Shadow AI is the use of AI tools or systems without formal approval, oversight, or governance by an organization. It creates risks around data leakage, compliance, security, and inconsistent decision-making, and is typically managed through policy, approved alternatives, training, and monitoring.