Author: Lourdes Rojas, MBA · PMP · PgMP · ISO 27001 · GDPR | Published: May 18, 2026
Unmanaged AI adoption — employees using unauthorised AI tools outside IT oversight — is creating serious compliance, liability, and patient safety risks in healthcare organisations. Learn how to detect, govern, and mitigate Shadow AI before it becomes a regulatory crisis.
Shadow AI refers to the use of artificial intelligence tools, models, or automated systems by employees or departments within an organisation without the knowledge, approval, or oversight of IT, compliance, or leadership teams. It is the AI equivalent of Shadow IT — and in healthcare, it carries consequences that extend far beyond a data breach notification.
> Definition: Shadow AI is any AI-enabled tool, application, or workflow deployed within an organisation outside of formally sanctioned channels, without risk assessment, vendor vetting, or governance controls.
The phenomenon is accelerating. As consumer-grade AI tools become more capable and accessible, clinical staff, administrators, and operations teams are independently adopting tools to solve immediate problems — scheduling optimisation, clinical documentation drafting, patient communication, coding assistance — without waiting for institutional approval processes that can take months.
The result is a growing layer of ungoverned AI operating inside healthcare organisations, processing sensitive patient data, influencing clinical decisions, and creating compliance exposure that most organisations have not yet begun to quantify.
Healthcare organisations face a structural tension that makes Shadow AI particularly difficult to manage. On one side, clinicians and administrators are under relentless pressure to reduce documentation burden, improve throughput, and deliver better patient experiences. On the other side, formal technology procurement and compliance processes are slow, resource-intensive, and often perceived as obstacles rather than safeguards.
When a physician discovers that a consumer AI tool can reduce their documentation time by 40 minutes per shift, the incentive to use it immediately — without waiting six months for an IT review — is powerful. When a billing team finds an AI coding assistant that reduces denial rates, the business case for immediate adoption is compelling.
The problem is not the intent. The problem is the absence of governance infrastructure that would allow those tools to be adopted safely and compliantly.
Under the HIPAA Privacy and Security Rules, covered entities and their business associates are required to implement administrative, physical, and technical safeguards for protected health information (PHI). When employees use unsanctioned AI tools that process PHI — uploading clinical notes to a consumer LLM, for example — the organisation may be in violation of HIPAA even if the employee acted in good faith.
The Office for Civil Rights (OCR) has made clear that workforce training and access controls are not optional. Shadow AI represents a category of access control failure that existing HIPAA compliance frameworks were not designed to address.
For organisations operating in or serving patients in the European Union, the EU AI Act classifies many healthcare AI applications as high-risk systems subject to mandatory conformity assessments, transparency requirements, and human oversight obligations. Shadow AI — by definition — bypasses all of these requirements.
Organisations that cannot demonstrate oversight and control of AI systems used in clinical or administrative contexts face significant enforcement exposure as the EU AI Act's implementation timeline progresses.
The NIST AI RMF provides a structured approach to identifying, assessing, and managing AI risks across the AI lifecycle. Shadow AI creates a fundamental gap in this framework: you cannot govern what you cannot see. Organisations that have invested in AI governance programmes based on NIST AI RMF principles may have a false sense of coverage if they have not addressed the Shadow AI detection problem.
Shadow AI does not typically arrive through a single dramatic event. It accumulates gradually, through a series of individually reasonable decisions made by people trying to do their jobs better.
The most common entry points include consumer large language models used for clinical documentation drafting or summarisation; AI-powered scheduling and patient communication tools adopted by front-desk staff; third-party coding and billing AI tools procured by revenue cycle teams without compliance review; AI features embedded in existing software platforms that activate without explicit organisational approval; and personal AI assistants used on work devices for administrative tasks that incidentally involve PHI.
Each of these represents a different governance challenge. Some involve deliberate adoption decisions made without proper channels. Others involve passive activation of AI features that organisations did not know they were enabling.
Detection is the prerequisite for governance. Organisations cannot manage Shadow AI they have not identified. An effective detection programme combines four approaches.
Network and endpoint monitoring can identify traffic to known AI service endpoints — OpenAI, Anthropic, Google Gemini, and others — from organisational devices and networks. This provides a signal of AI tool usage without necessarily revealing the specific use case.
Procurement and expense audits can surface AI tool subscriptions purchased on corporate cards or through departmental budgets outside of IT procurement channels. Many Shadow AI tools are inexpensive enough to be purchased without triggering standard procurement controls.
Employee surveys and interviews are often the most direct path to understanding actual AI usage patterns. Conducted with appropriate confidentiality protections, they can reveal both the tools in use and the underlying needs that drove adoption — information that is essential for designing effective governance responses.
Software inventory and SaaS discovery tools can identify AI-enabled applications installed on organisational devices or accessed through organisational accounts, including AI features embedded in productivity suites and communication platforms.
The instinctive response to discovering Shadow AI is often prohibition — issuing policies that ban unauthorised AI use and relying on disciplinary consequences to enforce compliance. This approach consistently fails.
Prohibition without alternatives does not eliminate the underlying need that drove Shadow AI adoption. It drives the behaviour underground, making it harder to detect and govern. It creates adversarial relationships between compliance teams and clinical staff. And it forfeits the genuine productivity and quality benefits that well-governed AI can deliver.
The effective response is governance: creating the infrastructure, processes, and approved tool sets that allow AI to be adopted safely and compliantly within the organisation. This means establishing a clear AI governance framework aligned with ISO 42001 and the NIST AI RMF; creating an AI tool review and approval process that is fast enough to be practical; providing approved alternatives for the most common Shadow AI use cases; training clinical and administrative staff on AI governance requirements and the risks of unsanctioned tools; and implementing ongoing monitoring to detect new Shadow AI adoption as the tool landscape evolves.
Organisations that do not address Shadow AI are not avoiding risk — they are deferring it. The costs of inaction compound over time and typically materialise in one of three ways.
A regulatory enforcement action triggered by a HIPAA breach or EU AI Act non-compliance finding can result in significant financial penalties, mandatory corrective action plans, and reputational damage that affects patient trust and staff recruitment.
A patient safety incident involving an ungoverned AI tool — a clinical decision support tool that produces biased recommendations, a documentation AI that introduces errors into the medical record — creates liability exposure that no organisation can afford to dismiss.
A competitive disadvantage as organisations with mature AI governance programmes are able to adopt and scale AI capabilities faster, more safely, and with greater confidence than those operating in a reactive, ungoverned mode.
For most healthcare organisations, the Shadow AI governance journey begins with three immediate steps.
First, conduct a Shadow AI discovery audit — a structured effort to identify what AI tools are currently in use across the organisation, through what channels they were adopted, and what data they are processing. This audit should be conducted with a posture of understanding rather than enforcement, to maximise disclosure.
Second, establish a rapid AI tool review process — a governance mechanism that allows clinical and administrative teams to submit AI tools for review and receive a decision within a defined timeframe. The goal is to make the compliant path faster and easier than the Shadow AI path.
Third, develop an AI governance policy that addresses Shadow AI explicitly — defining what constitutes an unsanctioned AI tool, what the approval process is, and what the consequences of non-compliance are. This policy should be developed with input from clinical, administrative, and compliance stakeholders to ensure it reflects operational realities.
Eunoia Consulting Co. specialises in designing and implementing AI governance frameworks for healthcare and veterinary organisations. Our AI Governance service provides the strategic foundation, policy infrastructure, and implementation support your organisation needs to govern AI — including Shadow AI — effectively and compliantly.
Lourdes Rojas is the founder of Eunoia Consulting Co. and a specialist in AI governance, healthcare operations, and regulatory compliance. She holds an MBA from Quantic University, a Master's from Columbia University, and certifications in ISO 27001, GDPR, PMP, and PgMP.