Skip to content
Shenzhen · The Greater Bay Area · Earth

Shadow AI Is Already in Your Company: Stop Asking Whether to Adopt It

The usage decision was made months ago by individuals, not by you. What is still open is whether the AI running inside your company has a contract, a retention rule and a named owner behind it.

8 min read1,703 words
AI AdoptionEnterpriseNot yet translated.

Which version of your company's AI is actually in production?

Your team is already using AI, unofficially, on the highest-risk data you hold. The open question is not whether to adopt the technology — that decision was made months ago by individuals, in private — but whether the version now in use has a single control attached to it.

The usual explanation is wrong: nobody did it out of defiance. A task became unbearable — a 60-page agreement to review by Thursday — and a twenty-dollar subscription made it survivable that afternoon. Doing it officially meant a ticket, a security review and a decision six weeks out. The workaround arrived in an hour. That is a procurement failure before it is a discipline failure.

What makes this a matter for the person holding the P&L is the shape of the usage, not its volume: the tasks where AI's value is self-evident are exactly the tasks that touch your most sensitive material.

Where does the unsanctioned usage concentrate?

In the audits I have run, it clusters in five places, and rarely anywhere else:

ClusterWhat gets pastedWhy it is sensitive
Contract and tender reviewClauses, pricing schedules, indemnitiesConfidential terms you signed obligations about
Finance and board reportingDraft commentary, variance tables, forecastsUnpublished numbers behind a covenant
HR writingPerformance notes, job specs, redundancy lettersPersonal data, and the highest legal exposure per page
Customer complaintsEmail threads, account history, case notesPersonal data plus a record that reads like your final position
Engineering debuggingLog lines, schema, sample recordsProduction data with no redaction step

Usage concentrates wherever the deadline is tightest and the document is worst — the same places where a mistake is expensive and a training default is indefensible.

Where is the evidence already sitting, in systems you own?

You do not need a forensic investigation to find the tools. Three sources will give you most of the list this week, and two require nobody's cooperation:

  • The expense ledger and corporate card statements. Search for the recurring software lines under the approval threshold.
  • Your identity provider's third-party app grants. In Google Workspace or Microsoft Entra, look at which external applications employees consented to, and with what scopes.
  • Endpoint or browser extension inventories, if your device management tooling reports them.

A fourth source — DNS or egress logs — tells you a domain was reached, not what was pasted into it, which is the only thing that matters for classification. And none of the four will find the person using a personal laptop, a personal card and a personal account. That gap does not close with tooling, only by making the sanctioned route fast enough that the personal route stops being worth the friction.

Shadow AI is not a discipline problem, it is a procurement and controls problem: your team adopted whatever worked fastest, and the only decision still available to you is whether the version they are using has a contract, a retention rule and an owner behind it.

What does the consumer tier do differently with the same prompt?

The output is often identical, and that is the trap. The difference is entirely in the surrounding contract and configuration, and it is where a CFO rather than an engineer has standing.

On consumer tiers, inputs are typically eligible for model training by default unless the user opts out — a step almost nobody takes, because it is buried and the tool does not advertise it. On business and enterprise tiers, training on your content is excluded by default under the terms. That distinction is the difference between a prompt being transient and a prompt being, in effect, published. Beyond it: retention windows you cannot set, no data processing addendum for a customer, no subprocessor list, no residency choice, no administrative visibility, no audit record. If someone asks what data left your organisation, on which date, under whose account, the consumer route gives you a shrug. There is a fuller treatment of the records an enterprise AI system has to be able to produce when a customer or a regulator asks, and I would give that one to whoever owns your security questionnaire responses.

What is already on the ledger, and where does that number come from?

I can give you arithmetic; I will not give you a benchmark, because the only defensible figure is the one you compute from your own accounts.

Say 40 people each hold one personal-tier subscription at roughly $20 a month. That is 40 × 20 × 12, or $9,600 a year, arriving as 40 separate lines, each below the threshold that triggers scrutiny. Treat that as illustrative arithmetic for your own count, not a finding about your company.

Where the spend hidesWhat it looks likeWhy it survives review
Individual subscriptionsOne line per personUnder the threshold individually
A manager's team planOne card, monthlyPlausible, and never security-reviewed
Developer API keysUsage-based, variableReads as infrastructure
AI features inside approved toolsBundled into a renewalPassed procurement under the old scope
Premium tiers of owned toolsSmall uplift on a known lineNobody re-reads a renewal that got cheaper per seat

The framing that moves this conversation is that it is a reclassification, not a new cost. You are already paying for the capability. What you are not paying for is the contract, the retention setting, the logging, the seat management, or the ability to switch any of it off.

Why does a ban fail on arithmetic rather than ethics?

A ban needs an instrument. To enforce one you need identity-bound access to AI tools, control of what leaves your network, and devices you manage — the same instrumentation you need to run AI safely. So the situation resolves cleanly: if you can enforce a ban, you do not need one, because you can govern the usage instead. If you cannot enforce it, the ban is a policy with no instrument, and its observable effect is that usage moves further out of sight — personal devices, personal accounts, content pasted with the customer names still in it.

The cost is not only hidden usage, it is lost capability. Every rollout I have been asked to repair had the same first failure: the sanctioned tool was slower than the personal one on the task the person actually had, with the file formats they actually receive. A tool that needs a different login, a converted file and a re-upload gets abandoned within a fortnight, and the conclusion drawn is that AI does not work here.

What does discovery look like without turning it into a witch hunt?

Announce a two-week inventory with an explicit amnesty: nothing reported carries a disciplinary outcome. Ask five questions individually, and write down the answers.

  1. Which tools do you use, and on a work account or a personal one?
  2. What goes into them? Name the document type, and say whether it contains customer names, prices, or anything about a person.
  3. What did you stop using — because it was blocked, or because somebody told you to?
  4. Which tool did you try and abandon, and what went wrong?
  5. If this were withdrawn tomorrow, what specifically would stop getting done?

Questions four and five carry most of the value, and they are the two nobody asks. The abandoned tools are failure modes you would otherwise pay a vendor to rediscover.

Some people will under-report; assume that and cross-check against the ledger rather than sounding like you are testing them. If the amnesty turns out to be a trap, the second inventory finds nothing, and the finding is false.

Which controls change the risk, and in what order?

If you can only do one thing, do the first row: it converts an unknown quantity into a list of named people, and every other control depends on that list existing.

ControlWhat it changesHow you verify it exists
Identity-bound accountsUsage becomes attributable and revocableYou can produce the user list from your IdP
Business-tier terms, training excludedContent stops being a training inputThe signed clause plus the admin console setting
A written rule at the paste boundaryNames categories that may never leaveStaff can name two without looking them up
Administrative usage loggingAn incident becomes a dated recordYou can answer "which account, which day" unaided
A named owner for the AI estateSomeone reconciles the ledger quarterlyA name, with hours in their week

On sequencing, since it saves money: buy the business tier before you build anything. Converting 40 expensed subscriptions into a governed estate is procurement and configuration, and I have watched companies spend six figures on a platform before doing the cheaper thing that removes most of the risk.

What is the actual decision, and when is waiting defensible?

Waiting is defensible under two conditions at once: the material in your workflows is genuinely low-sensitivity — no personal data, no pricing, no unreleased intellectual property — and the usage sits with people whose judgement you would back anyway. Under both, your incremental exposure is roughly what you already carry through email and removable media. Waiting is close to indefensible if any workflow touches regulated personal data or terms you signed confidentiality obligations about, because there the missing control is the entire risk rather than a fraction of it.

I do not have a trustworthy figure for what share of enterprise AI usage is unsanctioned, and neither does anyone selling you a platform: the measurement is the thing that is missing, which is precisely the problem.

The decision is a comparison between two costs, and only one appears in your accounts. The visible one is a licence line you have been treating as trivial. The invisible one is the absence of a retention rule, an audit record and a name on a page. Pull the card statement and the identity provider consent list this week, count the lines, and you will know whether you are choosing between a governed version and an ungoverned one, or merely between two governed ones.

Keep reading

More in AI Adoption

Ready to build a system?[ Book a Call ]