Shadow AI: When Company Data Leaves Your Control

A marketing manager has a meeting at 11 a.m. The numbers from last week’s reactivation campaign are disappointing, but nobody has had time to investigate them properly.

There is an export from the CRM system on the desktop. It contains campaign results, player activity, deposits and bonus costs. The manager opens an AI assistant in another browser tab, uploads the file and asks a simple question:

“Why did this campaign perform worse than the previous ones?”

A minute later, there is an answer. It is clear, structured and useful enough to bring into the meeting.

Nothing about this feels like a security incident.

The manager has not installed suspicious software. There has been no attempt to bypass company systems. No database password has been shared. Nobody has deliberately ignored a compliance policy.

The employee simply found a faster way to do the job.

The same logic applies elsewhere in an iGaming business. A sportsbook manager wants to understand a weekend margin drop and pastes betting results into an AI tool. Someone working with payments uploads failed deposit records to look for a pattern. A fraud analyst asks an assistant to compare several suspicious player histories. An affiliate manager sends partner performance data to a chatbot and asks which accounts deserve attention.

Each request makes sense in isolation.

Taken together, they create a problem that many companies are only beginning to understand.

It is called Shadow AI.

The new shadow IT is much easier to use

Shadow IT has existed for decades. Employees have always found software that made their work easier before the IT department approved it. Personal Dropbox accounts, private messaging applications, spreadsheets that became unofficial databases and SaaS tools purchased on company cards were all versions of the same phenomenon.

Generative AI changes the scale of the problem.

There is almost no barrier to entry. An employee does not need to install anything or persuade anyone to buy a licence. A browser, an account and a few minutes are enough.

More importantly, AI becomes more useful when it receives more context.

A generic question such as “how can I improve reactivation?” produces a generic answer.

Upload campaign history, player behaviour, bonus costs and deposit activity, and the answer becomes much better.

That is where productivity and data governance begin to collide.

Netskope reported in 2026 that almost half of enterprise generative AI users were using personal AI applications. The same research found hundreds of monthly incidents in the average organisation in which sensitive information was sent to AI services.

This should not be surprising. Employees are under pressure to produce answers faster, and AI is very good at removing work that used to consume hours.

The problem is that the organisation may have no visibility into where that work is taking place.

In iGaming, a useful file is often a sensitive file

The risks are particularly obvious for gambling operators because ordinary operational analysis frequently involves information that deserves careful handling.

A campaign export may include player IDs, bonus history, deposit behaviour and activity patterns.

A sportsbook investigation may contain stakes, odds, markets, results and customer-level betting records.

A payment analysis may include deposits, withdrawals, payment methods, transaction failures and account information.

A fraud or Responsible Gambling investigation may contain behavioural signals that are sensitive by their very nature.

A spreadsheet does not need to contain names, addresses or passport numbers to reveal a great deal about a customer.

Take a table containing an internal player ID, betting frequency, average stake, deposit history, recent losses, VIP classification and campaign responses. It may look anonymous to the person exporting it. To the operator, it describes the financial and behavioural history of a real customer.

If that file is uploaded to an external AI service chosen by an employee, the organisation has created a new data processing route.

The problem starts with a series of very ordinary questions.

Which AI service was used?

Was it a personal or company account?

Where was the information processed?

How long will it remain there?

What contractual terms apply to that particular account?

What privacy settings are enabled?

Can somebody else access the conversation history?

Can the company identify what information was uploaded six months later?

Can it delete it?

Did the employee have permission to send the data there in the first place?

In a governed system, these questions have documented answers.

With Shadow AI, the first person inside the organisation to know that the processing happened may be the employee who uploaded the file.

Training is only one part of the problem

Much of the public discussion about AI and confidential data has been reduced to a single question: does the model train on what I send it?

That matters, but it is a poor substitute for a data governance policy.

Different providers have different rules. The same provider may also have different rules for consumer accounts, enterprise products and API usage. Privacy settings may vary. Retention may vary. Contractual protections may vary.

An organisation cannot sensibly manage sensitive information on the assumption that every employee knows the difference.

Even if a particular AI provider does not use business data to train its models, several questions remain. The company still needs to know where its data is going, under which agreement, for what purpose, for how long and with what access controls.

Shadow AI is therefore a control problem before it is a model-training problem.

The issue is not that every public AI service behaves irresponsibly. Many enterprise AI products now offer serious security and privacy protections.

The issue is that an employer cannot govern a process it cannot see.

Then there is the problem nobody calls a security incident

Suppose no confidential information leaks.

There is still another risk.

A marketing manager uploads a dataset and asks an AI assistant to calculate NGR by campaign.

What does NGR mean?

Most people in the industry can give an answer. Unfortunately, they may not all give the same one.

One operator may subtract bonuses in a particular way. Another may account for taxes differently. One business unit may exclude certain adjustments. Finance may use an official definition while marketing has spent years using an older spreadsheet formula.

Now put a generic AI assistant in the middle.

It can calculate almost anything it is asked to calculate. It can also make an assumption when the instruction is incomplete.

The result may look excellent. There may be a table, a short explanation and a convincing conclusion.

It may also be based on a definition the company does not use.

The same problem applies to Active Players, retention, conversion, bonus cost, sportsbook margin and dozens of internal KPIs.

This is where Shadow AI becomes Shadow Analytics.

Employees are no longer only moving data into uncontrolled tools. They may also be creating unofficial analytical logic outside the systems where business definitions are governed.

That is a dangerous combination because wrong analysis rarely announces itself as wrong. It usually arrives looking polished.

Why banning AI is unlikely to solve the problem

The obvious response is prohibition.

Block access to public AI services. Add a policy saying that company data must never be entered into them. Tell employees to use approved software only.

There are good reasons to do all three.

But prohibition does not remove the reason people started using AI.

The marketing manager still has a meeting at 11 a.m.

The sportsbook manager still needs an explanation for the margin drop.

The fraud analyst still has twenty cases waiting.

If an AI assistant can reduce an hour of manual work to five minutes, the incentive to use it does not disappear because a policy document says otherwise.

Some employees will follow the rule. Others will search for another service. Some will use a private account. Some will move the work to a personal device.

This has happened with practically every generation of useful workplace technology.

The more practical question is not how to stop employees from wanting AI.

It is how to give them access to AI without forcing company data to leave the environment the company already controls.

Bring the AI to the data

This is the approach we took with the AI Agent in Gamblitude.

The Agent works inside the operator’s existing analytics environment. A user does not need to export business data, save another CSV and upload it somewhere else before asking a question.

The marketing manager can ask why reactivation performance deteriorated.

The sportsbook manager can ask which leagues, events or markets were responsible for a change in margin.

A payments specialist can ask whether a fall in deposit success rate is concentrated around a particular provider, country or payment method.

The analysis takes place against data already available in Gamblitude.

Data provided to the Gamblitude AI Agent is processed within Gamblitude’s controlled cloud environment. Client data is not used to train, fine-tune or improve the underlying AI models.

The Agent also operates under the same access model as the rest of the platform. Gamblitude’s RBAC system determines which datasets a user is permitted to access. Asking the Agent a question does not provide a way around those permissions.

There is another important difference.

The Agent works with Metrics defined inside Gamblitude.

If an operator has one approved definition of NGR, that definition is used throughout the platform. The Agent does not need to invent one. The same principle applies to the operator’s other KPIs.

This matters because safe AI in a data-intensive business requires more than protecting files.

The company also needs to retain control over access and business logic.

AI governance will become an operating issue

For the last two years, much of the corporate debate about generative AI has focused on whether companies should allow it.

That question is becoming less useful.

Employees already know what these tools can do. New employees will increasingly arrive having used them throughout university and previous jobs. AI will become another normal part of office software.

The relevant question for operators is where this work should happen.

It can happen through personal accounts, exported files and a collection of tools selected independently by employees.

Or it can happen inside an environment where the company knows which data is being used, who is allowed to use it and which business definitions apply.

This is not an argument for giving an AI assistant unlimited access to everything.

It is an argument for applying the same discipline to AI that operators already apply to their data infrastructure.

Access should be deliberate. Data processing should be understood. Permissions should follow the user. Business definitions should remain controlled. Employees should know which environment is approved for company information.

The companies that get this right will not necessarily be those with the strictest AI policies.

They will be the ones that make the approved way of using AI useful enough that employees have little reason to look elsewhere.

Because the employee with the campaign file will still have a meeting at 11 a.m.

And they will still want an answer before it starts.