Shadow AI on Mobile: The Need for AI Governance

AI Apps

AI adoption inside businesses has moved faster than almost any technology before it. Staff now reach for AI tools by default, often through apps on their own phones, and the security measures most organisations rely on were built for a world before any of this existed. That gap is where shadow AI lives, the AI use nobody sanctioned, nobody reviewed, and nobody can currently see. And it doesn’t only come from careless employees pasting the wrong thing into a chatbot.

Malicious actors have moved just as quickly, using generative tools to craft sharper phishing, automate reconnaissance, and probe for exactly the blind spots that new AI traffic opens up. The result is a widening space between what your people are actually doing and what your controls can govern.

What is shadow AI?

Shadow AI is any use of AI tools inside an organisation that happens without the knowledge or approval of IT and security teams. It’s the AI equivalent of shadow IT, but broader and harder to spot. Sometimes it’s an employee pasting company data into a consumer chatbot to save time. Just as often it’s an AI feature quietly switched on inside an app the business already uses, sending data to a model provider that nobody signed off on. Because so much of it runs on personal mobile devices and over ordinary web connections, most of it never appears in the tools security teams already run.

What is AI governance?

AI governance is the set of policies, controls and oversight an organisation puts in place to manage how AI is used, by whom, and with what data. Done well, it decides which tools are sanctioned, what data may be shared with them, and how that policy is actually enforced day to day. The catch is that governance depends on visibility. You cannot write a meaningful policy for AI you don’t know is being used, and you cannot enforce a policy against traffic you can’t see. That’s why, for most organisations, the honest first step towards AI governance isn’t a policy document. It’s finding out what’s already happening.

Six weeks of real data

For six weeks, our on-device inspection engine recorded what AI activity actually looks like on our customers’ mobile fleets. This wasn’t a survey or a projection. It was real traffic from real devices, logged as it happened.

Between April and June, our detection database captured every AI connection moving across those fleets, and the picture it produced is worth sitting with. Adoption is close to universal, it’s growing fast, and most of it never shows up in the tools security teams already run. The shadow AI it reveals isn’t theoretical, it’s already on the devices in your organisation.

84% of our customers had AI traffic on their mobile fleet, and that volume is climbing by around 40% every month. To be clear, that’s month on month, not annually. So a footprint that looks small today is roughly half again as big four weeks later, and bigger still the month after that. Run that out over a quarter and something a security lead might currently wave off as marginal becomes the largest category of sensitive data leaving the fleet.

The bigger concern isn’t the volume, it’s what the traffic is made of. Of the AI domains we detected, 69% were ones we’d never seen before. That number tells you something uncomfortable about how blocklists work. A list goes out of date the moment you finish writing it, because the tool your team picked up this week wasn’t on anyone’s radar last week. So a static defence always trails a step behind, governing last month’s reality while your people have already moved on.

The easy assumption is that this is really an OpenAI problem. OpenAI did turn up in about a third of accounts, but the interesting part is everything behind it. We saw AI systems most security teams have never heard of, things like Bloomreach, Emarsys, Sprig, Sendbird and Gorgias, plus a pile of AI features quietly built into apps employees already had on their phones. Nobody chose to deploy most of these. They arrived as updates to software the company already trusted, switching on features that feed data to a model provider with no procurement step, no review, and nothing in the acceptable-use policy to cover them. And that’s the trap: you can’t govern a service you can’t name, and you can’t name one your tools never see.

the scale at which ai is adopted in form of corrata's data

Why shadow AI isn’t just old shadow IT

It’s tempting to file all this under shadow IT and reach for the usual playbook. That undersells what’s changed. Shadow AI is a genuinely new kind of problem.

Before 2022, there was simply no way for an employee to paste a client database into a consumer service in thirty seconds and get something useful back. The channel didn’t exist. Generative AI opened a completely new route for sensitive data to leave the building, and it’s casual, instant, and at the network level almost impossible to tell apart from ordinary web browsing.

Mobile is where the exposure runs deepest. A personal phone keeps no wall between work and personal life, so company data and consumer apps sit side by side on the same device with nothing in between. No proxy stands in the way, no inspection point, no gateway deciding what’s allowed out. The employee just connects straight to the AI service.

None of the tools already in place catches this, because nobody designed them to. EDR watches for malicious processes, not where a legitimate app sends its data. Email security only covers email, and this leaves by a different door. Older data loss prevention handled attachments and file transfers, not a browser tab or an in-app assistant streaming text to a model endpoint. Each of those tools does its own job fine. This just isn’t a job any of them was built for, which is why shadow AI slips through a stack that looks complete on paper.

Why AI governance has to start with visibility

There are broadly two ways to respond, and they lead to very different places.

two ways to handle shadow ai

The first is the blocklist: list the AI systems you know about, block them, and hope the list holds. It doesn’t. Our data shows why, with 69% of the domains we saw being brand new. Blunt blocking carries a second cost too. It nudges the more determined employees to work around you, through a personal hotspot or an unmanaged device, and once they do that you’ve lost whatever visibility you had to begin with. You haven’t removed the risk. You’ve just stopped being able to see it.

The second is to make it visible first, then govern it. This is the heart of real AI governance, and the order matters. Rather than guessing at a list, you watch what’s genuinely in use. Every AI service touching the fleet becomes visible, whether it’s sanctioned or not. New domains surface the moment they appear instead of weeks later when someone gets round to updating a feed. And the device itself stops sensitive uploads in real time, before anything crosses the line. Policy follows what you actually know, which is the only order that works when most of what you’re dealing with didn’t exist last month. You cannot govern shadow AI you cannot see.

Why only on-device DPI sees this

We can see all this because the inspection happens on the device itself. No VPN tunnel, no proxy, no agent relaying traffic back to the cloud. Our on-device deep packet inspection sees the real destination an app or an employee is connecting to, the actual AI service and the brand-new domain, rather than just coarse metadata about the connection.

Traditional MTD and MDM tools don’t look this deep. They’ll flag a known malicious domain or a dodgy Wi-Fi network, but they miss a marketing app quietly shipping data to an AI platform nobody signed off on, or an employee pasting sensitive content into a consumer chatbot.

For our customers, the difference is a live view of every AI service touching their fleet, and the ability to govern it, instead of finding out once the data has already gone. As AI models multiply inside everyday apps, that live view is the only foundation an AI governance policy can actually stand on.

Your employees are already using AI on their phones. That much is settled. The only open question is whether you can see it, or whether shadow AI is growing by 40% a month inside a channel you have no way to inspect.

See Corrata’s DPI in action. Request a demo to understand your organisation’s vulnerabilities.

 

Related Resources

Related Resources

Read the latest news on endpoint threat detection and response from the experts.

Read the latest news on endpoint threat detection and response from the experts.

  • AI Apps
    blog

    Blog

    Shadow AI on Mobile: The Need for AI Governance

    Read more
  • Complex network of binary code highlighting data flow and cybersecurity concepts
    blog

    Blog

    We caught a banking app using a weak cipher suite. Here’s how.

    Read more
  • LEADERSHIP ANNOUNCEMENTMark Kirwan Appointed CEO
    blog

    Blog

    Corrata Appoints Mark Kirwan as Chief Executive Officer

    Read more
  • Corrata Reimagines Mobile Device Security for the AI Era
    blog

    Blog

    Corrata Reimagines Mobile Device Security for the AI Era

    Read more