
Written by:
Editorial Team
DSG.AI
Internal audit has a new category of risk to opine on: AI agents running in your organization that nobody in IT, risk, or compliance formally approved. Shadow AI is the 2026 version of shadow IT, and it is moving faster, operating more autonomously, and touching more sensitive data than unsanctioned SaaS ever did.
Eighty percent of organizations report moderate-to-pervasive shadow AI use, according to a June 2026 industry roundup in Corporate Compliance Insights. Only 25% have full visibility into it. Zenity's 2026 State of AI Agents in the Enterprise study found that 82% of enterprises have AI agents their security teams didn't know existed. These are not experimental chatbots. They are agents that read email, access CRM data, query financial systems, and write to production databases.
The audit function's job is not to ban shadow AI. That ship has sailed. The job is to build an audit framework that governs what's already in use, identifies the highest-risk deployments, and gives the business a path to legitimize the agents worth keeping.
What makes shadow AI different from shadow IT
Shadow IT (an employee using Dropbox to share a file, or a team running a SaaS tool on a corporate card without procurement approval) created data governance and contract risk. Shadow AI creates all of that, plus:
Autonomous action risk. An unsanctioned SaaS tool stores data. An unsanctioned AI agent acts on it: drafts a response, routes a request, makes a scheduling decision, triggers a workflow. The difference between storage and action is the difference between a compliance gap and an operational risk.
Model opacity. When an employee uses an unapproved LLM to draft client communications, you often can't tell what training data the model used, what it retained, or whether its outputs meet your policies. The explainability gap is a direct audit scope problem.
Scale. A single AI agent can perform thousands of transactions per day. A single misconfigured agent can exfiltrate sensitive data, violate customer agreements, or produce biased outputs at a volume no human employee could match. Audit coverage for shadow AI cannot be sampling-based in the traditional sense.
EU AI Act exposure. As of August 2, 2026, the EU AI Act's Annex III high-risk system provisions are fully enforced. Penalties reach EUR 35M or 7% of global annual turnover for the most serious violations. An AI agent your organization didn't formally deploy, assess, or classify is a potential regulatory exposure, not just an IT governance gap.
The audit team's challenge: auditing what you didn't procure
The IIA Global Internal Audit Standards Cybersecurity Topical Requirement, effective February 5, 2026, gives audit teams a measurable framework for cyber risk. Shadow AI sits at the intersection of cybersecurity, data governance, and operational risk, and it is explicitly within scope.
The challenge is inventory. You cannot audit what you cannot see. Fifty-nine percent of audit, GRC, and IT decision-makers say shadow AI is a concern (Corporate Compliance Insights, June 2026), but concern and visibility are different things.
Step 1: Build the shadow AI inventory
The starting point is discovery, not assessment. This means:
Survey the business. A structured questionnaire to business unit heads and IT liaisons asking: what AI tools do your teams use? Which were procured through IT? Which were subscribed to directly? Which were built using vendor APIs? The answers will be incomplete: people underreport tools they know weren't approved; the gaps in the survey results are themselves a finding.
Scan network and endpoint logs. Legitimate procurement leaves an audit trail; shadow AI often doesn't. Network traffic logs frequently reveal LLM API calls (OpenAI, Anthropic, Google, Cohere) that were never routed through IT procurement. Endpoint logs may show browser extensions, CLI tools, or local model runners.
Review expense reports and corporate card data. Most shadow AI has a subscription fee. AI tools appear on expense reports labeled as "productivity software" or "research tools." A targeted review of software-category expenses typically surfaces 30-50% of unregistered AI tools in a first pass.
Engage IT and security. Your security team may already be investigating this. In 82% of enterprises, they are running behind the deployment curve (Zenity 2026). The audit should not duplicate their work but should independently verify their inventory and coverage claims.
Step 2: Risk-classify the agents you find
Not all shadow AI carries the same risk. The audit framework needs a classification scheme that prioritizes investigation and remediation.
| Risk tier | Criteria | Example | Audit response |
|---|---|---|---|
| Tier 1: Critical | Accesses regulated data (PII, financial, health); takes autonomous action; touches production systems | Agent drafting client communications from CRM data; agent querying financial databases to auto-generate reports | Immediate escalation; pause deployment pending formal risk assessment |
| Tier 2: High | Accesses internal-only data; takes action within internal systems; no regulated data but significant operational exposure | Agent summarizing internal meeting notes and routing to shared channels; agent auto-scheduling across business units | Document within 30 days; require formal AI governance review within 60 days |
| Tier 3: Moderate | Individual-use AI tools with no system integration; no action capability; no regulated data | Employee using a standalone LLM for personal productivity (drafting, research) with no company data input | Include in AI policy communication; no formal remediation unless policy violation confirmed |
| Tier 4: Low | Productivity AI in sanctioned vendor tools (Copilot in Microsoft 365, AI in Google Workspace) where the vendor has accepted data processing agreements | Microsoft Copilot used within the contracted O365 tenant | No action beyond confirming vendor DPA covers AI features |
Step 3: Audit the Tier 1 and Tier 2 agents
For the high-risk deployments, the audit should cover five areas:
1. Data governance. What data does the agent access? Is that data covered by the organization's privacy policy, customer agreements, and any applicable regulations? Was consent obtained where required? For EU AI Act Annex III applications, has a fundamental rights impact assessment been completed?
2. Model and provider risk. Which LLM provider powers the agent? What are the provider's data retention policies? Does the provider use your inputs to retrain its models (with or without opt-out)? Is the provider's security posture compatible with your data classification?
3. Output quality controls. What human review exists for the agent's outputs? Are there guardrails on what the agent can and cannot do (e.g., can it send external emails autonomously, or only draft for human approval)? How are errors caught and corrected?
4. Access controls. What credentials does the agent use? Are they personal credentials (an employee's API key), shared credentials, or a formally provisioned service account? Who can revoke access?
5. Logging and auditability. Is the agent's activity logged? Can you reconstruct what the agent did, when, and based on what inputs? For agentic workflows, auditability is the primary governance control: if there is no log, there is no audit trail.
Step 4: Establish a path to legitimacy
The audit's job is not to shut down every unsanctioned AI agent. Many of them are solving real business problems. The goal is to establish what a legitimate AI deployment looks like and give teams a path to get there.
This means creating (or recommending) a light-touch AI registration process: business unit submits an AI tool or agent for review, IT/security runs a standardized assessment, legal reviews data processing terms, and the tool is either approved (with conditions), approved pending changes, or prohibited. The registration process should be fast enough that employees use it rather than bypass it.
The audit's contribution is to define the minimum governance requirements : the five areas above: and to verify that registered tools actually meet them. That is a permanent audit scope item, not a one-time project.
What the IIA standards require
The IIA's Global Internal Audit Standards, effective January 2025, explicitly include technology risk in the audit universe. The Cybersecurity Topical Requirement (February 2026) adds AI-specific scope: audit teams are expected to assess AI tools used by the organization, including tools that support audit workflows themselves.
The EU AI Act adds a mandatory layer for organizations subject to EU law: any AI system falling under Annex III (high-risk applications including employment, credit, law enforcement, critical infrastructure, and others) requires a conformity assessment, technical documentation, human oversight measures, and registration in the EU AI database. An agent your organization didn't formally procure or assess is in violation from day one.
The shadow AI audit as an annual program
Shadow AI inventory will be out of date within six months. The pace of AI agent deployment means that the tools in use today will be different from the tools in use in Q4. This is not a one-time audit project; it is a recurring program.
Annual cadence minimum: survey update, network log review, expense report scan, and re-assessment of any Tier 1 or Tier 2 agents that have changed scope or provider. For organizations with high AI adoption rates, quarterly touchpoints on the high-risk tier are appropriate.
The audit function that builds this competency now, before AI agents become more deeply embedded in business operations, is in a better position than the function that waits for a regulatory finding or a data incident to force the issue.
Related: How to Govern an AI Audit Agent: The Explainability Gap No One Is Solving covers governance frameworks for the agentic audit tools your team uses. ISO 42001 for Internal Auditors: What the AI Management System Standard Means for Your Audit Plan maps the ISO 42001 requirements to audit scope. AI Agents for Internal Audit: What Actually Works in Production covers the production deployment landscape. For the full AI adoption statistics: AI in Internal Audit: Adoption Statistics and Research.
Sources
- Corporate Compliance Insights: News Roundup, June 5, 2026: shadow AI adoption and visibility figures.
- Zenity: State of AI Agents in the Enterprise 2026: 82% enterprises with unknown AI agents.
- The Institute of Internal Auditors: Global Internal Audit Standards, effective January 2025.
- The Institute of Internal Auditors: Cybersecurity Topical Requirement, effective February 5, 2026.
- EU Official Journal: Regulation (EU) 2024/1689, EU AI Act: Annex III enforcement from August 2, 2026; penalties up to EUR 35M or 7% of global turnover.
- Internal Audit 360: Shadow AI: The Growing Risk Internal Auditors Must Address.
Related
- Internal Audit Sourcing Cost Reference (2026): In-House vs. Mid-Tier vs. Big 4 vs. AaaS
- AI in Internal Audit: Adoption Statistics and Research (2026 Library)
- Audit-as-a-Service: What It Is, What It Costs, and When It Beats Hiring
- Co-Sourcing vs. Outsourcing Internal Audit: The Decision in One Table
- What Compliance-as-a-Service Actually Includes (and What Vendors Leave Out)


