Shadow AI refers to employees using unauthorized or unsanctioned generative AI tools instead of enterprise-approved solutions. This creates security risks because employees may inadvertently upload sensitive data, personal information, or intellectual property to external AI platforms that the organization cannot monitor or control.