Unapproved Apps in the Classroom: The Rising Threat of Shadow IT

As unapproved AI tools flood classrooms, schools face a growing cybersecurity blind spot. Here’s why “shadow IT” is one of the most dangerous — and overlooked — threats to student data today.

GUEST COLUMN | by Russ Munisteri

IURII MOTOV

In December 2024, popular assignment grading platform PowerSchool was hacked. It was the largest breach of American children’s personal information to date, leaking sensitive data of over 60 million students and 10 million teachers.

Keep in mind that PowerSchool is a large, reputable company, and it still skipped basic security protocols leading to this disaster. The unfortunate reality? Schools frequently use third-party platforms, and most of them aren’t nearly as safe as PowerSchool. For example, more than a quarter of teens in the U.S. use ChatGPT for their schoolwork — and schools have no access to what kind of sensitive data the students might be sharing. 

‘Here’s what shadow IT is, why it’s particularly dangerous for schools, and what you can do about it.’

What we’re seeing with ChatGPT and other AI platforms is contributing to the rise of shadow IT. Here’s what shadow IT is, why it’s particularly dangerous for schools, and what you can do about it. 

What is shadow IT? 

Shadow IT happens when people use apps, websites, or software that are not officially approved by the school’s IT team. Sometimes teachers download free grading tools, or students use AI chatbots or homework helpers. 

These tools may seem harmless and even helpful, but because they bypass official approval, IT teams have no visibility into what they do, what data they collect, or how secure they are. In schools, where student information is especially sensitive, shadow IT creates serious risks.

For example, AI agents are particularly vulnerable to cyberattacks. Any information students or teachers enter could be used to hack into emails, share personal information, and impersonate them in phishing attacks. 

Why is shadow IT a major issue for schools?

Cyberattacks were already a major problem for schools. The education and nonprofit sectors together face a heightened cyber risk in 2024 compared to two years ago, according to Moody’s Ratings. In fact, 82% of reporting K-12 organizations experienced cyber threat impacts.

Education systems are often easy targets. They’re typically underfunded, and their cybersecurity protocols are usually behind. Student data can be valuable, too. Student loan information, grades, and birthdays can all sell for a high price on the dark web. With shadow IT on the rise, the chances of data breaches are also increasing. 

In today’s classrooms, free AI chatbots, writing assistants, and grading apps are only a click away. However, when tools are used without approval, there is no way for IT teams to monitor what data leaves the system or how it is stored. This lack of visibility increases the likelihood of accidental privacy violations, which may put schools in violation of laws like FERPA in the U.S. 

On top of that, many shadow AI tools have weak security features, leaving the school’s network more vulnerable to hackers or scams. Finally, the biggest challenge is that IT teams cannot manage or fix risks they don’t know exist. If these tools remain invisible, schools cannot protect against potential breaches or misuse, making shadow IT a serious and ongoing issue.

How to protect school assets from shadow AI

Schools can’t block every new AI tool that appears, but they can build guardrails that make safe use possible.

Set clear, simple rules. Publish easy-to-understand guidelines, written in student-friendly language, highlighting which AI tools are approved and which are not.

Educate teachers and students. Offer short lessons or workshops on the risks of using unapproved tools and the basics of keeping data safe.

Use monitoring technology. Equip IT teams with tools that can detect unapproved apps running on school devices or networks.

Approve with care. Create a checklist to review AI apps for security, privacy, and educational value before allowing them in the classroom.

Tips for IT teams on how to keep schools safe

Fighting shadow IT works best when schools treat it as a shared effort, not just an IT problem. The first step is discovery, where IT teams identify which AI tools are already being used without permission. 

From there, collaboration is key. Teachers, principals, and even parents need to understand why controls matter and how they help protect students and staff. Clear explanations and relatable stories can make the risks and benefits of AI more tangible for non-technical audiences. 

Finally, because AI evolves so quickly, communication must be ongoing. Regular reminders, updates, and refreshers ensure that everyone stays informed and that policies remain relevant.

Ways to use AI safely in schools 

AI doesn’t have to be the enemy. With the right approach, it can support teachers and empower students.

Recommend safe tools. Provide a vetted list of AI apps that help teachers save time with grading or lesson prep.

Teach AI literacy. Add lessons that show students how to use AI responsibly while understanding privacy and security.

Use AI for insights. Leverage approved AI tools to analyze anonymous school data and improve instruction without compromising privacy.

Monitor responsibly. Combine usage monitoring with strong policies so schools can benefit from AI innovation while staying safe.

Use AI without risking shadow IT

Shadow IT in schools is not just an IT inconvenience — it is a real threat to student privacy, data security, and trust. As AI tools continue to grow in popularity, it’s crucial for schools to create clear guidelines, educate staff and students, and put monitoring systems in place. 

By treating shadow IT as a shared responsibility across the entire school community, educators can reduce risks while embracing the opportunities that AI offers. With the right balance of caution and innovation, schools can protect their data, comply with privacy laws, and help students and teachers use AI safely and responsibly.

Russ Munisteri, CISSP, is a seasoned IT professional with over 25 years of experience in systems administration, cybersecurity and technical education. As program chair and lead instructor at MyComputerCareer, he leverages his extensive industry background and teaching expertise to prepare learners for success in IT and cybersecurity. Munisteri holds a master’s in education from Queens College. Connect with Russ on LinkedIn.

0 Comments

    Leave a Comment

    %d bloggers like this: