain-04-stroke-standard 1
ai-computer-stroke-rounded 2
ai-security-01-stroke-standard 1
ai-cloud-stroke-sharp 1
ai-network-stroke-rounded 1