A security review finds forty unsanctioned AI tools in use across the business. Marketing is running copy through one model, finance is summarising contracts in another, three teams are paying for the same product on personal cards, and somebody in HR has been drafting performance feedback in a chatbot.
The meeting that follows asks one question: how do we stop this?
It is a reasonable question and it is the second one. The first is what forty tools, adopted without budget, training or permission, are telling you about the state of your organisation — because that is a readiness finding, and it is more actionable than the security one.
This is the normal condition, not an outbreak
The scale of it is well documented. Microsoft and LinkedIn’s 2024 Work Trend Index surveyed 31,000 full-time knowledge workers across 31 countries and found that 75 per cent were using AI at work, and that 78 per cent of those users were bringing their own AI tools — a practice the report labels BYOAI. It rises to 80 per cent at small and medium-sized companies, and it is not a generational quirk: 85 per cent of Gen Z, but also 73 per cent of boomers and older workers.
Set alongside that, the same survey found 60 per cent of leaders saying their company lacks a plan and vision for implementing AI.
Those two findings are the same finding. Where the organisation has not provided a route, people have built one. Shadow AI is what demand looks like when it arrives before supply.
What the research says drives it
Unsanctioned technology use is not new, and it has been studied properly. Steffi Haag and Andreas Eckhardt’s work on shadow IT in Business & Information Systems Engineering defines it as systems and services that employees or functional managers adopt and use, which the organisation’s IS management neither provides nor approves — and identifies three consistent drivers: performance expectancy (the unsanctioned tool is believed to work better), effort expectancy (it is easier), and social influence (colleagues are using it).
Their most useful contribution is the insistence that shadow IT has a dual nature. It is simultaneously a governance risk — unmanaged systems create security exposure, compliance gaps and integration problems — and an innovation signal, because people adopt unauthorised tools precisely when the approved alternatives do not meet their needs.
Treating it only as the first is what makes organisations poorer at the second. A programme that shuts down forty tools without asking what each one was doing has destroyed a free, unusually honest requirements exercise.
This is the same mechanism that produces the spreadsheet that survives an ERP go-live. The tool is different; the diagnosis is identical. Someone had work to do, the sanctioned path did not do it, and they routed around the obstacle.
The reason you cannot simply ask
Here is the finding that should change how you measure this. In the same survey, 52 per cent of people who use AI at work were reluctant to admit using it for their most important tasks, and 53 per cent worried that using AI on important work makes them look replaceable.
Read that carefully, because it is not a compliance problem. People are not hiding AI use because they fear a policy breach. They are hiding it because disclosure feels like an admission that their judgement was not required — that the part of the job they are valued for could be done without them.
This has three consequences that most AI readiness surveys ignore:
- Self-reported AI usage is systematically understated, and understated most where the stakes are highest. Your survey is most wrong about exactly the work you most need to understand.
- The people best at using it are the least likely to say so, because they have the most to lose from the inference. The internal expertise you could be spreading is deliberately invisible.
- Amnesty programmes largely fail when the fear is about status rather than sanction. “Tell us what you are using, you will not be in trouble” does not address a worry about looking replaceable.
It is the same trust dynamic that determines whether people act on a model’s output at all — adoption stalls when employees do not trust what the system produces, and disclosure stalls when they do not trust what the organisation will conclude about them.
Reading the pattern
Not all shadow AI means the same thing. What was being done with it is the diagnosis.
| What people are using it for | What it actually tells you |
|---|---|
| Summarising long documents | Information is reaching people in a form they cannot consume in the time available |
| Drafting routine written output | A volume problem nobody has established, because it was absorbed as unpaid overtime |
| Explaining your own systems or policies | Internal documentation is unusable, or people cannot find it — a knowledge management failure |
| Writing formulas, queries or code snippets | A capability gap in a tool you already own and thought people were trained on |
| Translating or rewriting for tone | Real communication friction, often across countries or between functions |
| Checking their own work before submitting | Low confidence and an absent feedback loop — usually a management finding, not a tooling one |
The last row is the one worth pausing on. When people use an external model to check work before showing it to a manager, the organisation has a supervision problem that predates AI entirely.
Why blocking underperforms
Blocking is sometimes necessary, and where regulated data is involved it is not optional. But as a general strategy it has a specific weakness: it removes the visibility without removing the behaviour.
The three drivers Haag and Eckhardt identify are untouched by a block. The work is still hard, the sanctioned tool is still slower, and colleagues are still getting through their day faster. What changes is the route — from a corporate laptop to a personal phone, where there is no logging, no data boundary and no possibility of ever measuring it. Haag and Eckhardt also studied how users justify violating IT usage restrictions, drawing on neutralisation theory; people are practised at reasoning their way past a rule that stands between them and their workload.
And Markus and Tanis’s observation about enterprise systems applies with full force: operational staff adopt workarounds to cope with early problems and then fail to abandon them once the problems are resolved. A workaround established during the eighteen months you spent selecting an approved platform will still be in use after it launches.
What to do with the finding
Treat the inventory as a requirements document. Forty tools is forty statements about unmet need, gathered without a workshop and without anyone trying to please you. Group them by the table above and you have a prioritised list of what a sanctioned capability would actually have to do.
Compete on effort, not authority. Effort expectancy is a driver, so the sanctioned route has to be genuinely easier. If it requires a business case, a licence request and a two-week wait, it loses to a browser tab regardless of policy. The realistic target is not compliance; it is being the path of least resistance.
Separate the data question from the capability question. These get conflated and they need different answers. “Customer records must not leave our tenancy” is a hard boundary. “People are using AI to draft internal meeting notes” is not a breach; it is a signal. Blanket policies that treat both identically are ignored on the second case and therefore weakened on the first.
Make disclosure safe in the specific way the fear requires. Since the worry is about looking replaceable, the counter has to be visible and behavioural: senior people describing their own AI use and what they still had to correct; recognition for the person who found a better method rather than quiet suspicion; and managers explicitly not treating “you used AI for that” as a criticism. Whether managers actually reinforce that message is measurable, and it is the variable that decides whether disclosure improves.
Govern it as culture, not as a document. The US National Institute of Standards and Technology’s AI Risk Management Framework is built on four functions — Govern, Map, Measure and Manage — and treats Govern as the cross-cutting one, describing it as cultivating a culture of AI risk management rather than issuing rules. The framework is also explicit that AI is socio-technical: impacts emerge not only from models and data but from how people build, deploy and use them. A policy that nobody can follow while doing their job is not governance; it is documentation of an intention.
Measuring something people are hiding
Given the concealment finding, direct questions will underestimate. Four approaches that hold up better:
- Ask about the task, not the tool. “How long does it take you to produce a first draft of a client summary?” Time distributions that have collapsed in one team and not another tell you where AI is already embedded.
- Ask about colleagues. Third-person questions attract markedly more honest answers on status-threatening topics.
- Use expenses and traffic. Personal-card reimbursements and DNS logs are unglamorous and considerably more accurate than a survey.
- Watch people work. Half a day of observation in one function surfaces what a questionnaire will not, for the same reason it works before a go-live — it measures behaviour rather than what people are willing to declare.
None of this requires a large exercise. It requires accepting that the honest number is not obtainable by asking politely.
The finding underneath
Shadow AI is usually reported upward as a control weakness. It is better understood as three simultaneous statements about the organisation: there is real demand, the sanctioned route is not meeting it, and people do not feel safe saying so.
The first is good news and most organisations spend heavily trying to manufacture it. The second is a solvable design problem. The third is the one that will still be there after the tooling is sorted out, and it is the one that determines whether your eventual approved platform gets used for anything that matters — or only for the tasks nobody minds admitting to.
More on adoption, trust and capability in the AI Adoption Readiness Hub, or use the AI Adoption Readiness Assessment to establish where your organisation actually stands before choosing a platform.
