Table of contents
Shadow IT used to mean a rogue spreadsheet and a departmental Dropbox. In 2026 it means an AI assistant summarising your client contracts, a browser extension quietly reading every page your team opens, and a SaaS subscription on somebody’s personal card holding half a project’s data. For UK and EU businesses — and for the MSPs who support them — shadow IT has stopped being a tidy-up job and become a genuine security, cost and compliance problem.
The encouraging part is that this is a solvable problem, and solving it does not mean confiscating the tools that make people productive. It means visibility, a fast approval path, and enough skilled hands to keep the work going after the first clean-up. Below are nine practical wins you can apply this quarter, plus a realistic view of what it takes to staff the effort.

What shadow IT actually looks like in 2026
Shadow IT is any technology used for work that your IT function has not approved, does not manage and often cannot see. The classic definition covered unsanctioned software installs. The modern version is broader and much harder to spot, because almost none of it involves installing anything at all.
In a typical SME or MSP-supported client, it shows up as:
- Unsanctioned AI assistants. Free-tier chatbots used to rewrite proposals, debug code or summarise meeting notes.
- Browser extensions. Note-takers, grammar helpers and AI sidebars with permission to read and change data on every site.
- OAuth-connected apps. Third-party tools granted standing access to Microsoft 365 or Google Workspace by a single click, with no expiry.
- Personal accounts on corporate devices. The same laptop, a different identity — and therefore no logging, no DLP and no offboarding.
- Departmental SaaS. A project tool, a design subscription or a scheduling app expensed monthly and never registered anywhere.
The common thread is that shadow IT is rarely malicious. It is almost always someone trying to hit a deadline with a tool that works better than the sanctioned one. Treating it as a discipline problem is the fastest way to drive it further underground.
Why the AI era changed the rules
Three things changed at once. First, capable AI tools became free and instant — no procurement, no install, no admin rights, just a browser tab. Second, AI features started appearing inside software that has already been approved, so the usage never trips a “new app” alert. Third, the productivity gain is real enough that people will not wait six weeks for a decision.
That combination is why the problem now grows faster than the governance around it. It also raises the stakes, because the data going into these tools is not trivial: source code, client proposals, pricing, HR records and support tickets containing customer detail.
The threat side has moved just as quickly. Verizon’s 2026 Data Breach Investigations Report notes that roughly 15% of attack techniques are now bolstered by generative AI, with attackers using it to work faster at every stage — from finding gaps to writing malware. Defenders working with an incomplete inventory are, in effect, bringing last year’s map to this year’s terrain.
The real cost of shadow IT for SMEs and MSPs
The security cost is the obvious one, and it is not abstract. IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a breach at USD 4.99 million — a 12% year-on-year rise and a record high — and records a 56% increase in AI-driven attacks such as deepfake impersonation and AI-enabled malware. Every unmanaged tool widens the surface those attacks can land on.
But shadow IT costs money in quieter ways too, and these are the ones that show up on an MSP’s margin:
- Duplicate spend. Three teams paying for three tools that do one job.
- Offboarding gaps. A leaver’s personal-account subscription keeps the data long after their badge stops working.
- Compliance exposure. Under UK GDPR you have to know where personal data is processed. Unregistered tools mean you do not.
- Slower incident response. When something goes wrong, unknown systems turn a two-hour investigation into a two-day one.
- Support drag. Service desks end up troubleshooting tools they were never told about and cannot administer.
9 smart wins: a practical clean-up programme
These nine steps are ordered deliberately. The early ones build trust and visibility; the later ones make the improvement stick.
1. Open with an amnesty, not an audit
Announce a two-week window where anyone can declare a tool with no consequences. You will surface more shadow IT in a fortnight than six months of scanning will find, because people volunteer what logs cannot see.
2. Inventory identity, not just endpoints
Pull the list of OAuth application grants in Microsoft 365 or Google Workspace. This single report is the highest-yield discovery step available to most organisations, and it costs nothing.
3. Rank findings by data sensitivity
A design tool holding stock photos is not the same risk as an AI notetaker sitting in client calls. Sort the shadow IT register by what data the tool touches, then work top-down.
4. Give people a sanctioned AI option
You cannot ban your way out of this. Provide a business-tier AI tool with contractual data protections and make it easy to reach. Demand for shadow IT collapses when the approved path is genuinely good.
5. Put a named owner against every app
Every tool in the register gets a business owner and a review date. Unowned tools are how shadow IT quietly reappears twelve months later.
6. Fix joiners, movers and leavers
Tie offboarding to the app register, not just to the directory. Revoke OAuth grants and cancel personal-card subscriptions as part of the standard leaver checklist.
7. Read the expense reports
Finance data is an underrated detector. Recurring low-value card charges and software receipts in inboxes will reveal subscriptions no network tool will ever see.
8. Write a one-page AI and SaaS use policy
One page, plain English, with three lists: fine to use, ask first, never. Long policies are ignored, and ignored policies are how unapproved tools get justified after the fact.
9. Re-run the review every quarter
Shadow IT is a flow, not a stock. A quarterly cycle — re-pull grants, re-check expenses, refresh the register — keeps a one-off clean-up from decaying within a year.
How to discover unsanctioned apps without buying another platform
Discovery tooling is useful, but most organisations can get a long way with what they already own. Before you add another subscription to the estate, work through these sources:
- Identity provider logs. Sign-in and consent logs show which third-party apps hold access and who granted it.
- DNS and firewall logs. Outbound requests to AI and SaaS domains give you usage patterns without any endpoint agent.
- Browser extension inventory. Most MDM and RMM platforms can already report installed extensions across managed devices.
- Expense and card data. Recurring charges under approval thresholds are where departmental shadow IT hides.
- Mailbox receipts. A tenant-wide search for “your subscription” and “welcome to” style receipts is crude but remarkably effective.
Run those five and you will have a defensible baseline. The catch is that none of it is a one-afternoon job, and it competes directly with the ticket queue — which is exactly where most programmes stall.
Governance your team will actually follow
The organisations that keep shadow IT under control share one habit: their approval process is faster than the workaround. If a request takes three days, people wait. If it takes three weeks, they route around you and the register goes stale again.
Three principles are worth adopting:
- Publish a sanctioned catalogue. A visible list of approved tools per category removes the main reason people go looking elsewhere.
- Commit to a request SLA. Five working days for a decision, with a named reviewer, beats an open-ended queue every time.
- Explain the reasoning. “This tool trains on your input and has no data processing agreement” persuades. “Not approved” does not.
Staffing the shadow IT problem with OutsourceZA
Almost every business we speak to already knows what needs doing. What they do not have is a person with time to do it while the service desk is running hot. Shadow IT work is steady, unglamorous and easy to defer indefinitely — which is why it needs dedicated capacity rather than good intentions.
That is the gap OutsourceZA’s IT outsourcing and outstaffing services are built to fill. We place skilled South African security and infrastructure professionals into UK and EU teams as an extension of your own staff, typically at a 40–60% cost saving against local hires. South Africa sits in the UK/EU timezone band, so an outstaffed analyst works your hours, joins your stand-ups and hands over to your day team in real time — not overnight by ticket note.
For MSPs, the model is deliberately flexible. Start with one analyst to run the discovery and register, then scale up or down as client demand shifts, without carrying permanent headcount through quiet quarters. Because our engineers are MSP-ready, they arrive familiar with multi-tenant RMM, PSA and Microsoft 365 administration rather than learning it on your clients’ time.
You can read more about how we work, see the calibre of people in our network on our IT jobs board, or get in touch to talk through what a shadow IT clean-up would take in your environment.
Frequently asked questions
Is shadow IT always a security risk?
Not always, but it is always an unknown, and unknowns cannot be risk-assessed. A well-built tool used sensibly may be perfectly safe; the problem is that nobody has checked, and nobody would know if its security posture changed.
How is shadow AI different from traditional shadow IT?
Shadow AI is a subset of shadow IT with two extra wrinkles: the data you paste in may be retained or used for training, and the tools often live inside software you have already approved, so they never look like a new application.
Should we simply block unapproved AI tools?
Blocking alone tends to move the activity to personal phones, where you have no visibility at all. Pair any block with a sanctioned alternative — that combination reduces shadow IT far more reliably than prohibition on its own.
How long does a first shadow IT discovery take?
For a business of 50–250 staff, expect two to four weeks for a first pass covering identity grants, network logs, expenses and an amnesty round. Keeping the register current afterwards is a few hours a week rather than a project.
Can an outstaffed engineer own this work?
Yes, and it suits the model well. This is continuous, process-driven work that benefits from one consistent owner — which is easier to justify at outstaffing rates than at local salary levels.
What should we do first if we have done nothing so far?
Pull your OAuth application grants this week. It takes under an hour, requires no new tooling, and reliably reveals the shadow IT that carries the most access to your data.
Bringing unapproved tools back into the light
Shadow IT is a signal, not a failure. It tells you where your sanctioned toolset is too slow, too limited or too hard to reach — and in the AI era that signal is arriving faster than most IT teams can process it. The organisations that handle it well are not the ones with the strictest rules; they are the ones with visibility, a fast yes-or-no path, and someone whose actual job it is to keep the register honest.
If that last part is what is missing, talk to OutsourceZA about adding UK-hours capacity to your team without UK-level cost.
Book your consultation
Book a chat with Niel or Johan so we can understand exactly what (and who) you need for your business to succeed. It’s also a great time to ask any questions you may have. See you soon!