• Insights · AI governance
Shadow AI Is Already Your Operating Model
What happens when employees adopt tools faster than governance can track them
By Suchetana Bauri · 16 September 2026 · AI Strategy & Governance
The challenge
You cannot assign accountability for an AI system that nobody has admitted exists.
The opportunity
Treat shadow AI as demand data. Find the work, bring it into view and make the governed route faster than the workaround.

The last article asked: who actually owns AI risk in your organisation? The answer was not a committee. Accountability follows the decisions: who chooses the tool, approves the data, trusts the output, connects it to a system and accepts what could still go wrong.
Here is the obvious next problem. What if those decisions never reach the committee?
The accountability gap nobody can map
An employee opens a personal ChatGPT account to rewrite a proposal. A recruiter asks a browser extension to summarise CVs. A manager connects an AI notetaker to every meeting. A finance analyst uploads a spreadsheet because the approved assistant cannot read it. A developer creates an agent that can pull files, update tickets and send messages, then shares the workflow with the team.
The work gets done. The risk register stays clean.
This is shadow AI: AI tools, features, accounts and agents used for work outside the organisation’s approved systems and processes. The UK’s National Cyber Security Centre put the issue plainly in new guidance published on 7 September: policies have not kept pace with adoption, and where they fail to meet business needs, staff will continue to adopt AI before their employers can assess it or offer a usable alternative.[^1]
Four days later, this site published an accountability map. Two days after that, OneTrust released a 2026 governance survey that makes the sequel unavoidable. Forty-six per cent of the 1,200 senior leaders surveyed said they had good visibility into approved AI but limited visibility into employee-led or unsanctioned use. A third said staff had used unapproved AI because approved options or processes were not available quickly enough. Nearly one in three found use cases only after they were already live.[^2]
That is not an edge case. It is an operating model nobody designed.
The work gets done. The risk register stays clean.
Descriptive alt text: a pull-quote system used at natural conceptual shifts to highlight key messages without competing with the five substantial infographics.
01 –
Shadow AI used to mean somebody pasted text into a chatbot. That is still happening, at scale, but it is no longer the whole story.
The adoption story has changed
Today, AI arrives inside ordinary software. A transcription feature appears in a meeting platform. A writing assistant turns up in the browser. A customer tool adds automated recommendations. A spreadsheet offers analysis. A no-code service lets anyone assemble an agent from a model, company files and a set of actions. Sometimes the employee chooses a new product. Sometimes a familiar product quietly becomes an AI product around them.
This makes the old question – “Which AI tools have staff bought?” – inadequate. Shadow AI now has at least four forms:
- An unapproved tool: a consumer chatbot, image generator, coding assistant or notetaker used for work.
- An unapproved account: an accepted product accessed through a personal login, outside company retention, security and contractual controls.
- An approved tool used out of scope: the right system, but with the wrong data, purpose, integration or level of reliance.
- A shadow agent: an AI workflow that can retrieve information or act across systems without a recorded owner, reviewed permissions or an agreed way to stop it.
From chatbots to embedded AI
The final category changes the stakes. A chatbot returns an answer. An agent can use credentials, contact another service, alter a record or trigger the next step. The private shortcut becomes a small operational actor.
When a shortcut becomes an actor
The Cloud Security Alliance reported in April that 82% of surveyed organisations had discovered shadow agents during the previous year, despite 68% expressing high confidence in their visibility. Sixty-five per cent reported at least one agent-related incident; only 21% had a formal process for retiring agents. Those figures come from a commissioned industry survey, not a census of every workplace, but the contradiction matters more than the precise percentage: confidence is high, discovery is late and lifecycle control is weak.[^3]
The dashboard says “AI adoption”. The reality is a collection of tools, accounts, prompts, permissions and automations whose boundaries do not match the organisation chart.
02 –
Most shadow AI begins with an ordinary act of competence. Someone finds a faster way to do a task.
This is why the moral language around it is so unhelpful. Employees “circumvent” policy. They “evade” controls. They become the “weakest link”. All three descriptions may be true in a particular case. As a general explanation, they are evasions of management responsibility.
A ban is not a control
A policy is competing with a product that opens in seconds, speaks plain English and often solves the immediate problem. If the official alternative is absent, slow, confusing or less useful, the policy will lose. The employee does not stop needing the result; the activity simply becomes less visible.
Why the workaround wins
Microsoft’s UK research found that 71% of employees surveyed had used unapproved consumer AI at work and 51% did so every week. Forty-one per cent chose tools they already knew from their personal lives; 28% said their employer offered no approved option. In June, PagerDuty reported that two-thirds of office professionals at large organisations had used AI at work despite believing it was not permitted. Eighty-one per cent thought leaders followed different rules from everyone else.[^4][^5]
That last number deserves attention. Shadow AI is not only a security gap. It can become a legitimacy gap.
The adoption gap is measurable
If a senior executive uses a personal AI assistant to prepare a board paper while telling staff that public tools are prohibited, the lesson is not “take the policy seriously”. The lesson is that policy is theatre. If one team receives an enterprise assistant while another is told to wait, the organisation has created two classes of AI access. If managers reward speed but refuse to discuss how the result was produced, they are buying plausible deniability with employee risk.
The useful test is brutally simple: would a reasonable employee regard the approved route as a serious way to complete the work?
If not, the organisation does not have an adoption problem. It has a service-design problem.
Would a reasonable employee regard the approved route as a serious way to complete the work?
03 –
The risk is the missing context
The phrase “shadow AI” can make the tool sound inherently dangerous. That is too crude. The same model might be low-risk in one use and indefensible in another.
Ask it to suggest headings from public material and very little may be at stake. Give it employee complaints, unreleased financial figures or a client contract and the data risk changes. Use its output as rough inspiration and a human remains firmly in the loop. Use it to rank candidates, flag fraud or decide which customer receives attention and the consequence changes. Connect it to email, cloud storage or a payment system and the possible blast radius changes again.
The same tool can carry different risks
What governance lacks in a shadow use is not merely approval. It lacks context:
- What job is the AI doing?
- Which data enters it, and where does that data go?
- What can the system read, write, send or change?
- Who checks the output?
- Who is affected if it is wrong?
- Who can stop it?
Without those answers, legal cannot assess the purpose, security cannot see the access, the data owner cannot approve the information flow, and the business owner cannot consciously accept the residual risk. The accountability chain described in the previous article breaks before its first link.
Six questions reveal the real exposure
The data exposure is already substantial. PagerDuty found that 88% of the office professionals it surveyed had shared some work-related information with public AI tools. Forty-three per cent had shared correspondence, 40% meeting notes or summaries, 34% customer information and 31% financial information or confidential documents and strategies. Verizon’s 2026 Data Breach Investigations Report found regular workplace AI use had risen from 15% to 45% in a year; shadow AI had become the third most common non-malicious data-leakage activity in its dataset.[^5][^6]
These findings do not prove that every prompt caused harm. They prove that AI has become an information route. Organisations that still treat it as a novelty application are looking in the wrong place.
AI has become an information route
The risk is also more than leakage. An unreviewed AI summary can remove the qualification that mattered. An invented citation can enter a client document. A tool can reproduce bias in language that sounds calm and objective. An employee can begin to rely on a result without being able to explain how it was reached. An agent can keep the permissions it needed for a temporary task long after the task has ended.
The dangerous property is not intelligence. It is invisible dependency.
04 –
The first response to shadow AI is often technical detection: inspect network traffic, block domains, audit browser extensions, review app permissions and watch for sensitive information leaving the organisation. Those controls have a place. They do not produce the full picture.
Discovery without punishment
People also use personal devices. They move between accounts. AI features are embedded in approved software. A team may create a workflow inside a platform that IT already trusts. Technical discovery can tell you that a service was reached; it may not tell you why it was used, whether the output shaped a decision or what would break if access disappeared tomorrow.
So begin with an amnesty, not an ambush.
For 30 days, ask staff to declare tools and uses without disciplinary action for good-faith disclosure. Be explicit about the exceptions: deliberate theft, fraud or conduct that would already breach serious rules does not acquire immunity because AI was involved. The aim is not to excuse harm. It is to reveal the system before deciding how to govern it.
Ask only what is useful:
- Which tool, feature, account or agent are you using?
- What task does it help you complete?
- What type of information goes in?
- Which systems can it access or change?
- Who uses or relies on the output?
- Who would notice if it failed?
Combine the answers with procurement records, expense claims, sign-in data, third-party app consents, browser-extension inventories, network discovery and data-loss-prevention signals. Do not publish a league table of offending departments. Publish what the organisation learnt: the common unmet needs, repeated tools, risky data flows and work that depends on unofficial automation.
Build one live view of AI use
The NCSC’s current shadow IT guidance makes the cultural point directly. Staff are less likely to report unknown services if they fear reprimand; organisations should anticipate user needs, offer a quick request process and bring useful unsanctioned services under control rather than relying on unnecessary lockdowns.[^7]
Visibility built through fear is temporary. People become better at hiding. Visibility built through usefulness can endure.
So begin with an amnesty, not an ambush.
05 –
An “approved tools” list is necessary and insufficient. Approval is not a halo.
Govern the action, not the logo
A company may approve an enterprise chatbot for general drafting. That does not automatically approve health data, legal advice, recruitment scoring, unrestricted plugins or an agent that can send external email. Conversely, an unfamiliar tool used with synthetic data in a sandbox may present less risk than an approved assistant given broad access to production systems.
- Variable – Lower-risk end – Higher-risk end
- Data – Public, synthetic, non-sensitive – Personal, confidential, regulated, security-sensitive
- Consequence – Ideas and reversible drafts – Decisions affecting people, money, rights, safety or public claims
- Agency – Generates an answer for review – Reads from systems, takes actions or triggers other actions
A use with low-risk data, low consequence and no agency can usually move through a fast lane. Increase any of the three and the controls should rise with it. Increase all three and the system needs formal assessment, named owners, monitored operation and an immediate way to halt it.
This is where the previous accountability map becomes operational. For every significant AI use – discovered or proposed – record five decisions:
- Business owner: decides whether the use is worth doing and is answerable for the outcome.
- Data owner: decides which information the system may use.
- Technical owner: controls identity, permissions, integrations, logging and change.
- Human decision owner: decides how much reliance to place on the output and when a person must intervene.
- Risk acceptor: consciously accepts what remains, with authority proportionate to the possible harm.
A shadow tool without these names is not merely unapproved. It is unowned.
Agents need an additional rule: give every agent its own identity, its own minimum permissions and its own expiry date. Do not let it borrow a person’s permanent credentials. Log what it does. Define the actions that require human approval. Test the shutdown before deployment, not during an incident.
The NCSC’s August guidance on agentic AI recommends sandboxing, restrictive network access, attributable activity, near-real-time monitoring, named responsibility and an emergency ability to “pull the plug”. That is the new baseline. The employee with a clever workflow is not deploying a colleague. They are creating a software actor, and it should be governed like one.[^8]
A shadow tool without these names is not merely unapproved. It is unowned.
06 –
Make the safe route win
The goal is not to eliminate all shadow AI. The NCSC does not think that is realistic, and neither should anybody who has watched consumer software spread through a workplace. The goal is to reduce the incentive to hide and the consequence when somebody experiments.[^1]
That requires a better internal offer.
Give people a capable default. Provide an approved tool for common work and explain, in examples, which data it may handle. “Use AI responsibly” is not guidance. “You may use the company assistant to restructure an internal presentation, but not to analyse individual employee cases” is guidance.
Set an approval service level. Low-risk requests should receive an answer in days. Publish the criteria and the expected time. If governance cannot say yes or no before the deadline that created the need, it is not governing the decision; it is documenting why somebody bypassed it.
Create a sandbox. Let teams test unfamiliar tools with synthetic or non-sensitive data, restricted connections and no production actions. Safe experimentation is cheaper than covert production use.
Train by role and moment. The recruiter, software developer, communications lead and finance analyst do not need the same AI course. They need scenarios drawn from their own decisions. The EU AI Act’s AI literacy requirement remains in application in 2026 and expects measures to reflect people’s knowledge, experience and context of use, not a universal test score.[^9]
Make disclosure rewarding. When a team reveals a useful shadow workflow, help assess and formalise it. Credit the people who found the improvement. If every disclosure ends with confiscation, disclosure will end.
Enforce the red lines. A permissive culture is not a careless one. Block tools that cannot meet basic data and security conditions. Prohibit sensitive information in consumer accounts. Require formal review for consequential decisions. Remove persistent credentials from unowned agents. Apply consequences to deliberate breaches consistently, including at senior level.
The sequence matters: discover, provide, clarify, then enforce. Reverse it and governance becomes a contest of evasion.
The sequence matters: discover, provide, clarify, then enforce.
07 –
A 30-day shadow AI reset
Leaders do not need another six-month policy project. They need a short operational reset.
Days 1-3: set the interim rule. Name the approved tools and accounts. State what must never enter a public service. Pause unreviewed agents that can take consequential or irreversible actions. Give staff one place to ask questions.
Days 4-10: open the declaration window. Invite teams to report tools, embedded features, personal accounts, integrations and agents. Ask what problem each solves and what work now depends on it. Promise non-punitive treatment for good-faith disclosure and honour it.
Days 11-20: build the live register. Join employee reports with technical and commercial discovery. For each use, record purpose, data, consequence, agency, systems accessed, owner and status. Separate “block now” from “assess quickly”; panic is not a classification method.
Days 21-30: close the adoption gap. Approve low-risk uses, replace unsafe tools with workable alternatives and assign owners to anything that remains. Publish the fast-track route, the red lines and the first set of role-specific examples. Give every retained agent an identity, permission boundary, monitor and shutdown method.
Then track measures that reveal reality:
- Time taken to decide on a low- or medium-risk request.
- Percentage of known AI uses with a named business owner and data owner.
- Number of agents with unique identities, minimum permissions and expiry dates.
- Repeat demand for unavailable capabilities.
- Staff confidence about what they may do.
- Good-faith disclosures and near misses.
- High-impact outputs released without recorded human review.
Expect reported shadow AI to rise at first. That can be a sign of improving governance, not worsening behaviour. A clean register produced by silence is less valuable than a messy one produced by trust.
A clean register produced by silence is less valuable than a messy one produced by trust.
The next accountability question
The previous article argued that a committee cannot own AI risk because ownership sits with the people making risk-bearing decisions. Shadow AI shows what happens when the organisation makes those decisions difficult to surface.
The employee chooses the tool because procurement is slow. The manager trusts the result because the deadline is close. The team connects the agent because nobody has provided a sandbox. The executive praises the efficiency but asks no questions about the route. Each choice has an owner, even when the governance process never records one.
This is why shadow AI should not be framed as a side issue for cyber security. It is the stress test of the entire AI operating model. It tests whether policy reflects work, whether approval can keep pace with demand, whether leaders follow their own rules, whether people can disclose mistakes and whether accountability exists outside the meeting where it is discussed.
OneTrust’s newest figures capture the contradiction. Eighty-seven per cent of surveyed organisations encourage agent use, but only 47% say that use is backed by clear governance, oversight and controls. Just 5% report clear coordination and accountability across the AI lifecycle.[^2]
Organisations are not waiting to become ready. They are adopting first and trying to become ready around the adoption.
The answer is not to slow everybody to the speed of governance. It is to rebuild governance at the speed of work.
Your employees have already shown you where AI is useful. The question is whether you can bring that use into the light before a shortcut becomes infrastructure – and before infrastructure without an owner becomes the next incident.
The answer is not to slow everybody to the speed of governance. It is to rebuild governance at the speed of work.
References
- Advancing accountability in AI (EN)
- Investigating accountability for Artificial Intelligence through … – With the growing prevalence of AI-based systems and the development of specific regulations and stan…
- Artificial Intelligence
- NTIA Artificial Intelligence Accountability Policy Report …
- ITI’s AI Accountability Framework
- Locating fault for AI harms: a systems theory of foreseeability, reasonable care and causal responsibility in the AI value chain – This paper presents an original perspective on fault and responsibility for harms caused by artifici…
- Artificial Intelligence Accountability Policy – Earned Trust through AI System AssuranceNTIA.govArtificial IntelligenceAI Accountability Policy Repo…
- Free-AI
- [PDF] Part 2 – Operationalizing Principles for Responsible AI – NITI Aayog
AI governance · operating model
Bring shadow AI into the light.
I help organisations turn hidden AI demand into a practical, accountable route for safe adoption.
