[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-shadow-ai::en":3,"gloss-cluster-shadow-ai::en":23,"gloss-next-shadow-ai::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"shadow-ai","security","Shadow AI","Shadow AI is the use of AI tools inside a company without IT or security approval — an employee pasting customer records into a public chatbot, a team wiring an unvetted API into production, or a browser extension that quietly ships your data to a third party. It's the AI-era version of shadow IT, and it spreads fast because the tools are free, useful, and one click away. The risk isn't just leaked secrets: data pasted into some consumer tools can be retained or used for training, and you may be breaching your own customer contracts or GDPR without realizing it. For founders, shadow AI cuts both ways — you want your team to move fast, and you also don't want to become the cautionary breach story. Practical note: publish a short, permissive AI-use policy that names approved tools, offer a sanctioned option with a data-processing agreement, and log or gateway AI traffic rather than banning it outright.","Shadow AI is AI used inside a company without security approval — customer records pasted into a public chatbot, an unvetted API wired straight into production.",null,[11,14,17,20],{"slug":12,"name":13},"data-residency","Data Residency",{"slug":15,"name":16},"pii","Personally Identifiable Information (PII)",{"slug":18,"name":19},"prompt-injection","Prompt Injection",{"slug":21,"name":22},"sub-processor","Sub-processor",[24,28,32,36,39,42,45,48,51,54,57,60],{"slug":25,"category":5,"name":26,"updated_at":27},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":29,"category":5,"name":30,"updated_at":31},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":33,"category":5,"name":34,"updated_at":35},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":37,"category":5,"name":38,"updated_at":35},"bridge-letter","Bridge Letter",{"slug":40,"category":5,"name":41,"updated_at":35},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":43,"category":5,"name":44,"updated_at":27},"byok","Bring Your Own Key (BYOK)",{"slug":46,"category":5,"name":47,"updated_at":35},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":49,"category":5,"name":50,"updated_at":31},"data-classification","Data Classification",{"slug":52,"category":5,"name":53,"updated_at":35},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":55,"category":5,"name":56,"updated_at":35},"data-minimization","Data Minimization",{"slug":58,"category":5,"name":59,"updated_at":35},"data-poisoning","Data Poisoning",{"slug":61,"category":5,"name":62,"updated_at":35},"data-processing-agreement","Data Processing Agreement (DPA)"]