Most employees who install an unapproved app or sign up for a new SaaS tool are trying to get their work done faster. The trouble starts afterward: IT can’t patch software it doesn’t know about, can’t protect data stored in services it never approved, and can’t avoid paying twice for tools that overlap.
That gap is widening. Gartner predicts that by 2027, 75% of employees will acquire, modify, or create technology outside IT’s visibility, up from 41% in 2022.
This guide covers what shadow IT is, where it appears, why employees turn to it, what it costs, and how IT teams can detect and reduce it.
What is shadow IT?
Shadow IT is any hardware, software, cloud service, or AI tool that employees use for work without the knowledge or approval of the IT department. It includes unapproved apps installed on company computers, personal devices used to access company data, and SaaS subscriptions purchased outside IT’s procurement process.
Shadow IT is rarely malicious. It’s usually a workaround: an employee needs a capability, the approved tool doesn’t provide it, or the approval process feels slow, so they find their own solution. The risk comes from the fact that IT can’t manage, secure, or account for technology it doesn’t know exists.
Common examples of shadow IT
Shadow IT can show up almost anywhere employees use technology. Common examples include:
Unapproved SaaS applications: Project management, file-sharing, or design tools that a team signs up for with a company card or a personal account.
Messaging and collaboration apps: Third-party chat or video tools used alongside, or in place of, the company’s approved platform.
Personal cloud storage: Work files saved to personal accounts so they’re easier to reach from home or share with outside contacts.
Software installed on company computers: Utilities, browsers, remote access tools, or free downloads that employees install without IT’s involvement.
Browser extensions: Add-ons that can read page content or connect to outside services, often installed without any review.
Generative AI tools (shadow AI): Public AI chatbots and assistants used to draft content, summarize documents, or analyze data, sometimes with company information pasted in.
Personal devices: Laptops, tablets, and phones used for work without approval or outside a formal BYOD program.
Why employees turn to shadow IT
Several pressures drive shadow IT. Some employees adopt their own tools to solve a problem without waiting on IT, especially when the approved option has recurring issues or lacks a feature they need. Others take a “better to ask forgiveness than permission” approach because the official approval process feels slow.
Hybrid and remote work adds to the problem. Employees may prefer to use personal computers and tablets for work, even when the company has no policy that allows it. Some people simply don’t know an IT policy exists, or don’t realize that what they’re doing falls outside it.
These causes point to part of the fix. When approved tools meet employees’ needs and software requests get quick answers, there’s less reason to go around IT.
The risks and hidden costs of shadow IT
The cost of shadow IT goes beyond subscription fees. Most of it shows up indirectly, as security exposure, wasted spend, and extra work for IT.
1. Security gaps from unpatched software
Software IT doesn’t know about doesn’t get patched. Unapproved apps can sit on endpoints for months running outdated versions with known vulnerabilities, and IT can’t prioritize fixes for software that isn’t on its radar.
2. Data exposure and compliance issues
When company data moves into unapproved apps, personal cloud accounts, or public AI tools, IT loses control over where it’s stored, who can access it, and how long it’s kept. That can complicate audits and make it harder to show that sensitive data is handled according to policy.
3. Duplicate and unused spending
When teams buy their own tools, organizations often end up paying for several applications that do the same job. Subscriptions can keep renewing after the person who bought them moves on, and approved licenses can sit unused while employees rely on tools they found themselves.
4. Extra work for IT teams
Shadow IT generates support requests for tools IT never vetted, integration problems with approved systems, and cleanup work when an unapproved app causes an issue. Unknown tools also slow incident response, because IT first has to discover what’s involved before it can act.
How to detect shadow IT
Shadow IT spans devices, installed software, and cloud services, so no single signal catches all of it. Most IT teams combine several sources:
Endpoint software inventory: A current list of the applications installed on each managed computer shows unapproved software soon after it appears.
Software installation alerts: Alerts on new installs let IT review changes as they happen, without waiting for a scheduled audit.
Expense and procurement records: Recurring charges for software that never went through IT often reveal unapproved SaaS subscriptions.
Identity and sign-in logs: Sign-ins to unapproved apps with company accounts can surface cloud services that don’t live on an endpoint.
Conversations with teams: Asking departments which tools they actually use can uncover gaps in the approved toolset faster than any scan.
Endpoint inventory is the foundation for the software side of the problem, and it’s a core part of IT asset inventory management.
How to reduce shadow IT and its costs
These steps help keep shadow IT small, visible, and inexpensive, and they fit within a broader set of IT security best practices.
1. Keep inventory current with continuous monitoring
The longer unapproved software stays on an endpoint, the longer it can go unpatched and the longer the organization may pay for it. Annual audits built on static spreadsheets leave months where new software goes unnoticed.
Use an endpoint management tool that keeps hardware and software inventory up to date for every managed computer and alerts IT when software is installed or removed. That makes shadow IT discovery part of routine operations.
2. Compare installs against what you pay for
Software inventory answers a basic cost question: how many copies of each application are installed, and where? Comparing that count with purchased seats can reveal licenses nobody is using, as well as tools installed on more machines than the organization has paid for.
Look for overlap too. If inventory shows several applications doing the same job across departments, they’re candidates for consolidation.
3. Standardize on approved tools and make requests easy
Redundant tools add cost and complexity. Agree on a standard set of approved applications for common needs such as messaging, file sharing, and project management, and publish the list so employees know what’s available. Working with fewer vendors can also simplify renewals and may improve pricing.
Pair the list with a simple, fast request process. Employees are less likely to go around IT when they can get a quick answer.
4. Connect inventory to patching
Unapproved apps are often the ones that fall behind on updates. When inventory, vulnerability data, and patch status live in the same place, IT can see which endpoints are running outdated or vulnerable software and decide whether to update it or remove it.
5. Remove unapproved software quickly
When unapproved software turns up, a fast response limits both risk and cost. Running an uninstall script or remote command on the affected endpoint lets IT remove it without a desk visit or a full remote session.
Follow up with the employee as well. Learning why they installed the tool can reveal a need the approved toolset doesn’t meet.
How Splashtop AEM helps IT teams control shadow IT
Splashtop AEM (Autonomous Endpoint Management) is an endpoint management platform that gives IT teams real-time visibility and policy-based automation across managed endpoints from a single console.
Hardware and software inventory shows system, hardware, and software details for each managed computer, with snapshots IT can compare over time and exports for audit reviews. The Software Inventory view can be filtered by vendor or platform, which makes it easier to spot unapproved applications and count installs across the environment. Configurable alerts notify IT when software is installed or uninstalled, or when hardware is added or removed.
When IT finds something to address, Scripts and Tasks can run commands, scripts, and installations across multiple endpoints at once, and Smart Actions can run a predefined task automatically when an alert triggers. Policy-based patching for operating systems and 100+ third-party applications, AI-powered CVE insights, and dashboards help keep approved software current and show where risk remains.
Get visibility into the software on every managed endpoint
Shadow IT grows in the gap between what employees need and what IT can see. Closing that gap starts with an accurate, current view of the software running across your endpoints, followed by a clear set of approved tools and a fast way to act when something unapproved appears.
Splashtop AEM gives IT teams that visibility, along with the automation to keep endpoints patched and consistent. Start a free trial to see what’s running across your managed endpoints, with no credit card required.






