This isn't a marginal phenomenon
The Cloud Security Alliance reports that 98% of surveyed organizations already have unsanctioned AI use, while 86% lack visibility into how data flows into and out of these tools. Only 37% have any AI governance policy in place.
Source: Cloud Security Alliance.
This can no longer be described as a collection of isolated incidents. It is a structural gap between adoption and governance.
The problem didn't start with agents
The first generation of Shadow AI was relatively simple. An employee had a document and needed to summarize it, so they pasted the content into their personal chatbot. A marketer needed to generate a campaign. A developer needed to solve a coding problem. An analyst needed to interpret data.
The motivation was almost always the same: do the work better and faster.
This matters because it changes how to approach the problem. We're not necessarily dealing with malicious employees. We're dealing with employees who found a technological capability before their organization did.
But Shadow AI just changed scale
The problem today no longer boils down to what information an employee is pasting into a chatbot. With agents, the questions change entirely:
- What can an AI agent access?
- Under what identity?
- What permissions does it have?
- What systems can it query?
- What actions can it execute?
- Who authorized that connection?
- What evidence is left behind?
- Needs someone to hand it information
- One-off interaction, no persistent system memory
- Risk concentrated in what data is shared
- Can have persistent access to information and tools
- Can execute actions and interact with enterprise systems
- Operates at a speed no manual approval process can keep up with
The paradox: blocking can make it worse
This is where one of the hardest decisions for a CIO, CISO, or compliance lead comes in. The natural reaction is to block domains, applications, extensions, and personal accounts. From a security standpoint, that's understandable.
But there's a problem: blocking the tool doesn't eliminate the need that drove the employee to use it. If someone needs to summarize 50 pages in ten minutes and the organization gives them no alternative, the need is still there.
- They can switch tools
- They can use another device
- They can look for another service
- They can find another way
The real crisis isn't unauthorized AI
It's the lack of visibility into what's happening inside the organization. A company can have a responsible AI use policy, an AI committee, an approval process, and an authorized corporate tool — and still not know what AI its employees actually use.
That's the point where a policy stops being governance. Governance requires the ability to observe, classify, decide, control, and demonstrate.
What an organization should do
It wouldn't start with a policy. It would start with visibility.
Build a real inventory of tools, models, agents, integrations, data, and users — including what was never formally approved. You can't govern what you don't know exists.
It's not enough to know someone uses a tool. You need to understand what for, with what data, and with what impact. Generating ideas for a slide deck is not the same risk as an agent accessing customer data.
Risk should depend on the context of use, not just the tool's name: sensitive data, decisions about people, critical systems, autonomy, integrations, and applicable regulation.
If the official alternative is worse than the tool the employee already found, the policy will lose. The organization needs to offer approved tools that are secure, useful, fast, and accessible.
Not every AI use needs to be blocked. But you do need to know what information can leave the organization, to where, under what conditions, and with what guarantees.
An agent needs far more than an initial approval: identity, permissions, boundaries, oversight, traceability, and evidence — maintained throughout its entire lifecycle.
The solution isn't eliminating Shadow AI
This is probably the most uncomfortable conclusion: we're not going to eliminate Shadow AI simply by banning it. AI adoption doesn't depend solely on corporate policy. It depends on people, and people will keep looking for tools that let them work better.
The simplest example is also the most revealing one: taking a photo of a document and sending it to a personal LLM. It can happen in seconds. It requires no integration, no IT project, no malicious intent. And that's exactly why it's so hard to solve with traditional controls alone.
But easy doesn't mean right. It isn't ethical to send corporate information to a personal tool just because it's the fastest way to solve a problem. The employee has a responsibility. But so does the organization.
From Shadow AI to Governed AI
That's why the conversation needs to change. Not "how do we stop our employees from using AI?" but "how do we make using AI safely easier than using it in secret?" That shift looks small, but it completely changes the governance model.
- Prohibit
- Detect
- Sanction
- Discover
- Understand
- Classify
- Enable
- Control
- Evidence
The goal shouldn't be a company where no one uses AI outside the official catalog. The goal should be a company where the AI already in use can become known, assessed, authorized, and governed AI.
The crisis isn't solved by shutting AI down. It's solved by making governance able to keep pace with it. And that will probably be one of the great tests of enterprise maturity over the next few years.
Frequently asked questions
Shadow AI is the use of AI tools, models, or agents inside an organization without formal approval, oversight, or registration by IT or the governance function. It ranges from an employee pasting information into a personal chatbot to an agent with access to enterprise systems that nobody formally authorized.
Because blocking the tool doesn't eliminate the need that drove the employee to use it in the first place. If someone needs to summarize 50 pages in ten minutes and the organization gives them no alternative, they will find another tool, another device, or another way. The risk doesn't disappear — it becomes less visible, which is exactly what makes it more dangerous.
A chatbot needs someone to hand it information every time. An agent can have persistent access to systems, query tools, and take actions on its own, at a speed no manual approval process can keep up with. That's why governing agents means managing identity, permissions, and traceability — not just what data gets shared.
Not with a policy — with visibility. Build a real inventory of tools, models, agents, integrations, and users, including what was never formally approved. From there you can understand actual usage, classify risk by context, and offer a corporate alternative that's as good as the one the employee already found.
ISO/IEC 42001:2023 requires exactly what Shadow AI exposes: an inventory of AI systems (Annex A.4), impact and risk assessment (§6.1, §8.2), and controls over each system's lifecycle, including systems that weren't built in-house. Implementing the standard forces you to discover and classify the AI that's already in use, not just the AI that was approved.
Do you know what AI your teams are actually using?
Our free assessment maps the real AI usage in your organization — tools, agents, and data — against what ISO 42001 requires.
You may also be interested in: AI systems inventory · ISO 42001 vs ISO 27001 · ISO 42001 vs NIST AI RMF