Shadow AI in organizations: A distribution-based financial risk analysis for governance and secure AI adoption
Shadow artificial intelligence (AI), referring to the unapproved use of AI tools within organizations, is emerging as a governance challenge that extends beyond traditional shadow information technology (IT) by introducing cybersecurity, compliance, and financial risks. As generative AI tools become increasingly accessible in work environments, employees may use such systems outside formal organizational controls, creating hidden exposure pathways that are difficult to monitor and manage. This study proposes the SAIR (Shadow AI Risk) model, a quantitative risk assessment framework that builds on established information risk analysis principles to examine the financial consequences of Shadow AI usage. The framework distinguishes between primary financial losses, representing direct damages, and secondary financial losses, capturing consequential impacts such as reputational harm and regulatory effects. Scenario-based Monte Carlo simulation is employed to capture uncertainty and estimate financial loss distributions. The findings show that Shadow AI financial risk is shaped jointly by behavioral exposure, threat capability, organizational resistance, and the potential for secondary-loss escalation. Stronger organizational resistance substantially reduces successful loss event frequency, whereas increased exposure and threat capability amplify financial consequences. The additional analyses further demonstrate that financial risk estimates are sensitive not only to expected parameter values but also to the underlying distributional assumptions, particularly in the upper tail. They also show that the magnitude of financial loss and the concentration of losses provide complementary perspectives on organizational risk. Finally, the proposed organizational self-assessment approach provides a practical pathway for adapting SAIR to organization-specific conditions and available operational evidence. By quantifying parameter sensitivities and distributional behavior, the SAIR framework enables organizations to assess Shadow AI financial risk in a structured manner and supports evidence-based prioritization of mitigation strategies. Overall, the study provides a distribution-aware foundation for managing AI-related organizational risk and supports more secure, accountable, and resilient AI adoption.
Authors
- Estela Carmona-Cejudo
- Hind Albasry (ORCID: https://orcid.org/0000-0001-9997-3985)
- Enver Delic
- Robert Muster
Institutions
- Wittenborg University (NL)
Publication Details
- Journal
- Social Sciences & Humanities Open
- Published
- 2026-10-05
- DOI
- https://doi.org/10.1016/j.ssaho.2026.103782
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00