In Brief

The governance problem is no longer whether employees use these tools. It is whether the organization can see that use, determine what data is involved, and respond before an incident forces the issue.

For CDOs, CISOs and CIOs accountable for enterprise AI governance
The four control stages
01Discover what is actually in use.
02Classify by data and use case.
03Provide a sanctioned route.
04Monitor and renew the inventory.
Proof in this piece
Vendor reputation and tool popularity are poor substitutes for risk classification. The same general-purpose assistant can be used to rewrite public marketing copy, summarize patient notes, analyze customer data, or draft a securities filing. The product may be identical; the consequence is not.
Evidence base
IBM · Gartner · Cisco · McKinsey · KPMG and University of Melbourne · National Cybersecurity Alliance and CybSafe · NIST · ISO/IEC · California Privacy Protection Agency · Government Accountability Office · European Commission

Shadow AI refers to employees using artificial intelligence tools within an organization without formal authorization, visibility, or supervision from IT, security, or data governance teams. The governance problem is no longer whether employees use these tools. It is whether the organization can see that use, determine what data is involved, and respond before an incident forces the issue.

IBM’s 2026 Cost of a Data Breach Report put the global average breach cost at a record $4.99 million and found that one in four malicious breaches were AI-enabled, a 56% increase year over year. In the same study, the share of security incidents involving shadow AI more than doubled to 43%, while more than two-thirds of organizations lacked governance processes capable of limiting it.

Leaders see a different picture. In the 2026 AI and Data Leadership Executive Benchmark Survey, 88.7% of data leaders said safeguards and guardrails for responsible AI use were in place, up from 62.9% two years earlier.

Together the figures expose the executive problem, even though they measure different populations and conditions: a policy or governance body can exist without operational control. For the CDO, CISO, or CIO, the work is to close that gap with an inventory, risk classification, approved route, and monitoring cycle.

Shadow AI Is Unauthorized Processing, Not Just Shadow IT

Shadow IT is unauthorized software. An employee adopts a file-sharing service, project tracker, or note-taking application that the organization did not review. Traditional controls therefore concentrate on the vendor, account, credential, and location of the data.
Shadow AI adds unauthorized processing. If an employee submits a contract to a public chatbot, the governance questions extend beyond where the document went. The organization needs to know what the model did with the content, what the provider’s terms and configuration permit, whether the input or output was retained, and what evidence remains for an audit or investigation.
That difference changes the response:
The traditional shadow IT response is incomplete. Blocking a domain may stop access to one service. It does not classify the processing already taking place across approved platforms.

Why a Blocklist Cannot Govern Shadow AI

Prohibition is a common first response: publish a policy, block popular generative AI services, and add a warning to security training. The evidence shows why that is insufficient.

Gartner reported in November 2025 that 69% of organizations suspected or had evidence that employees were using prohibited public generative AI, based on a survey of 302 cybersecurity leaders. Gartner also predicts that by 2030, more than 40% of organizations will experience a security or compliance incident caused by unauthorized AI use.

The KPMG and University of Melbourne global study, covering 48,340 respondents across 47 countries, found that 57% of employees hide their use of AI and present AI-generated work as their own. Almost half admitted using AI in ways that contravene company policy, including uploading sensitive company information into free public tools. Only 40% said their workplace had a generative AI policy.

Policy friction is only part of the explanation. AI capabilities now arrive inside software the organization already bought and approved. Document editors summarize, CRM systems draft outreach, support platforms suggest responses, and meeting tools transcribe discussions. These features may appear through a product update rather than a new purchase, so they never trigger the review designed for a new vendor.

Employees also adopt standalone AI tools one at a time, often to meet a deadline or fill a gap in the approved toolset. That activity may never create a departmental procurement record. A blocklist can restrict known services, but it cannot discover every embedded feature, individual account, or new model endpoint. Shadow AI therefore has to be managed as a continuing configuration, data, and accountability problem.

The Policy and Control Gap

The available measures point to a consistent distinction between governance artifacts and governance operations.

SignalFigureSource

Cisco’s 2026 Data and Privacy Benchmark Study, covering 5,200 professionals across 12 markets, makes the distinction especially clear: the governance body has become standard equipment well ahead of the maturity required to operate it.

A committee and policy are useful only if they change decisions. The operational test is whether the organization can identify its AI systems, classify the data and use cases attached to them, detect a new tool, assign an owner, and record what was approved or rejected.

EWSolutions consultants have conducted more than 100 data governance assessments since 1997. EWSolutions also reports more than 155 data management and governance programs since 1997, including work for the US Department of Defense, FDA-regulated healthcare organizations, and Fortune 500 enterprises. The control gap should be tested through ownership and measurement, not the existence of a policy alone.

Blue Network Cables Patch Panel Rows 1200x600 1

A Four-Stage Shadow AI Control Sequence

Effective shadow AI governance is a repeating operational cycle. The sequence below applies the stewardship and accountability structure of the G3℠ Data Governance and Stewardship Methodology, used by EWSolutions since 2006, to unauthorized AI tools.

The order matters. An organization cannot write an enforceable use policy for systems and data flows it has not identified.

Use three inputs to build the initial shadow AI register:

  • Network and endpoint telemetry. Review egress to known AI domains, browser extensions, and API calls to public AI tools and model providers. This captures visible use of standalone assistants and external models.
  • Procurement and SaaS records. Review every contracted platform against its current feature set, not only the capabilities approved at purchase. This is where embedded AI features are most likely to surface.
  • Structured self-report. Ask business units to disclose use cases through a non-punitive process. When 57% of employees report concealing AI use, self-report can reveal context that technical telemetry and procurement records miss.

Reconcile the findings into one register. Treat it as a dated baseline, not a final inventory. Each entry should identify the tool or feature, business use, data involved, user group, system owner, and discovery source.

Vendor reputation and tool popularity are poor substitutes for risk classification. The same general-purpose assistant can be used to rewrite public marketing copy, summarize patient notes, analyze customer data, or draft a securities filing. The product may be identical; the consequence is not.

Classify each use case with four questions:

  • What data class enters the AI tool: public, internal, confidential, or regulated sensitive data?
  • Under the applicable product terms and configuration, is the input or output retained or used to improve the service?
  • Is the AI-generated output used to make or materially inform a decision about a person?
  • Which legal, regulatory, security, privacy, or contractual requirements apply to this entity, dataset, jurisdiction, and use?

The jurisdiction question already affects US organizations. The California Privacy Protection Agency finalized regulations in September 2025 covering automated decision-making technology, risk assessments, and cybersecurity audits. Risk assessment obligations began January 1, 2026, and ADMT compliance is required from January 1, 2027. An organization cannot evaluate whether a use case falls within those requirements if the use case is absent from its inventory.

A policy is easier to follow when the approved route can meet the business need. EWSolutions recommends pairing restrictions with a practical alternative: an enterprise-grade tool with appropriate contractual and configuration protections, a response time measured in days rather than quarters, and coverage for the use cases found during discovery.

Publish which tools are approved for each data class in language employees can apply without interpreting a legal or security standard. Give procurement, legal, security, privacy, and data governance one review path so the requester receives a single decision.

Increased requests signal disclosure rather than rising risk: once the approved route becomes credible, more employees ask for access. Track those requests alongside discoveries and incidents. The useful measure is whether work is moving into a classified, reviewable environment.

AI inventories decay as vendors add features, teams change workflows, and new tools enter the market. EWSolutions recommends a scheduled cycle rather than an annual policy review:

  • Quarterly rediscovery across telemetry, procurement records, and structured self-report
  • Continuous monitoring of model-provider egress, access controls, and new AI features in contracted platforms
  • A named steward for each business unit who owns that unit’s register entries
  • Metrics reported to the governance body, including tools discovered, time from discovery to classification, requests approved, and incidents attributable to unsanctioned tools

Quarterly review is an operating recommendation. The cadence should tighten when the estate or risk profile changes quickly. What matters is that the organization measures how long new AI use remains unknown and how quickly it reaches a documented decision.

What Standards and Regulators Already Expect

Shadow AI is not only a security preference. Existing frameworks and regulations already depend on inventory, lineage, risk assessment, and accountable use.

NIST published the Generative AI Profile as a companion to the AI Risk Management Framework. It calls for organizations to “establish known assumptions and practices for determining data origin and content lineage” and to document the origin and history of training data. An organization cannot apply those practices to an AI system it has not identified. NIST is also developing control overlays for securing AI systems under SP 800-53, including an overlay for organizations adopting and using generative AI assistants.

ISO/IEC 42001, published in December 2023, specifies requirements for an artificial intelligence management system. For organizations using the standard, unmanaged AI use creates an immediate scoping and evidence problem: the management system cannot assess a use case that remains outside its inventory.

The Government Accountability Office found that generative AI use cases at eleven selected federal agencies rose from 32 to 282 between 2023 and 2024. Officials at ten of twelve agencies said existing policy could obstruct adoption.

The GAO findings show that AI use can expand rapidly even where inventories are mandatory, while policy creates friction for legitimate adoption. For private organizations without a current inventory, that is a reason to test actual use rather than infer it from approved procurement.

Light Shaft Dark Concrete Steps 1200x600 1

Prioritize Shadow AI Risk by Business Consequence

Long, undifferentiated risk lists are difficult to fund and harder to operate. The following categories help executives decide where discovery and remediation should begin.

The most direct risk is sensitive data leaving an approved processing environment one prompt at a time. The National Cybersecurity Alliance and CybSafe found in their 2025-2026 study of more than 6,500 respondents that 43% admitted sharing sensitive workplace information with AI tools without employer knowledge. Among the information shared, internal company documents accounted for 50%, customer data for 44%, and financial data for 42%. In the same study, 58% had received no training on the related security and privacy risks.

Without a register, the organization cannot establish the provider terms and configuration that governed the exchange. The first control is therefore the ability to identify the tool and reconstruct the data flow.

Unauthorized AI use can create compliance or contractual exposure when regulated or confidential data enters an unapproved service. Applicability depends on the data, jurisdiction, and purpose. That is precisely why classification must happen at the use-case level. A small consumer tool does not create a small compliance issue if the processing falls within a regulated activity.

Proprietary methods, unreleased product details, source code, and negotiating positions can lose practical protection when employees submit them to tools whose terms and access controls the organization has not reviewed. The immediate governance question is whether the organization can show which information was disclosed, under what terms, and what protective measures applied. Any legal conclusion about confidentiality or trade-secret status requires counsel and case-specific facts.

The KPMG and University of Melbourne research found that 66% of employees rely on AI output without checking its accuracy, and 56% report having made mistakes at work because of AI. Shadow AI adds an evidence problem: the organization may have no approved accuracy baseline, review workflow, or record of which output came from which model version.

The control should follow the consequence of the decision. A drafting aid for low-risk internal text does not need the same validation as a tool informing employment, credit, healthcare, legal, or financial decisions.

Unauthorized AI tools can introduce credentials, browser extensions, external APIs, and data flows outside the monitored estate. IBM’s 2026 Cost of a Data Breach Report found that among organizations that experienced an AI-related breach, 92% lacked proper access controls for AI systems. Access decisions must be attached to the inventory and monitored after approval.

Govern Shadow AI Without Stalling AI Adoption

Control and adoption are not opposing goals. Poorly designed governance slows legitimate use while leaving concealed use untouched. Effective governance shortens the route from a business need to a documented decision.

McKinsey’s State of AI research, covering 1,993 respondents across 105 nations, found that 88% of organizations used AI in at least one business function, up from 78% the year before. The executive question is therefore not whether adoption should occur. It is whether that adoption happens inside a structure that can be classified, approved, monitored, and audited.

Gartner reported in April 2026 that organizations with successful AI initiatives invest up to four times more in data and analytics foundations, while those at the highest maturity report up to 65% greater business outcomes. The finding supports the broader management decision to fund the data and analytics foundations that responsible AI use requires.

Shadow AI and the EU AI Act

Does the EU AI Act apply to shadow AI?

The EU AI Act applies to actors that place an AI system on the EU market, put one into service, or use one in the EU. Internal approval status does not replace the need to assess whether a system and use fall within that scope. US enterprises should evaluate the Act based on their actual EU activities and role rather than assume that an unsanctioned tool is outside the inventory.

What Effective Shadow AI Governance Can Prove

The goal is not a permanent claim that no unsanctioned tool exists. A more useful executive measure is how quickly the organization detects new use and whether it can reconstruct the decision that followed.
Executives should put four questions to their own organization and require an answer on demand:
These questions separate documented intent from operational control. Technology helps answer them, but it cannot supply ownership, data classification, or a decision record by itself. Those are data governance responsibilities. That turns shadow AI from an unknown estate into a managed risk.

Request an AI Governance Consultation to assess your current AI estate, establish a defensible inventory, and build the stewardship structure that makes it hold.