Article · Writing

Shadow AI Is Not Innovation. It Is Risk Without Governance.

Employees using personal AI accounts for company work create risk without governance. The answer is better approved tools, clear rules, and real accountability.

Cartoon of a vault-door entrance with compliance plaques beside an open orange door marked Personal ChatGPT Account, where an employee wheels a cart of customer data past a dismayed CISO

I am about as aggressive an advocate for enterprise AI adoption as you will find.

I think organizations should move faster. Experiment more. Put capable AI tools in the hands of employees. Redesign workflows around them. Learn what works before the organization chart, procurement process, and annual planning cycle catch up.

But there is one form of AI adoption I have very little patience for:

Shadow AI.

Employees using personal ChatGPT, Claude, Gemini, or other AI accounts to perform company work, particularly when they are moving organizational data, customer information, source code, documents, or other proprietary information through tools the organization has not approved.

That is not innovation.

It is technology adoption without governance, visibility, contractual protection, or accountability.

And organizations should be working aggressively to eliminate it.

I learned a long time ago that speed and security need each other

I spent more than a decade as a local government executive, including roles where I was responsible for organizational transformation and digital transformation across large parts of government.

I often worked under mandates from mayors and other leaders to make meaningful change quickly.

My natural approach has always been something close to: go fast and try very hard not to break things.

That philosophy does not always make me the most popular person in the room with a CISO.

But I have also always tried to build strong partnerships with security leaders because innovators and security professionals need each other.

In a large organization, whether government or private sector, you can only innovate as fast as you can innovate safely.

Why?

Because when something goes badly wrong during an innovation effort, large organizations have an immune response.

They do not just stop the experiment.

They remember it.

Years later, someone proposes something that vaguely resembles the failed initiative and the organizational antibodies show up: security objections, procurement controls, legal reviews, new policies, new committees, new approval gates.

The original failure becomes institutional memory.

That is one of the reasons shadow AI concerns me so much.

AI dramatically lowered the technical skill required to create technology risk

Shadow IT has existed forever.

But traditionally, creating serious technology risk often required at least some technical sophistication.

Generative AI changed that.

Today, an employee can paste a contract into a chatbot, upload a customer spreadsheet, submit proprietary source code, analyze HR records, summarize controlled information, or build a workflow connecting organizational data to an external AI platform without understanding almost anything about how the underlying technology works.

And most employees doing this are not malicious.

Quite the opposite.

They are trying to be productive.

That is what makes shadow AI such a difficult problem.

The motivation is good.

The mechanism can be extraordinarily risky.

Netskope's 2026 research found that 47% of enterprise generative AI users were still using personal AI applications. Its more detailed AI report found 30% of users relying only on personal AI applications and another 14% using both personal and organization-managed tools.

This is not an edge case.

It is a mainstream enterprise behavior.

Employees clearly want AI.

The question is whether organizations are going to give them a safe way to use it.

The downside can be wildly disproportionate to the productivity gain

This is where I think leaders need to understand the asymmetry of shadow AI.

An employee may save 30 minutes by dropping information into a personal LLM.

The organization may inherit months or years of consequences.

Large organizations operate inside a dense web of security, regulatory, contractual, and customer obligations.

They may rely on SOC 2 controls, ISO 27001 information security frameworks, PCI DSS requirements around payment information, privacy laws, cybersecurity requirements, records retention requirements, intellectual property protections, data residency restrictions, and increasingly complex AI-specific regulations.

On top of that sit hundreds or thousands of contracts containing confidentiality provisions, security requirements, restrictions on subcontractors, limitations on data processing, incident notification requirements, and explicit or implicit commitments about how customer information will be handled.

Shadow AI can punch straight through those controls.

Imagine that an employee uploads customer information, source code, financial data, personally identifiable information, a confidential contract, or proprietary engineering material into a personal AI account.

Now start asking questions.

Was that AI provider approved as a processor or subcontractor?

Did the organization agree to its terms?

Where was the data processed?

Where was it stored?

Did it leave the country?

How long will it be retained?

Can the organization prove that it was deleted?

Was it used for model improvement?

Who can access the account?

Is multifactor authentication required?

Does the organization have logs of what was submitted?

Can security investigate the interaction six months later?

Was regulated data included?

Did the employee just violate a customer's contract?

Could the activity constitute a reportable security or privacy incident?

Those questions get uncomfortable very quickly.

And the consequences are not theoretical.

A shadow AI incident can create control exceptions during an audit. It can complicate a SOC 2 examination or an ISO 27001 certification process. Mishandling payment information can create PCI DSS compliance problems. Improper handling of personal information can trigger privacy investigations, notification requirements, regulatory exposure, and litigation.

A customer contract can create an entirely different category of pain.

If you promised a customer that its information would only be processed in approved environments, would remain within a particular jurisdiction, would only be accessed by authorized subprocessors, or would be protected according to specific security standards, one employee using a personal AI account may put the organization in breach of those commitments.

That can mean lawyers.

Incident response teams.

Outside forensic investigators.

Mandatory customer notifications.

Remediation plans.

Audit findings.

Insurance notifications.

Delayed deals.

Procurement holds.

Lost customers.

Contractual damages or indemnification disputes.

Regulatory scrutiny.

And a very uncomfortable conversation with the board.

There is also intellectual property risk.

Companies spend years building proprietary code, pricing models, product designs, strategy documents, algorithms, customer knowledge, and other trade secrets. Organizations generally have to take reasonable measures to protect information they consider confidential or proprietary.

Allowing that information to casually migrate into personal AI accounts is difficult to reconcile with that responsibility.

The math is absurd.

Someone saves 20 minutes writing a presentation and potentially creates hundreds of hours of legal, security, compliance, and executive work.

That is not innovation.

That is an unmanaged liability.

I am especially worried about government

I still speak regularly with friends working in local government.

What I hear concerns me.

In many cases, the state of AI deployment they describe feels several years behind what I see happening inside large companies.

There are absolutely governments doing impressive work with AI.

But across much of local government, deployment remains slow, fragmented, heavily constrained, or nonexistent.

That creates a predictable problem.

Employees go home and use extraordinarily capable AI systems in their personal lives.

They see what these tools can do.

Then they come to work and are told they cannot use them, or they are given an "enterprise AI" product so constrained that it bears little resemblance to the tools they use at home.

Human behavior takes over.

People find a workaround.

And government can have an even more complicated risk profile.

Public agencies may handle law enforcement information, personnel records, health information, taxpayer information, infrastructure data, legal communications, procurement information, economic development negotiations, personal information about residents, and records subject to specific retention or disclosure requirements.

A government employee putting that information into an unmanaged AI platform can create problems far beyond ordinary cybersecurity.

There can be public records implications.

Records retention issues.

Privacy issues.

Legal discovery issues.

Procurement and contractual issues.

Questions about where government information is being stored and who has access to it.

And potentially the worst possible sentence for a public agency to have to say:

"We don't actually know what information employees put into these systems."

The desire of government employees to become more productive is a good thing.

But good intentions do not mitigate institutional risk.

If government is going to tell employees not to use consumer AI, it has an obligation to move much faster in providing them with a viable alternative.

So what should organizations do?

1. Give employees approved AI

The first answer to shadow AI cannot simply be "no AI."

That strategy is dead on arrival.

Unless you intend to air-gap your systems and put every employee in something resembling a SCIF, your workforce has access to consumer AI.

You cannot uninvent ChatGPT.

Organizations therefore need enterprise-approved AI environments with appropriate security, identity, logging, contractual protections, data controls, and governance.

The best defense against shadow AI is giving employees a legitimate alternative.

2. Make the enterprise tool actually good

This is where I think many organizations are making an expensive mistake.

I have seen enterprise AI initiatives that appear to have been designed as though the primary customer were the CISO rather than the employee.

Every useful capability gets removed.

Every interesting integration gets blocked.

The model is several generations behind.

Uploads do not work.

Context is tiny.

The tool cannot connect to anything.

Then leadership spends millions deploying it and wonders why employees continue using personal AI.

That is a money bonfire.

Security is a requirement.

But usability is also a security control.

If your sanctioned tool is dramatically worse than the tools employees use at home, some percentage of your workforce will route around it.

Your approved environment needs to be good enough that using it is easier than violating policy.

3. Modernize AI and data governance

Most organizations were not designed for a world where every employee effectively has access to an infinitely patient junior analyst, programmer, researcher, writer, and data processor sitting inside a browser.

Policies need to catch up.

Organizations should clearly define what data can be used with which AI systems, what tools are approved, where human review is required, which use cases require additional controls, how AI systems are procured, how activity is logged, and who owns the risk.

Governance cannot be a 70-page policy nobody reads.

It has to become part of how work gets done.

I go into considerably more detail on this in my AI Transformation Field Guide, but the principle is simple: governance should make safe AI easier, not merely make unsafe AI prohibited.

4. Detect and block shadow AI

And then comes the part employees will like least.

Block it.

Modern security platforms can increasingly identify personal versus enterprise AI instances, detect uploads and prompts containing sensitive information, restrict specific actions, and steer users toward approved applications.

Use those capabilities.

If organizational policy says employees cannot move company information through personal AI accounts, the organization should not knowingly leave those doors wide open.

People will complain when their personal ChatGPT account suddenly stops working from their work computer.

Then something interesting will happen.

They will start asking how to accomplish the same thing with the enterprise tool.

That creates demand.

Demand creates feedback.

Feedback makes the enterprise platform better.

5. Create real accountability

Technology controls will never catch everything.

Employees therefore also need to understand that AI policy is an information security policy, not a suggestion.

There should be education first.

Clear approved alternatives.

Clear rules.

Clear explanations of why those rules exist.

But after that, deliberately circumventing controls or repeatedly putting organizational information into unauthorized AI platforms needs consequences.

For serious or repeated violations, those consequences can include termination.

That may sound aggressive.

But we already accept that intentionally moving sensitive corporate information into unauthorized personal cloud storage, emailing protected information to a personal account, or bypassing cybersecurity controls can become a serious disciplinary matter.

Putting the same information into an unauthorized AI system should not magically become acceptable because the interface has a friendly chat box.

Move fast. But move inside the guardrails.

I do not want security concerns to become the excuse organizations use to delay AI.

Quite the opposite.

The existence of shadow AI is an argument for faster enterprise AI adoption.

Your employees are telling you something when they bring their own AI tools to work.

They believe these systems make them better at their jobs.

Listen to that signal.

Give them great tools.

Build sensible governance.

Create safe places to experiment.

Train people aggressively.

Remove unnecessary barriers.

And then make the boundary unmistakably clear:

Use AI. Use it a lot. Learn it. Experiment with it. Find ways to transform how we work.

But do it inside the environment we can protect.

Because the fastest way to destroy an organization's appetite for AI innovation is not moving too slowly.

It is moving recklessly, creating a preventable incident, and giving the organizational immune system a reason to attack everything that comes next.