Shadow AI Is the Next Off-Channel Communications Risk
Shadow AI — the use of generative AI tools outside approved organizational governance — is emerging as the next evolution of communications compliance risk. As employees increasingly rely on AI to draft emails, summarize meetings, analyze documents, generate content, and accelerate everyday work, organizations must extend existing recordkeeping, supervision, and data governance practices to new ways of creating and sharing business communications.
The regulatory questions are familiar, even if the technology is new. Many of the governance principles developed for off-channel communications — including policy, training, monitoring, and approved technology — provide a strong foundation for governing AI. The challenge now is applying those controls consistently across public AI tools, enterprise AI platforms, and the next generation of autonomous AI agents.
Key takeaways
- Shadow AI creates many of the same recordkeeping and supervision risks as off-channel communications — while introducing new data governance challenges.
- Existing FINRA and SEC rules already apply to AI use, so organizations don't need to wait for AI-specific regulation to govern AI.
- AI-generated business communications may themselves become records that require supervision, retention, and discovery.
- Enterprise AI platforms reduce risk but do not eliminate governance, compliance, or recordkeeping obligations.
- The most effective approach is governing AI use through policy, monitoring, training, and approved tools — not prohibiting it.
Shadow AI mirrors the familiar off-channel problem
Shadow AI refers to employees using generative AI tools — ChatGPT, Claude, Gemini, and similar — for firm business without approval, oversight, or a way to capture what was shared. It describes unsupervised use, not a ban on AI itself.
Today, shadow AI extends far beyond consumer chatbots. Employees increasingly rely on Microsoft 365 Copilot, Google Gemini, Salesforce Einstein, Slack AI, Zoom AI Companion, Adobe Firefly, Notion AI, GitHub Copilot, and hundreds of emerging AI applications that may be attempting to access your enterprise software.
The security and data protection capabilities vary widely across providers and change frequently. That’s why it’s important for organizations to own the responsibility for governing how AI-generated communications, prompts, uploaded documents, and business outputs are used, retained, and supervised.
What is shadow AI?
Shadow AI is the unauthorized or unsanctioned use of artificial intelligence tools for business purposes outside an organization's approved governance framework. This includes public AI services, personal AI accounts, embedded AI features within enterprise software, browser extensions, AI coding assistants, and increasingly autonomous AI agents that complete work on behalf of employees.
Shadow AI does not necessarily mean employees are intentionally violating policy. More often, it reflects a gap between how quickly AI technology evolves and how quickly governance programs — which includes training — adapt.
If you spent the last few years building governance programs and written supervisory procedures (WSPs) for off-channel communications, you already understand the anatomy of the shadow AI problem. Senior management has witnessed how a text message from a registered rep's personal phone can lead to a significant regulatory action. The same logic applies here.
An employee faces productivity pressure. A convenient tool is available outside approved channels. They use it.
Sensitive firm or client data enters an environment the firm doesn't control or audit. In many cases, the firm doesn't even know the data left.
Unlike traditional off-channel messaging, AI introduces an additional challenge. Information may be transformed, summarized, analyzed, or incorporated into future AI interactions after it leaves the organization, depending on the provider's architecture, retention policies, and enterprise controls. Organizations may lose visibility into what data left and how it was later used.
What causes shadow AI?
Employees rarely adopt shadow AI because they want to bypass compliance. They adopt it because AI helps them work faster.
Professionals use AI to summarize meetings, draft emails, analyze spreadsheets, write client communications, generate marketing content, research regulations, create presentations, and automate repetitive tasks. When approved enterprise AI tools are unavailable — or perceived as less capable than consumer alternatives — employees often default to whatever tool delivers results most quickly.
This mirrors the behavioral patterns that fueled off-channel communications. Convenience consistently outweighs policy when organizations fail to provide secure, sanctioned alternatives.
FINRA's 2025 Annual Regulatory Oversight Report described off-channel communications failures in terms that apply almost word-for-word to shadow AI:
- Failing to retain and review communications made through non-firm-approved tools
- Writing overly general policies that don't specify permitted and prohibited platforms
- Neglecting to monitor for employee use of unapproved communication channels
The regulatory structure — FINRA Rule 3110, FINRA Rule 2210, and SEC Exchange Act Rule 17a-4 — does not care whether the unapproved channel is WhatsApp or a public generative AI output that is communicated or pertains to the business.
The same principle extends beyond financial services. Healthcare organizations must govern protected health information under HIPAA. Government agencies face public records, FOIA, and records retention obligations.
Insurance carriers, law firms, and life sciences organizations all face legal, contractual, and regulatory requirements governing business communications and sensitive information. Across every industry, the real question is whether organizations can govern AI use.
Firms that have already expanded these processes for off-channel communications have a head start. The work that's been done over the past two years extends directly to how firms will evaluate AI use.
Five key implications for compliance and legal teams
Generative AI is reshaping who's on the hook when something goes wrong. Here are five ways that shift plays out for compliance and legal teams.
1. Regulatory exposure is already here
FINRA Regulatory Notice 24-09 (June 2024) is unambiguous: FINRA rules are technology-neutral, applying to generative AI tools the same way they apply to any other technology. If an employee uses an unsanctioned AI tool to draft a client communication, that output may constitute a business communication subject to retention under Rule 17a-4. If the AI interaction informs a trading decision, supervision requirements under Rule 3110 are in scope.
The same obligations increasingly apply to AI-generated communications themselves. Whether AI drafts client emails, summarizes meetings, generates investment commentary, produces marketing copy, or assists customer service interactions, organizations remain accountable for ensuring those communications comply with existing supervisory, recordkeeping, advertising, privacy, and disclosure requirements.
AI changes how communications are created. It doesn't change the organization's regulatory responsibility for them.
As enterprise AI becomes embedded directly into productivity platforms like Microsoft Teams, Outlook, Slack, Salesforce, and Zoom, organizations should assume that AI-assisted communications will become part of everyday business operations rather than isolated technology experiments. Governance programs must evolve accordingly.
2. Data exfiltration compounds the recordkeeping risk
When an employee pastes a client account summary, a draft pitch, or non-public deal information into a public AI interface, that data has left the firm's control. Off-channel text messages mainly created a records-retention risk. Shadow AI compounds that exposure: the firm may not know what data was shared, with whom, or where it was processed.
FINRA's 2025 report identifies Data Loss Prevention (DLP) gaps — not monitoring outbound network activity for unauthorized data transfer — as an examination finding. Firms without DLP controls for AI-bound traffic have a blind spot examiners are likely to scrutinize.
AI interactions raise questions that traditional channels don't — like how long prompts, conversation history, and outputs get retained. This varies by AI provider and deployment model. Depending on the tool, that data may be kept, added to user history, or stored within enterprise environments.
Organizations should understand how approved AI tools manage prompts, files, and generated content to ensure sensitive information remains appropriately governed.
Enterprise AI platforms often provide stronger administrative controls than public AI tools, including configurable retention settings, identity management, and tenant-level security. Those capabilities reduce risk, but they do not eliminate an organization's responsibility to understand where business information resides, how AI-generated content is used, or whether business records must be retained under applicable regulatory requirements.
3. AI-generated communications introduce new supervisory obligations
AI is changing how business communications are created. Employees increasingly rely on AI to draft emails, summarize meetings, generate research, prepare client presentations, create marketing content, and recommend next actions. In many organizations, AI-generated content is becoming part of normal business operations rather than an isolated productivity tool.
Existing regulatory obligations continue to apply regardless of whether a communication is written entirely by an employee or generated with AI assistance. Organizations remain responsible for supervising business communications, maintaining required records, and ensuring AI-assisted outputs comply with applicable regulatory, legal, and internal policy requirements.
As AI capabilities expand, compliance teams should evaluate employee prompts and the business communications AI helps produce. Governance increasingly extends across the entire communication lifecycle — from prompt to generated output to the final communication delivered to a client, customer, or colleague.
4. Hallucinations increase accountability risk, not just accuracy risk
Generative AI systems can occasionally produce inaccurate, incomplete, or fabricated information, commonly referred to as hallucinations. While many discussions focus on the technical causes of hallucinations, the greater compliance concern is organizational accountability. If AI-generated content is distributed externally or relied upon internally, organizations — not AI vendors — remain responsible for its accuracy, appropriateness, and regulatory compliance.
This creates an additional supervisory obligation. AI-generated communications should be subject to the same governance principles organizations apply to employee-created business communications, including appropriate review, approval workflows, supervision, and retention where required. The objective is to ensure organizations maintain confidence in the information they distribute.
5. Prohibition alone will not work
The off-channel experience showed that blanket prohibitions, unsupported by monitoring and sanctioned alternatives, shift liability instead of changing behavior. Employees who used personal devices to communicate with clients did not stop because a WSP said they should. The same dynamic applies to AI.
Effective shadow AI programs go beyond prohibition, adding training, sanctioned alternatives, and monitoring capabilities that detect unauthorized use. A prohibition-only policy for AI tools invites the same examination findings that off-channel communications generated in 2022 and 2023.
Organizations should recognize why employees adopt shadow AI in the first place. AI helps people work faster, automate repetitive tasks, summarize complex information, generate content, and improve productivity.
Effective governance addresses that reality by providing secure, approved AI capabilities rather than relying solely on restrictive policies.
TIP
Map your existing off-channel controls to AI use cases before writing new policies. Most of the governance infrastructure already exists.
How off-channel controls map to shadow AI
Off-channel communications and shadow AI follow the same pattern: employees move to a tool the firm doesn't monitor, nothing gets captured or retained, and the firm loses the ability to supervise what was said.
Unapproved messaging apps like WhatsApp, Signal, and iMessage created this gap in recent years. Unapproved AI tools — ChatGPT, Claude, Gemini, and other public assistants — create the same gap today, and firms often have even less visibility into what was entered as a prompt or generated as output. It's the same regulatory exposure through a new communication channel.
| Off-channel problem | Shadow AI equivalent |
|---|---|
|
Unapproved messaging apps |
Unapproved AI tools |
|
No capture, no retention, no supervision |
Limited visibility into prompts and outputs |
|
Rule 17a-4 and Rule 3110 violations |
Same rules, new channels |
The controls firms built to close the off-channel gap carry over directly. Approved channel policies that name permitted and prohibited platforms become AI acceptable use policies that name approved tools and use cases. Network-level blocking becomes CASB and DLP monitoring for AI traffic. Keyword surveillance for off-channel indicators becomes usage monitoring paired with sanctioned AI alternatives, so employees have an approved option instead of a reason to go around one.
| Control deployed | AI governance equivalent |
|---|---|
|
Approved channel policy |
AI acceptable use policy |
|
Network-level blocking |
CASB/DLP monitoring |
|
Keyword surveillance |
Usage monitoring + sanctioned alternatives |
Shadow AI vs. enterprise AI
Not every AI tool carries the same risk. Shadow AI using public AI tools run on consumer accounts that individual users manage themselves, give firms limited administrative oversight, and may retain prompts under the provider's own policies rather than the firm's.
Enterprise AI platforms, including Microsoft 365 Copilot, Salesforce Einstein, Slack AI, Zoom AI Companion, and Google Workspace AI, run on organization-managed identities, give IT and compliance centralized control over access, and offer configurable retention and tenant-level settings.
Enterprise platforms lower shadow AI risk, but firms are still expected to supervise AI-assisted communications and apply the same recordkeeping controls they would anywhere else.
| Public AI | Enterprise AI |
|---|---|
|
Consumer accounts |
Organization-managed identities |
|
Limited admin oversight |
Centralized governance |
|
Individual users manage access |
IT and compliance manage access |
Shadow AI vs. BYOAI
Bring Your Own AI (BYOAI) refers to employees using personal AI accounts or preferred AI tools for business purposes, similar to Bring Your Own Device (BYOD). BYOAI is one of the most common forms of shadow AI because organizations often have little visibility into how personal AI services are used, what information is uploaded, or how generated outputs are incorporated into business communications.
Relying on employees' own, unapproved AI tools is not a sustainable end state for a regulated organization. However, technology is evolving quickly, and firms should have a mechanism in place to evaluate new tools that enable greater productivity. While it is not exactly like BYOD, firms can explore options to allow users to bring their own AI so that those tools can be evaluated for use by the business before a new shadow AI blind spot is created.
Shadow AI vs. off-channel communications
Off-channel communications and shadow AI share a common governance challenge: employees conducting business activities outside approved organizational oversight. The difference is that shadow AI expands the compliance risk surface to include IP leakage, cybersecurity issues, and data privacy violations.
Instead of only communicating through unapproved channels, employees may also upload confidential information, generate new business content, and increasingly rely on autonomous AI capabilities to perform work on their behalf.
Both challenges ultimately come down to the same governance question of whether your business can produce a defensible record if something goes wrong. Off-channel communications and shadow AI may look like administrative concerns. But without a record, organizations can't show what happened, when, or why.
Strong AI governance can reduce shadow AI use
Effective shadow AI governance relies on a practical set of controls. These controls extend governance infrastructure firms already have; none require waiting for new AI-specific regulation. Based on industry guidance and examination observations, effective programs share four characteristics.
Agentic AI is the next communications governance challenge
While most organizations are still operationalizing governance programs for generative AI, the next wave of innovation is already emerging: agentic AI. Unlike traditional generative AI, which responds to prompts, agentic AI can plan, make decisions, and execute multi-step tasks with limited human intervention. AI agents can schedule meetings, draft and send emails, analyze documents, generate reports, access and update CRM records, conduct research, and coordinate workflows across multiple business systems.
For compliance teams, this is the next evolution of communications governance. Instead of relying only on a human "in the loop" to evaluate generative AI outputs, firms need to shift toward human "on the loop" oversight — designing, testing, and implementing controls before agents connect to enterprise systems.
The underlying regulatory principles remain unchanged. Organizations are responsible for the business communications created within their environment, regardless of whether they originate from a person, an AI assistant, or an autonomous AI workflow. The challenge is extending governance, supervision, and recordkeeping controls to these new forms of business communication before they become another off-channel blind spot.
Five steps to closing your shadow AI gap
Closing the shadow AI gap starts with visibility and ends with sustained oversight. These five steps give compliance and IT leaders a practical path forward.
1. Audit current AI tool usage
Survey business lines, review network logs, and identify which AI tools employees use today, authorized or not, before you build controls around them. Look beyond public AI services. Inventory enterprise AI capabilities already embedded in productivity platforms such as Microsoft 365 Copilot, Salesforce Einstein, Slack AI, Zoom AI Companion, Google Workspace AI, Adobe Firefly, and other AI-enabled business applications. Understanding where AI is already being used is the first step toward governing it effectively.
2. Update your policies to address AI directly
FINRA's examination findings on off-channel communications have consistently cited overly general policies. Name specific permitted and prohibited AI tools in your acceptable use policy, and describe how you'll supervise AI-assisted communications, especially client-facing outputs.
Organizations should also define approved AI use cases, establish AI vendor evaluation criteria, clarify employee responsibilities, and document how AI-generated business communications will be reviewed, retained, and supervised.
3. Extend DLP and CASB monitoring to AI traffic
Configure DLP rules to flag uploads to known AI endpoints and alert on sensitive data patterns. Document these controls so they hold up under examination.
As AI adoption grows, organizations should expand monitoring beyond uploads to include broader AI usage patterns, emerging AI applications, and new autonomous workflows that may introduce governance or data protection risks.
4. Stand up sanctioned AI alternatives
Work with IT and business leaders to deploy enterprise AI tools that operate inside the firm's data governance boundary, so outputs are captured, retained, and supervised.
Employees consistently choose the tools that help them work most efficiently. Providing secure, enterprise-approved AI capabilities reduces the incentive to use unauthorized consumer AI services while enabling innovation within established governance controls.
5. Run targeted, use-case-specific training
Connect shadow AI behavior to regulatory consequence directly. Off-channel enforcement actions offer a close, recognizable parallel that helps employees recognize the risks quickly. Training should focus on practical scenarios employees encounter every day, including drafting client emails, summarizing meetings, creating presentations, analyzing confidential information, and using AI embedded within enterprise applications. Clear guidance is significantly more effective than broad warnings about AI risk.
Closing the shadow AI gap starts with what you have
Shadow AI is the off-channel problem you already know how to manage, applied to a new generation of technology.
Firms that have spent the past several years strengthening off-channel communications governance are well positioned to govern AI. The policy framework, supervisory processes, monitoring capabilities, and governance mindset already exist. The next step is extending those capabilities across generative AI, enterprise AI, and autonomous AI agents.
Organizations that treat AI governance as an extension of communications governance will be better positioned to support innovation while maintaining compliance and earning trust.
The goal is making sure every business communication — whether created by a person, generated with AI, or initiated by an autonomous AI agent — is captured, governed, supervised, retained, and discoverable.
Frequently asked questions
Shadow AI is the unauthorized use of generative AI tools by employees outside firm-approved channels — similar to how employees historically used personal messaging apps outside approved communication channels.
The SEC, FINRA, FCA and other regulatory bodies have been consistent in stating that rules are meant to be technology agnostic, and firms are expected to be aware of when AI outputs touch existing regulatory obligations and workflows — and ensure that the proper controls are in place.
Financial advisors may use AI tools where permitted by their organization, but firms remain responsible for supervising AI-assisted communications, protecting confidential information, and complying with applicable SEC and FINRA requirements.
Organizations should evaluate whether AI prompts, uploaded documents, generated outputs, or related metadata constitute business records under applicable regulatory, legal, or internal governance requirements. Retention policies should align with the organization's broader communications governance strategy.
AI recordkeeping refers to preserving AI-generated business records, communications, prompts where appropriate, metadata, and related business information in accordance with regulatory, legal, and organizational requirements.
Bring Your Own AI (BYOAI) describes employees using personal or unauthorized AI tools for business purposes. Like BYOD and off-channel communications before it, BYOAI introduces governance, security, and compliance challenges when organizations lack visibility into how AI is being used.
Firms can extend existing off-channel governance controls — acceptable use policies, employee training, DLP/CASB monitoring, and sanctioned AI alternatives — to cover generative AI tools.
AI vendor risk management is critical. Firms should assess a provider's data protection practices, experience working in highly regulated environments, and SLAs for retrieving information.
Share this post!
Smarsh Blog
Our internal subject matter experts and our network of external industry experts are featured with insights into the technology and industry trends that affect your electronic communications compliance initiatives. Sign up to benefit from their deep understanding, tips and best practices regarding how your company can manage compliance risk while unlocking the business value of your communications data.
Ready to enable compliant productivity?
Join the 6,500+ customers using Smarsh to drive their business forward.




Subscribe to the Smarsh Blog Digest
Subscribe to receive a monthly digest of articles exploring regulatory updates, news, trends and best practices in electronic communications capture and archiving.
Smarsh handles information you submit to Smarsh in accordance with its Privacy Policy. By clicking "submit", you consent to Smarsh processing your information and storing it in accordance with the Privacy Policy and agree to receive communications from Smarsh and its third-party partners regarding products and services that may be of interest to you. You may withdraw your consent at any time by emailing [email protected].
FOLLOW US