Shadow AI Is Not the Problem. Your Operating Model Is.
The consensus on Shadow AI is right about the risk and wrong about the cause.
The risk is real. I meet unauthorized AI in nearly every organization I advise, and the breach data confirms what the security teams fear: in IBM’s Cost of a Data Breach Report 2025, one in five breaches involved shadow AI, and organizations with high shadow-AI usage paid on average 670,000 dollars more per breach. Nobody should wave that away.
But the standard diagnosis, reckless employees plus missing rules, gets the system exactly backwards. Employees are not building unauthorized AI because they ignore the rules. They are building it because building has become nearly free while the official path has stayed expensive, slow and uncertain. Shadow AI is not a discipline failure. It is the predictable output of an operating model designed for a world where software was scarce.
The pain is not that people build. The pain is that the value stays local.
And the answer is not ChatGPT or Claude. The answer is three building blocks: a central AI platform where solutions participate in each other, incentives that make sharing worth more than hoarding, and a barrier to building so low that the official path beats the workaround. Everything else in this essay hangs on those three.
Everyone Builds Now. I Do Too.
Watch what happens inside any large company right now. Someone needs a small application to model and simulate a travel scenario, so they build one. Someone needs a tool that taps a few web sources and produces a market analysis, so they build one. Someone needs a scanner that identifies public tenders and drafts first answers, a sales-lead tracker, a file converter. Built, built, built. Whether the builder knows what they are doing is an open question. That they are building is not.
I will not pretend to watch this from a distance. It happens in my own firm too, and it happens to me. I generate a script that converts a WAV file or turns a Markdown file into a PDF. I use it once. Three weeks later I need it again, cannot find it, and let the model generate it a second time, because regeneration costs practically nothing. I genuinely forget what I have built. Software has become a throwaway article, and I am one of the people throwing it away.
The scale of this is larger than most executive dashboards admit. In the client conversations I sit in, the working assumption is still that unauthorized AI is a fringe of enthusiasts. The data says otherwise: when PagerDuty polled 1,250 office professionals at companies with at least 500 million dollars in revenue, with IT and technical roles excluded from the sample, 66 percent said they had used AI at work while believing it was forbidden. Two thirds of the non-technical workforce, building and using in the dark.
For the individual, every one of these moves is rational. For the organization, the sum is amnesia.
We Have Been Here Before, at a Slower Speed
This is not a new movie. It is a rerun at a higher frame rate. In the early 2000s we called it Shadow IT: the Access database under the desk, the Excel macros, the departmental tool that exactly one person understood. Enterprises paid the price for that era during digitalization, when they set out to modernize their process landscape and discovered systems nobody could explain, feeding processes nobody dared to switch off.
There was a brutal economic logic to why those systems stayed dark. Before AI, analyzing a 20,000-line orphan script meant assigning one person for three to four months. No business case survived that math, so the scripts were left alone and the ignorance compounded. Today AI could do that analysis for a fraction of the cost, which is a separate essay.
I have stood inside that inheritance twice. At a global logistics group in 2019, the job was to dissolve a large Oracle-based data warehouse into a modern architecture, and the first question was the oldest one in IT: what is actually in there? Nobody knew. At a European telecommunications group, from 2021, I led the factory that modernized 2,000 databases. For a given database there was perhaps one head left in the company, if that, who knew what was inside. And those databases did not float in free space; they hung together with applications and with each other, a web nobody had mapped.
Twenty years ago it was an Access database under one desk, feeding one report. Today it is an agent with credentials, memory and system access, feeding a live business process. In both cases exactly one person knows it is there.
What changed is the speed and the blast radius. What took a motivated power user weeks back then takes a prompt an afternoon in 2026. Anyone who can describe a tool can now produce one, which means the population of builders is no longer your IT department plus a few Excel wizards. It is everyone.
The Builder Is Rational. The Verdict Is on You.
Here is the sentence I hear, in various German and English variants, in enterprise after enterprise: “It will come to nothing anyway, so I will just build it myself.” It comes from employees who took an idea to the official channel, were told “great idea”, and then watched two years pass with nothing delivered. Heavy governance does not prevent Shadow AI. It manufactures it, and then congratulates itself on the policy.
Shadow AI is your organization’s verdict on the official system.
I wrote that sentence in Strategy is Good. Execution is Better., and I stand behind the harder passage around it: “Shadow AI … is not caused by reckless employees. It is caused by restrictive governance. The more rigid the approval process, the more employees turn to personal accounts and unauthorized tools. The governance designed to protect the organization drives risk into the shadows where it cannot be monitored or controlled.”
Read the verdict correctly and the moral panic dissolves. The people building in the shadows are your most motivated people. They saw a gain, they could not wait for you, and they were right that waiting would have cost them the gain. Punishing them treats the symptom as the disease.
The Real Pain: Value That Never Crosses a Desk
In a critical-infrastructure company I work with, everyone builds. The company put machines in employees’ hands so they could experiment, and they did: someone wrote themselves a sales assistant, and genuinely useful things emerged. Then came the company’s own assessment, and it was the honest one: none of it can be used by anyone else, because the path from one desk to a team, to a business unit, to the enterprise was never built. That is the real pain, and it has nothing to do with compliance.
The pattern generalizes far beyond one company. BCG’s 2026 workplace survey of 11,749 frontline employees across 14 markets found 74 percent using AI regularly, and 42 percent of those regular users saving at least one full workday per week. The number that matters most is the third one: 66 percent receive little or no guidance on what to do with the freed time.
Which does not mean the hour is lying around waiting to be collected. Without a route off the desk it goes straight back in: more drafts to check, more parallel threads, more switching between contexts. The heaviest AI users I work with, myself included, end the day busier, not freer. The gain is real at the task, and it never becomes capacity the enterprise can spend.
Productivity that stays personal is not an enterprise capability. It is a rumor.
So the right question is not the one most AI policies answer. The right question is never how do we stop employees from building; that battle is lost, and winning it would be worse than losing. The right question is: how does what one person built become something a team can use, then a business unit, then the enterprise? How does one person’s saved workday become a process that ten thousand people run?
Vibe Coding Is Not Software Development
I run a unit of nearly 200 people who build software for enterprises, AI-first for the past 18 months. So this is not nostalgia: vibe coding is not software development. Requirements engineering, architecture, security, testing, operations, monitoring. None of it disappears because the code arrived in an afternoon. Someone carries responsibility for what runs.
The throwaway class is fine, until it is not. My converter can stay disposable. The moment a generated solution touches shared data, a recurring process, a customer or a decision, it is organizational infrastructure, whether anyone declared it or not. The line is not build versus do not build. It is disposable versus load-bearing, and almost nobody can see where it runs.
The Four Wrong Answers
Confronted with all of this, enterprises reach for four answers. All four fail, each instructively.
Prohibition. Banning the tools does not reduce usage; it reduces visibility. The two thirds who already believed AI was forbidden used it anyway. A ban converts your most motivated employees into your least monitored systems.
Total centralization. Routing every idea through an architecture board, security, legal, data protection and procurement reproduces the exact condition that created Shadow AI in the first place: legitimate demand moving faster than the enterprise can answer.
A central chatbot. Licensing ChatGPT, Claude or Copilot for everyone solves access and part of the data question, and assistants are genuinely good for the quick individual task: comparing two spreadsheets, drafting an email, summarizing a tender. But an assistant license answers none of the structural questions: which solutions exist, who owns them, what data they touch, which ones can be reused, how they are evaluated, retired, paid for. A chatbot for everyone is a utility, not an operating model.
A platform without an operating model. The inverse failure. Even the right platform changes nothing if ownership, publishing paths, incentives and lifecycle remain undefined. Technology enables the operating model. It cannot substitute for it.
What actually works has three building blocks.
Building Block One: A Platform Where Solutions Participate in Each Other
The technical core is a central AI platform, and the design principle that matters is participation. Connect a system once, govern it with rights and roles, and every solution on the platform can use it, instead of each use case re-implementing the same integration and rebuilding, like 20 years ago, silo after silo.
The platform must not be bound to one vendor or one model. Models will be swapped over time, and an agent tested on one model will not behave identically on another, so evaluation, versioning and regression testing belong in the platform, not in the heads of individual builders.
On top of that core sit two structures the platform makes cheap. The first is a registry. Every relevant agent and application gets an entry:
- an owner, by name
- a purpose
- its data sources
- its permissions
- a version
- a review date
- a kill switch
The second is a catalog with maturity grades, from personal experiment to team-approved to enterprise-approved, so a colleague can find a solution, see what it may be trusted for, and copy it as a template instead of rebuilding it blind.
None of this needs to be heavy. Most of it can be automatic. All of it turns invisible building into visible capability.
Building Block Two: Whoever Pours Knowledge In Must Benefit
The second building block is the one enterprises skip most reliably. Today, sharing a solution is a punishment. The employee who publishes her tool is expected to document it, train colleagues on it and maintain it forever, on top of her actual job, for no recognition. My book’s name for the people who quietly decline that deal is the Secret Cyborgs: high performers who automate their own work and tell nobody, because telling somebody only ever produced more work. The book also states the rule I keep watching play out:
Incentives encode what the organization actually values. AI cannot override incentives. It can only reveal them.
So pay for what you want. Attribution by name in the catalog. Time and budget when a personal tool is promoted to a team asset, because hardening and documentation are work. Reuse counted in the numbers that matter for careers, not in the number of agents created.
And one hard protection: the original builder must never become the unpaid lifetime maintainer of an enterprise asset. If pouring knowledge into a shared solution costs the employee and benefits only the organization, the knowledge stays personal, and you are back in the shadows.
Building Block Three: Make the Official Path the Fastest Path
The third building block is a low barrier. Not low standards: low barriers. The test is simple. Is the official way to build and share a solution faster than the workaround? If the answer is no, employees will keep choosing the workaround, and they will be right to.
Risk-tiered lanes make this practical.
Green. Personal, read-only, low-risk tools. Instantly usable, automatically registered, approved models and data sources, no manual sign-off.
Amber. Team and process applications. Automated security and compliance checks, a named owner, evaluation, cost monitoring.
Red. Anything customer-facing, writing to production systems or acting autonomously. The full software lifecycle, human oversight, regression tests, rollback.
Not every AI application needs the same governance. Every relevant one needs visibility. Approval cycles measured in quarters, applied to tools that change weekly, are not control. They are the assembly line for more Shadow AI.
From Shadow AI to Business-Managed AI
Shadow-IT research drew a distinction that two decades of practice confirmed: the opposite of shadow IT is not central IT. It is business-managed IT, solutions that originate in the business but are visible and governed. The same move is now due for AI. The target picture is governed self-service: decentralized building on a shared platform, incentives that pull solutions into the light, governance proportional to risk. Turn Shadow AI into business-managed AI.
The regulatory clock has already started. The EU AI Act’s AI-literacy duties have applied since February 2025, and its Article 50 transparency obligations apply from 2 August 2026, twelve days before this essay’s publication date. Whether a given internal agent falls under them depends on the system and on your role as provider or deployer, but the direction is unambiguous: AI that nobody can inventory or explain is moving from bad practice to legal exposure.
So here is the verdict, and it is not aimed at the builders.
The builders are doing their part. They found the gains you asked them to find.
The tools are doing their part. Building has never been this cheap, and it will get cheaper.
The regulation is doing its part. With the transparency obligations that applied from 2 August 2026, the direction is set: visibility is where the law is going, and the inventory you cannot produce today is the finding of tomorrow’s audit.
The only unfinished part is the operating model, and the operating model has an owner: not the employee with the experiment box under the desk, not the vendor of your chatbot, but the leadership team that decides what gets a platform, what gets an incentive and what gets a lane. Shadow AI is the workforce’s answer to a question leadership has not answered yet. Answer it: one platform where solutions participate in each other, one real reason to share, one official path faster than the workaround. Do that, and the shadow does not have to be fought at all. It walks into the light on its own, because the light is finally the better deal.
The governance paradox, the Secret Cyborgs and the incentive redesign each have their own chapter in my book, Strategy is Good. Execution is Better. – Why Organizations Struggle to Scale AI → https://iamyb.com/book/#store