Key Takeaway: 61% of organizations discover unauthorized SaaS applications at least monthly. Shadow IT happens because approved tools do not meet actual needs. The MSP that discovers shadow IT and shuts it down without understanding why it exists is solving the symptom rather than the problem.
Shadow IT is the IT your organization is running that your IT provider does not know about. It is the SaaS application a department signed up for without telling anyone. It is the file sharing service an employee uses because the approved one is too slow. It is the AI tool a team adopted because it makes their work faster and nobody asked whether it was approved.
According to Auvik’s 2026 IT Trends Report, 61% of organizations discover unauthorized SaaS applications at least monthly. Twenty-three percent discover them weekly. More than 100,000 shadow AI applications were identified in 2025 alone. Twenty percent of MSPs say shadow IT is the most underestimated issue by leadership, ahead of disaster recovery and staffing concerns.
Shadow IT is not a new problem. What is new is the scale, the speed, and the addition of shadow AI as a distinct and more dangerous category.
Why Shadow IT Happens
Shadow IT happens because the approved tools do not meet the actual needs of the people doing the work. The employee who uses a personal Dropbox account to share large files is not trying to create a security problem. They are trying to do their job. The approved file sharing solution is too slow, too complicated, or too restricted for the task at hand.
The same pattern applies to every category of shadow IT: project management tools, communication platforms, AI assistants, data analysis tools, and customer relationship management systems. When the approved tool does not work well enough, people find alternatives. They do not ask permission because they expect the answer to be no, and they need to get the work done.
This is not a character problem. It is a systems problem. The organization that has a lot of shadow IT has a gap between what its approved tools provide and what its people actually need. Closing that gap is more effective than enforcing compliance with tools that do not work.
Shadow AI: The New and More Dangerous Category
Shadow AI is shadow IT applied to artificial intelligence tools, and it carries risks that traditional shadow IT does not. When an employee uses an unapproved file sharing service, the risk is primarily data governance: files are in a location the organization does not control. When an employee uses an unapproved AI tool, the risk is data governance plus data training plus output reliability plus legal liability.
The AI tool that an employee uses to draft client proposals may be using that client data to train its models. The AI tool that summarizes financial documents may be storing those documents on servers outside the organization’s control. The AI tool that generates code may be producing output that contains security vulnerabilities or intellectual property from other sources.
The Auvik report found that 76% of IT leaders report having an AI policy, but only 42% of help desk staff do. The policy exists. The awareness does not reach the people who are making the daily decisions about which tools to use.
What MSPs Should Be Doing About Shadow IT
The MSP’s role in shadow IT is not primarily enforcement. It is visibility and governance. The MSP that discovers shadow IT and immediately shuts it down without understanding why it exists is solving the symptom rather than the problem. The shadow IT will return in a different form.
Establish visibility first. You cannot govern what you cannot see. Network monitoring, SaaS discovery tools, and DNS filtering logs reveal the shadow IT that is already in the environment. The discovery conversation with the client is not a blame conversation. It is a “here is what we found, here is what it means, and here is what we need to do about it” conversation.
Understand why it exists. Every shadow IT application exists because someone needed something the approved tools did not provide. Understanding that need is the first step toward addressing it. Sometimes the answer is approving the shadow IT application after a security review. Sometimes it is finding an approved alternative that actually meets the need. Sometimes it is adjusting the approved tool’s configuration to remove the friction that drove people to the alternative.
Build a lightweight approval process. The approval process that takes three weeks and requires a committee review will be bypassed. The approval process that takes three days and requires a security review will be used. The goal is to make the approved path easier than the shadow path, not to make the shadow path impossible.
Implement an AI acceptable use policy. Shadow AI requires specific governance that general shadow IT policies do not address. The AI acceptable use policy defines which tools are approved, what data can be shared with them, and what the approval process is for new tools. Without this policy, every employee is making their own risk assessment about AI tools, and most of them do not have the information to make that assessment well.
The Cyber Insurance Connection
Shadow IT and shadow AI create cyber insurance exposure that most organizations do not recognize. The cyber insurance application asks about data handling practices, approved software, and security controls. The organization that has significant shadow IT may be misrepresenting its security posture on the application, which creates grounds for claim denial after an incident.
The MSP that conducts a shadow IT discovery as part of the cyber insurance renewal process is delivering genuine advisory value. The discovery is not just a security exercise. It is a coverage protection exercise.
Frequently Asked Questions
How do I discover shadow IT in a client’s environment?
DNS filtering logs, network traffic analysis, and SaaS discovery tools are the primary mechanisms. DNS filtering logs show every domain that devices on the network are connecting to, which reveals unauthorized SaaS applications. Network traffic analysis shows data flows that may indicate unauthorized tools. Dedicated SaaS discovery tools like Auvik, Torii, or BetterCloud provide more comprehensive visibility into the SaaS applications in use across the organization.
What should I do when I find shadow IT?
Document it, understand why it exists, assess the risk, and present the findings to the client with a clear remediation plan. The remediation plan should address both the immediate risk and the underlying need that drove the shadow IT adoption. Shutting down the tool without addressing the need will result in the same behavior with a different tool.
Is all shadow IT a security risk?
Not equally. A team using an unapproved project management tool that contains no sensitive data is a different risk than a team using an unapproved AI tool that processes client financial data. The risk assessment should consider what data the tool accesses, where that data goes, and what the consequences of a breach would be.
About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He helps MSPs operate with greater maturity and helps business owners make IT choices that make them more secure and more efficient. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.
Related Reading
- Shadow AI: What Unapproved Tools Cost Your Business
- AI Acceptable Use Policy: A Framework and Template
- Your Employees Are Already Using AI. The Question Is Whether Anyone Is Watching.
- Cyber Insurance Requirements 2026: What Carriers Actually Check
- MSP Cybersecurity Hub
This article is part of the AI for MSPs Hub and the MSP Cybersecurity Hub.