Deep dive
Wiz defines shadow AI as the unauthorized use or implementation of AI that is not controlled by, or visible to, an organization’s IT department — tools adopted without IT approval or security governance. The academy piece argues that easy interfaces widen the gap between what employees can reach and what organizations can control, and that outright bans can push more work into unsanctioned channels.

What Wiz sees in the cloud (2026)
Wiz’s State of AI in the Cloud 2026 report — linked from the academy primer’s broader security framing — finds AI embedded across environments: at least 81% of organizations using managed AI services, 90% running self-hosted models, and 80% of organizations using AI IDE extensions. Those figures describe sanctioned and unsanctioned footprint together; the shadow-AI risk is that security teams inherit tools and data flows without central oversight.
Wiz reading list
- What is Shadow AI? — Academy definition + Deloitte/Gartner cites
- State of AI in the Cloud 2026 — Managed / self-hosted / IDE extension stats
