Shadow AI in organizations: A distribution-based financial risk analysis for governance and secure AI adoption

Shadow artificial intelligence (AI), referring to the unapproved use of AI tools within organizations, is emerging as a governance challenge that extends beyond traditional shadow information technology (IT) by introducing cybersecurity, compliance, and financial risks. As generative AI tools become increasingly accessible in work environments, employees may use such systems outside formal organizational controls, creating hidden exposure pathways that are difficult to monitor and manage. This study proposes the SAIR (Shadow AI Risk) model, a quantitative risk assessment framework that builds on established information risk analysis principles to examine the financial consequences of Shadow AI usage. The framework distinguishes between primary financial losses, representing direct damages, and secondary financial losses, capturing consequential impacts such as reputational harm and regulatory effects. Scenario-based Monte Carlo simulation is employed to capture uncertainty and estimate financial loss distributions. The findings show that Shadow AI financial risk is shaped jointly by behavioral exposure, threat capability, organizational resistance, and the potential for secondary-loss escalation. Stronger organizational resistance substantially reduces successful loss event frequency, whereas increased exposure and threat capability amplify financial consequences. The additional analyses further demonstrate that financial risk estimates are sensitive not only to expected parameter values but also to the underlying distributional assumptions, particularly in the upper tail. They also show that the magnitude of financial loss and the concentration of losses provide complementary perspectives on organizational risk. Finally, the proposed organizational self-assessment approach provides a practical pathway for adapting SAIR to organization-specific conditions and available operational evidence. By quantifying parameter sensitivities and distributional behavior, the SAIR framework enables organizations to assess Shadow AI financial risk in a structured manner and supports evidence-based prioritization of mitigation strategies. Overall, the study provides a distribution-aware foundation for managing AI-related organizational risk and supports more secure, accountable, and resilient AI adoption.

Authors

Institutions

Publication Details

Journal
Social Sciences & Humanities Open
Published
2026-10-05
DOI
https://doi.org/10.1016/j.ssaho.2026.103782
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Shadow AI in organizations: A distribution-based financial risk analysis for governance and secure AI adoption

Estela Carmona-Cejudo, Hind Albasry, Enver Delic, Robert Muster
Social Sciences & Humanities Open
Information and Cyber Security
article

Shadow AI in organizations: A distribution-based financial risk analysis for governance and secure AI adoption

Estela Carmona-Cejudo, Hind Albasry, Enver Delic, Robert Muster
article en

Abstract

Shadow artificial intelligence (AI), referring to the unapproved use of AI tools within organizations, is emerging as a governance challenge that extends beyond traditional shadow information technology (IT) by introducing cybersecurity, compliance, and financial risks. As generative AI tools become increasingly accessible in work environments, employees may use such systems outside formal organizational controls, creating hidden exposure pathways that are difficult to monitor and manage. This study proposes the SAIR (Shadow AI Risk) model, a quantitative risk assessment framework that builds on established information risk analysis principles to examine the financial consequences of Shadow AI usage. The framework distinguishes between primary financial losses, representing direct damages, and secondary financial losses, capturing consequential impacts such as reputational harm and regulatory effects. Scenario-based Monte Carlo simulation is employed to capture uncertainty and estimate financial loss distributions. The findings show that Shadow AI financial risk is shaped jointly by behavioral exposure, threat capability, organizational resistance, and the potential for secondary-loss escalation. Stronger organizational resistance substantially reduces successful loss event frequency, whereas increased exposure and threat capability amplify financial consequences. The additional analyses further demonstrate that financial risk estimates are sensitive not only to expected parameter values but also to the underlying distributional assumptions, particularly in the upper tail. They also show that the magnitude of financial loss and the concentration of losses provide complementary perspectives on organizational risk. Finally, the proposed organizational self-assessment approach provides a practical pathway for adapting SAIR to organization-specific conditions and available operational evidence. By quantifying parameter sensitivities and distributional behavior, the SAIR framework enables organizations to assess Shadow AI financial risk in a structured manner and supports evidence-based prioritization of mitigation strategies. Overall, the study provides a distribution-aware foundation for managing AI-related organizational risk and supports more secure, accountable, and resilient AI adoption.

Social Sciences & Humanities OpenVol. 14
Wittenborg University (NL)
Openalex Percentile: Top 5%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.