A nurse pastes a patient’s discharge summary into a free chatbot to draft it faster. A billing coordinator uploads a claims spreadsheet to get help spotting errors. A case manager asks a public AI tool to summarize a complex chart. None of this activity looks like a security incident. It looks like someone getting their work done faster.
That’s what makes shadow AI different from the traditional threats healthcare organizations are used to defending against. There’s no malicious actor or intrusion. The activity looks normal, until a breach investigation or an insurance claim reveals it wasn’t. Shadow AI presents a new challenge for security-minded healthcare organizations, especially as they navigate the cyber insurance landscape. Here’s what you need to know about this new threat.
What Is Shadow AI?
In a healthcare setting, shadow AI is the unauthorized or unvetted use of AI tools and large language models (LLMs) by clinical, administrative, and technical staff. A Wolters Kluwer report found that 17% of healthcare professionals surveyed admitted to using unapproved AI tools. 50% did so “for a faster workflow, and 1 in 3 pointed to either a lack of approved tools or the approved tools lacking the desired functionality,” according to the report.
It’s clear that healthcare workers want ways to work more efficiently, and they know AI tools are here to help them achieve that goal. While 17% may not seem like a significant percentage, consider that just one instance of unauthorized use of an AI tool could lead to a security breach. The report cites that the average cost of AI security breaches for the healthcare industry in 2025 was $7.42 million. The risks are huge and growing.
The Part Insurers Are Starting to Ask About
Insurers are well aware of this risk, and they’re catching up. Until shadow AI, cyber insurance underwriting hinged on an organization’s ability to self-report about its risk. For example, what vendors touch your data and what safeguards do you have in place? Shadow AI threatens this model because of the unknown or unidentifiable AI usage occurring in an organization for everyday work.
Research from Paubox in 2025 found that “95% of healthcare organizations say employees with access to protected health information (PHI) are already using AI tools in email, yet one in four admit they have not formally approved any AI use at all.” The same research found that 75% of healthcare IT and compliance leaders believe employees mistakenly assume that tools like Microsoft Copilot are automatically HIPAA compliant.
Clearly, use of the technology is outpacing its governance, so insurers are starting to ask questions in underwriting applications about AI oversight. They’re treating scenarios in which unapproved AI tools process PHI as undisclosed vendor relationships — no different than an unvetted subcontractor. If a breach investigation discovers that gap, it may be considered misrepresentation and used to dispute or deny claims.
Two Sides of the Same Governance Gap
I recently wrote about a related risk: over-delegation, where employees using sanctioned AI tools stop scrutinizing the outputs and start auto-approving them. Shadow AI and over-delegation are two sides of the same coin. One happens outside the boundaries of governance, and the other happens inside boundaries that aren’t rigorous enough to catch a bad decision. In both cases, stronger AI oversight and crystal-clear communication of AI policies to employees are the answers.
How to Govern AI in Healthcare
Banning certain AI tools may be a natural instinct, but it doesn’t work. Staff facing real workload pressure will find a workaround, and a ban just pushes the activity further out of sight. The organizations managing shadow AI well tend to build a few things into their approach:
- They start with a governance body that consists of a cross-functional group of leaders across clinical, IT, compliance, and risk management. These people have the authority to evaluate and approve tools.
- That group classifies data by sensitivity to determine what material can go into an AI tool.
- They publish a specific list of sanctioned platforms along with a list of what’s off limits.
- They require real authorization and training before anyone gets access.
- They build in monitoring and audit trails so usage can be reviewed.
Governance Is a Key to Better Insurance Coverage (and Premiums)
As AI oversight becomes a standard part of cyber insurance underwriting, the organizations best positioned for coverage and good rates will be the ones that can demonstrate how they govern AI. What tools you permit, how you train your employees, cadence of communication, and what you prevent from going into AI tools are all factors.
If you’re unsure of how you’d answer an underwriter’s AI questions today, GuideIT helps healthcare organizations build AI governance programs that hold up under scrutiny. From policy development to tool vetting and staff training, we can help you close your shadow AI gap. Reach out to ask any questions of our AI leadership.
The Top Three Considerations for Healthcare Organizations Migrating to Windows 11
Next InsightWhy Insurers Want You Secure, Not Just Insured
Contact US
Wherever You’re Going, We’ll Develop the Way
Schedule a Free Consultation to discuss how GuideIT can plan your organization’s transformation.
Schedule a Free Consultation