In Brief
The governance problem is no longer whether employees use these tools. It is whether the organization can see that use, determine what data is involved, and respond before an incident forces the issue.
For
CDOs, CISOs and CIOs accountable for enterprise AI governance
The four control stages
01 Discover what is actually in use.
02 Classify by data and use case.
03 Provide a sanctioned route.
04 Monitor and renew the inventory.
Proof in this piece
Vendor reputation and tool popularity are poor substitutes for risk classification. The same general-purpose assistant can be used to rewrite public marketing copy, summarize patient notes, analyze customer data, or draft a securities filing. The product may be identical; the consequence is not.
Evidence base
IBM · Gartner · Cisco · McKinsey · KPMG and University of Melbourne · National Cybersecurity Alliance and CybSafe · NIST · ISO/IEC · California Privacy Protection Agency · Government Accountability Office · European Commission
Shadow AI refers to employees using artificial intelligence tools within an organization without formal authorization, visibility, or supervision from IT, security, or data governance teams. The governance problem is no longer whether employees use these tools. It is whether the organization can see that use, determine what data is involved, and respond before an incident forces the issue.
IBM’s 2026 Cost of a Data Breach Report put the global average breach cost at a record $4.99 million and found that one in four malicious breaches were AI-enabled, a 56% increase year over year. In the same study, the share of security incidents involving shadow AI more than doubled to 43% , while more than two-thirds of organizations lacked governance processes capable of limiting it.
Leaders see a different picture. In the 2026 AI and Data Leadership Executive Benchmark Survey , 88.7% of data leaders said safeguards and guardrails for responsible AI use were in place, up from 62.9% two years earlier.
Together the figures expose the executive problem, even though they measure different populations and conditions: a policy or governance body can exist without operational control. For the CDO, CISO, or CIO, the work is to close that gap with an inventory, risk classification, approved route, and monitoring cycle.
Shadow AI Is Unauthorized Processing, Not Just Shadow IT
Shadow IT is unauthorized software. An employee adopts a file-sharing service, project tracker, or note-taking application that the organization did not review. Traditional controls therefore concentrate on the vendor, account, credential, and location of the data.
Shadow AI adds unauthorized processing. If an employee submits a contract to a public chatbot, the governance questions extend beyond where the document went. The organization needs to know what the model did with the content, what the provider’s terms and configuration permit, whether the input or output was retained, and what evidence remains for an audit or investigation.
That difference changes the response:
The traditional shadow IT response is incomplete. Blocking a domain may stop access to one service. It does not classify the processing already taking place across approved platforms.
Why a Blocklist Cannot Govern Shadow AI
Prohibition is a common first response: publish a policy, block popular generative AI services, and add a warning to security training. The evidence shows why that is insufficient.
Gartner reported in November 2025 that 69% of organizations suspected or had evidence that employees were using prohibited public generative AI, based on a survey of 302 cybersecurity leaders. Gartner also predicts that by 2030, more than 40% of organizations will experience a security or compliance incident caused by unauthorized AI use.
The KPMG and University of Melbourne global study , covering 48,340 respondents across 47 countries, found that 57% of employees hide their use of AI and present AI-generated work as their own. Almost half admitted using AI in ways that contravene company policy, including uploading sensitive company information into free public tools. Only 40% said their workplace had a generative AI policy.
Policy friction is only part of the explanation. AI capabilities now arrive inside software the organization already bought and approved. Document editors summarize, CRM systems draft outreach, support platforms suggest responses, and meeting tools transcribe discussions. These features may appear through a product update rather than a new purchase, so they never trigger the review designed for a new vendor.
Employees also adopt standalone AI tools one at a time, often to meet a deadline or fill a gap in the approved toolset. That activity may never create a departmental procurement record. A blocklist can restrict known services, but it cannot discover every embedded feature, individual account, or new model endpoint. Shadow AI therefore has to be managed as a continuing configuration, data, and accountability problem.
The Policy and Control Gap
The available measures point to a consistent distinction between governance artifacts and governance operations.
Cisco’s 2026 Data and Privacy Benchmark Study , covering 5,200 professionals across 12 markets, makes the distinction especially clear: the governance body has become standard equipment well ahead of the maturity required to operate it.
A committee and policy are useful only if they change decisions. The operational test is whether the organization can identify its AI systems, classify the data and use cases attached to them, detect a new tool, assign an owner, and record what was approved or rejected.
EWSolutions consultants have conducted more than 100 data governance assessments since 1997 . EWSolutions also reports more than 155 data management and governance programs since 1997, including work for the US Department of Defense, FDA-regulated healthcare organizations, and Fortune 500 enterprises . The control gap should be tested through ownership and measurement, not the existence of a policy alone.
A Four-Stage Shadow AI Control Sequence
Effective shadow AI governance is a repeating operational cycle. The sequence below applies the stewardship and accountability structure of the G3℠ Data Governance and Stewardship Methodology, used by EWSolutions since 2006 , to unauthorized AI tools.
The order matters. An organization cannot write an enforceable use policy for systems and data flows it has not identified.
01 Stage One: Discover What Is Actually in Use
Use three inputs to build the initial shadow AI register:
Network and endpoint telemetry. Review egress to known AI domains, browser extensions, and API calls to public AI tools and model providers. This captures visible use of standalone assistants and external models.
Procurement and SaaS records. Review every contracted platform against its current feature set, not only the capabilities approved at purchase. This is where embedded AI features are most likely to surface.
Structured self-report. Ask business units to disclose use cases through a non-punitive process. When 57% of employees report concealing AI use, self-report can reveal context that technical telemetry and procurement records miss.
Reconcile the findings into one register. Treat it as a dated baseline, not a final inventory. Each entry should identify the tool or feature, business use, data involved, user group, system owner, and discovery source.
02 Stage Two: Classify by Data and Use Case
Vendor reputation and tool popularity are poor substitutes for risk classification. The same general-purpose assistant can be used to rewrite public marketing copy, summarize patient notes, analyze customer data, or draft a securities filing. The product may be identical; the consequence is not.
Classify each use case with four questions:
What data class enters the AI tool: public, internal, confidential, or regulated sensitive data?
Under the applicable product terms and configuration, is the input or output retained or used to improve the service?
Is the AI-generated output used to make or materially inform a decision about a person?
Which legal, regulatory, security, privacy, or contractual requirements apply to this entity, dataset, jurisdiction, and use?
The jurisdiction question already affects US organizations. The California Privacy Protection Agency finalized regulations in September 2025 covering automated decision-making technology, risk assessments, and cybersecurity audits. Risk assessment obligations began January 1, 2026, and ADMT compliance is required from January 1, 2027. An organization cannot evaluate whether a use case falls within those requirements if the use case is absent from its inventory.
03 Stage Three: Provide a Sanctioned Route
A policy is easier to follow when the approved route can meet the business need. EWSolutions recommends pairing restrictions with a practical alternative: an enterprise-grade tool with appropriate contractual and configuration protections, a response time measured in days rather than quarters, and coverage for the use cases found during discovery.
Publish which tools are approved for each data class in language employees can apply without interpreting a legal or security standard. Give procurement, legal, security, privacy, and data governance one review path so the requester receives a single decision.
Increased requests signal disclosure rather than rising risk: once the approved route becomes credible, more employees ask for access. Track those requests alongside discoveries and incidents. The useful measure is whether work is moving into a classified, reviewable environment.
04 Stage Four: Monitor and Renew the Inventory
AI inventories decay as vendors add features, teams change workflows, and new tools enter the market. EWSolutions recommends a scheduled cycle rather than an annual policy review:
Quarterly rediscovery across telemetry, procurement records, and structured self-report
Continuous monitoring of model-provider egress, access controls, and new AI features in contracted platforms
A named steward for each business unit who owns that unit’s register entries
Metrics reported to the governance body , including tools discovered, time from discovery to classification, requests approved, and incidents attributable to unsanctioned tools
Quarterly review is an operating recommendation. The cadence should tighten when the estate or risk profile changes quickly. What matters is that the organization measures how long new AI use remains unknown and how quickly it reaches a documented decision.
What Standards and Regulators Already Expect
Shadow AI is not only a security preference. Existing frameworks and regulations already depend on inventory, lineage, risk assessment, and accountable use.
Prioritize Shadow AI Risk by Business Consequence
Long, undifferentiated risk lists are difficult to fund and harder to operate. The following categories help executives decide where discovery and remediation should begin.
Govern Shadow AI Without Stalling AI Adoption
Control and adoption are not opposing goals. Poorly designed governance slows legitimate use while leaving concealed use untouched. Effective governance shortens the route from a business need to a documented decision.
McKinsey’s State of AI research, covering 1,993 respondents across 105 nations, found that 88% of organizations used AI in at least one business function, up from 78% the year before. The executive question is therefore not whether adoption should occur. It is whether that adoption happens inside a structure that can be classified, approved, monitored, and audited.
Gartner reported in April 2026 that organizations with successful AI initiatives invest up to four times more in data and analytics foundations, while those at the highest maturity report up to 65% greater business outcomes. The finding supports the broader management decision to fund the data and analytics foundations that responsible AI use requires.
Shadow AI and the EU AI Act
Does the EU AI Act apply to shadow AI?
The EU AI Act applies to actors that place an AI system on the EU market, put one into service, or use one in the EU . Internal approval status does not replace the need to assess whether a system and use fall within that scope. US enterprises should evaluate the Act based on their actual EU activities and role rather than assume that an unsanctioned tool is outside the inventory.
What Effective Shadow AI Governance Can Prove
The goal is not a permanent claim that no unsanctioned tool exists. A more useful executive measure is how quickly the organization detects new use and whether it can reconstruct the decision that followed.
Executives should put four questions to their own organization and require an answer on demand:
These questions separate documented intent from operational control. Technology helps answer them, but it cannot supply ownership, data classification, or a decision record by itself. Those are data governance responsibilities. That turns shadow AI from an unknown estate into a managed risk.
Request an AI Governance Consultation to assess your current AI estate, establish a defensible inventory, and build the stewardship structure that makes it hold.