All insights

Governance & Audit

Shadow AI in Government Offices: The Real Risk

· 10 minute read

The real AI incident in most offices will not be a jailbroken on-prem model. It will be a clerk pasting an official PDF into a public chatbot because the official path was slow, blocked, or never built.

Walk a district office after lunch and you can already see the official future and the unofficial present on the same desk. The official future is a circular about a forthcoming AI helpdesk. The unofficial present is a browser tab, often on a phone hotspot because the NIC proxy still blocks the interesting sites, into which a clerk has dropped a scanned grievance and last week's standard reply. The clerk is not a villain. The clerk is trying to finish the dak. The PDF, however, is now in a system no one in the department can subpoena, delete, or even name with confidence.

This is an opinion, and the opinion is blunt. Shadow AI — unofficial public chatbots processing official files — is the dominant near-term risk for Indian government offices, PSUs and campuses. It is larger than the risk that your still-unbought official agent will hallucinate a scheme name. You cannot govern a model you did not deploy. You can only govern the habit, the approved path, and the file.

It is not legal advice and it is not a claim that any particular public product is unlawful to use for personal tasks. It is a claim about official PDFs, unpublished notes, and citizen attachments leaving the estate without a processor contract, a purpose, or a log.

Name the thing

Shadow AI is not a staff member using a thesaurus. It is unofficial processing of official information by a public model host the department does not control. The usual objects are PDFs of notes, scanned certificates, draft tenders, citizen emails, Excel extracts from an MIS, and question-bank fragments. The usual hosts are consumer chatbots, browser plugins, and 'free' meeting-summariser extensions that join official video calls.

It spreads for three boring reasons. The official path is slow or absent. The official machine blocks the useful site while the phone does not. And leadership announced AI as a virtue without issuing a tool. Virtue plus vacuum equals paste.

Do not confuse it with a sanctioned pilot on a vendor cloud that you at least have on a file. That may be a bad architecture. It is not shadow. Shadow is the processing that never entered the register.

The harms that are not science fiction

Leakage is the first harm. A draft tender, a cabinet paragraph, a student's disability certificate, a vendor's commercial, an answer key. You will not get a tidy breach email from the public host. You will get a rumour, a coaching-centre screenshot, or a journalist's question.

Unlogged decisions are the second. An officer who asks a public model whether a grievance is 'fit for rejection' and then rejects it has made a decision with an invisible adviser. RTI, CAG and the citizen will ask for the record. The record will be a chat the officer cannot export and the department cannot retain for CERT-In's 180 days because the department never held it.

Contamination is the third. Once staff trust a fluent unofficial answer, they stop opening the circular. Wrong scheme names enter standard replies. That is not a deepfake crisis. It is a quiet decay of the official voice.

Vendor and vigilance risk is the fourth. A bidder who learns that evaluation notes were pasted into a public tool has a story. A vigilance angle does not need a proven leak. It needs a process that looks reckless.

If you only brief leadership on model jailbreaks, you are briefing the wrong incident.
What left the deskWhy staff did itWhat you cannot do afterwards
Citizen PDF + draft replyOfficial helpdesk not live; dak is heavyErase the host's copy; prove who saw it
Draft RFP / commercial comparisonWanted cleaner English before the committeeConvince a bidder the process was closed
Question paper fragmentFaculty 'checked wording' from homeTrust the exam, or afford a re-exam
Board / cabinet draftPA on a deadline, official VPN downControl the paraphrase once it is out

What the law already lets you say

You do not need a new AI Act to tell staff not to send official files to strangers. Service rules, classification circulars, official-secrets provisions where they apply, and ordinary IT acceptable use already cover disclosure. DPDP will add a fiduciary duty that is hard to reconcile with unofficial processors you never appointed. MeitY notified the Act and the 2025 Rules on 13 November 2025. Most remaining operational duties apply from 13 May 2027. The habit will not wait.

CERT-In's 28 April 2022 directions expect specified ICT logs to be retained for 180 days in India. A public chatbot on a personal phone is not your ICT. You cannot retain what you never saw. That is the compliance shape of shadow AI: not a missing clause, a missing system.

The India AI Governance Guidelines of 5 November 2025 will be quoted in speeches about responsible AI. Quote them if it helps you get an official tool funded. Do not quote them as if they had already criminalised a browser tab. They are guidelines, not a substitute for an office order and a working on-prem or otherwise official agent.

Detection without a witch-hunt

You will not find most shadow AI in a proxy log if it rides on phones. Look at behaviour. Sections that produce sudden fluent English on files that used to be clumsy. Staff who cannot name the circular they just cited. A shared password to a consumer AI account on a desk desktop. Meeting bots that appear in official video calls uninvited.

Ask, in writing, which unofficial tools are in use. Amnesty for the first inventory week produces a longer list than a threat. The list is the start of a register, not the start of charges.

Then measure friction on the official path. If the official agent needs four logins and cannot see the circular corpus, you are funding shadow AI with your own architecture. Blocking sites on the LAN without offering a desk tool is how you move the paste to 4G.

Replace. Do not only forbid.

The only durable answer is an official path that is faster than the unofficial one for the actual job: summarise a circular, draft a reply, check a checklist, retrieve a scheme rule. On-prem or air-gapped if the files are live citizen or unpublished papers. No training on customer data. A log the department holds.

Forbidding without replacement is a press note. Staff will nod and keep a second phone. Leadership that wants both a headline about AI and a ban on tools will get the leak and the headline.

This is why shadow AI is a procurement problem as much as a conduct problem. The vacuum is a purchase you postponed.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.

We blocked the websites. Problem solved.

You blocked them on the LAN. Phones remain. Meeting plugins remain. Blocking without an official tool raises the IQ of the workaround. Measure phones and offer a desk path.

Our staff are too junior to cause a real leak.

Junior staff handle the PDFs. Senior staff handle the drafts. Both paste. Rank is not a control. Class of file is.

Public models already saw the gazette. What is the harm?

The gazette is public. The noting, the attachment, the draft, the commercial, the student certificate are not. Shadow AI is almost never a gazette-only paste.

We will wait for a national circular on unofficial AI.

You already have disclosure rules. Waiting is how the first incident writes the circular for you, in a newspaper.

A 21-day shadow-AI reduction

The aim is not a body count of clerks. The aim is a register of unofficial tools, a signed AUP, and a faster official path for the two most common pastes.

  1. Week 1: amnesty inventory. Which tools, which file classes, which sections. No charges for honest lists.
  2. Week 2: issue the two-page AUP. Name approved tools even if the list is short. Open an official drafting path for published circulars.
  3. Week 3: pick the two heaviest unofficial jobs — usually grievance rewrite and circular summary — and put them on an official agent with logs. Brief section heads on phones and photographed files.

How this shows up in the file

The file should hold the inventory, the AUP, the residual-risk note on personal devices, and the date the official path went live for the two heaviest jobs. If you only have a block-list, you have performed security theatre.

A quarterly line in the governance review — unofficial tools still in use — keeps the subject from becoming a one-week campaign.

This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation, academic-regulation or engineering advice. Confirm against the current Gazette, DPDP text and Rules, CERT-In direction, India AI Governance Guidelines, UGC/AICTE/NAAC notices, NEP documents, GFR, departmental manual and your counsel before you file it. Guidelines are not statute. Circulars move.

Questions this usually raises

What is shadow AI in a government office?
Unofficial public chatbots or plugins processing official files, drafts or citizen attachments outside a system the department controls. It is a habit and a vacuum, not a brand name.
Is using a public chatbot at work automatically illegal?
Using one for personal learning is not the point. Sending official unpublished files or personal data to a host you did not appoint as a processor is the point. Service rules and, as DPDP duties commence, fiduciary obligations care about that disclosure.
Does CERT-In require us to log unofficial chatbot use?
CERT-In's 28 April 2022 directions apply to logs of specified ICT systems you operate, retained 180 days in India. Unofficial tools on personal phones are usually invisible to you. That invisibility is the problem, not a reporting form you missed.
Will an official on-prem agent kill shadow AI?
Only if it is faster for the real job and staff are told unofficial paste of live files is forbidden. An official agent that cannot see the circular corpus will lose to the phone.
Should we monitor staff phones?
That is a legal and service-rule question for your counsel, not a default IT project. Start with amnesty, an AUP, official devices for high-risk sections, and a better official path. Covert phone monitoring is how you lose the room.

Sources