
Shadow AI has traditionally referred to employees using unauthorized AI tools. But a new challenge is emerging: AI features embedded inside applications that enterprises have already approved.
From Microsoft 365 Copilot and Salesforce Einstein to Slack AI and Notion AI, vendors are rapidly adding AI capabilities through routine product updates.
These features often appear without a separate procurement process, leaving security teams unaware that an application's data boundaries have changed.
Approved Apps Don't Always Mean Approved AI
Unlike standalone AI applications, embedded AI lives inside trusted SaaS platforms. That makes it much harder to discover using traditional SaaS inventories or application blocklists.
An organization may have approved a CRM, collaboration platform, or documentation tool months ago. But when AI summarization, content generation, or autonomous workflows are introduced later, those capabilities can process corporate data without undergoing a dedicated security review.
Industry analysts increasingly warn that embedded AI is becoming one of the biggest blind spots in enterprise AI governance because organizations often govern the application—but not the AI feature inside it.
Security Teams Need Visibility Beyond SaaS Inventories
The challenge isn't simply discovering another application. It's understanding which AI features are active, what data they can access, and whether they introduce new permissions or external model interactions.
Recent research found that third-party embedded AI is where many organizations lose visibility, with leaders identifying vendor-controlled AI capabilities as a growing governance priority.
At the same time, security experts are calling for continuous monitoring instead of one-time vendor assessments as AI capabilities evolve.
What It Means for Enterprises
As SaaS vendors continue shipping AI features by default, enterprises can no longer assume that an approved application remains unchanged.
Effective AI governance now requires continuous visibility into embedded AI capabilities, alongside traditional SaaS management.
Organizations need to understand when AI features are activated, what enterprise data they can access, and whether existing security policies still apply.
For security teams, the focus is shifting from managing applications to governing the AI capabilities inside them.
Platforms like CloudEagle.ai help organizations discover embedded AI, identify Shadow AI, and continuously monitor AI usage so new AI features don't become hidden security and compliance risks
Let the headlines come straight to you with Access Granted — a monthly edition of Okta announcements, expert perspectives, analysis, and more.
