Shadow AI is usually told as a story about employees: someone signs up for an unsanctioned tool and moves work into it. There is a quieter version. The SaaS applications you already approved are adding AI features on their own, and many switch on by default. You did not adopt the AI. It arrived in a product update.
A note-taker starts recording and transcribing every meeting. A CRM begins summarizing customer records with a model hosted somewhere you have not reviewed. A support tool trains on your ticket history. Each feature ships inside a vendor you already trust, so it inherits access you already granted, and it never appears on a shadow-AI list built to catch new tools.
Trusted Vendor, Untracked Capability
The exposure rides in on existing trust. The app was vetted before it had AI, the data connection was approved for the old feature set, and now a new capability is processing sensitive content under permissions granted for something else.
What Your Approval Actually Covered
Shadow-AI lists track what employees bring in. They don't track what vendors quietly add. Approval covered what a tool did at the time of review — not what it does after the next product update. Abnormal's AI Governance monitors how approved apps and integrations actually handle data, flagging vendor tools that start processing or moving sensitive content in new ways even after they were cleared. Approval was a point-in-time decision. Behavior is what shows you what the tool does now.
See the latest from Abnormal's product and engineering teams.

