← Back to blog

Shadow AI is the BFSI governance blind spot nobody put on the risk register

Every Indian bank, NBFC and insurer now runs an AI program it never approved, never inventoried and cannot see. Shadow AI has quietly become the fastest-growing attack surface in financial services.

Anand Prabhu·Co-founder, AramGRC·June 17, 2026·9 min read

Every Indian bank, NBFC and insurer now has an AI program it never approved, never inventoried and cannot see. It is called shadow AI — staff pasting customer data, underwriting notes and board decks into consumer chatbots — and it has quietly become the fastest-growing attack surface in financial services.

The numbers are stark.

Salesforce's 2026 workforce survey found that roughly two-thirds of employees now use AI tools at work, while fewer than one in five organisations have any formal AI security policy. Productiv's 2026 analysis puts the average enterprise at around 14 distinct AI tools in active use — of which IT is typically aware of only four or five.

A BlackFog survey of 2,000 workers at large firms found nearly half adopting AI without employer approval, and — more troubling for any risk committee — a majority of C-suite and senior leaders comfortable looking the other way. For a regulated financial institution, the exposure is not abstract. When a relationship manager drops a delinquent borrower's profile into a free chatbot to draft a polite reminder, that record enters a third-party processing pipeline outside the institution's data-protection controls.

Under India's DPDP Act, that is processing without a lawful basis. Under RBI's outsourcing and IT governance expectations, it is an undocumented data flow to an unassessed third party. Neither shows up in a single control narrative today.

The cost is measurable. IBM's 2025 Cost of a Data Breach research found that breaches involving shadow AI carried a meaningful premium over the baseline, and industry trackers now put the average shadow-AI-linked breach in the multi-million-dollar range. Layer on the fact that around three-quarters of shadow AI tools fail SOC 2 expectations, and the governance gap becomes a balance-sheet item.

What good looks like: a live AI inventory that captures sanctioned and discovered tools; network and CASB telemetry to surface unmanaged GenAI traffic; a clear, role-specific data-handling policy (never paste KYC, account numbers, model logic or board material); and — critically — a sanctioned alternative, because the evidence is unambiguous that providing an approved enterprise tool collapses shadow usage faster than any ban.

Software AG's research found that roughly half of shadow AI users said they would keep using their tool even if it were explicitly banned. You cannot prohibit your way out of this. You govern your way out.

Shadow AIBFSIGovernance
WhatsApp