Every company has a shadow AI problem. Most leaders can't see it yet.
Shadow AI is arriving faster than shadow IT did, and the old chokepoints are not enough.
Original LinkedIn versionSomewhere around the early 2010s, IT teams realised the argument had already been lost. People were using Dropbox, Trello and whatever else helped them get work done, whether procurement liked it or not. They wired these tools into daily work. By the time central IT noticed, the software was load-bearing and you couldn’t pull it out without grinding the business to a halt.
We called it shadow IT, and cleaning it up took the better part of a decade. CASBs were invented. Single sign-on went from nice-to-have to table stakes. Security teams learned to make the approved option less annoying than the thing people found for themselves instead of saying no.
The same pattern is happening right now with AI. Only this time, nobody is getting a decade to tidy it up. What took 10 years with SaaS is taking 10 months with LLMs, and the consequences don’t rhyme neatly with what we learned last time.
In any reasonably sized knowledge-work business, there is almost certainly some shadow AI already in motion. Sales reps pasting prospect lists into ChatGPT for outreach copy. Analysts dumping internal financials into a chatbot to speed up a board pack. Recruiters running candidate resumes through free summarisation tools. Engineers using Copilot in ways their security team hasn’t approved and couldn’t detect if they tried. Operations leads building agents in no-code platforms over a weekend. A growing number of SaaS vendors have also added AI features, sometimes with settings buried deep enough that buyers may not have properly evaluated what changed.
None of this is malicious. Most of it isn’t even policy-violating, because most companies haven’t written the policy yet. And where they have, half the business has never read it and the other half is quietly routing around it. It’s happening because the tools are good, and consumer-grade AI is still outpacing the enterprise-grade version.
This is exactly how shadow IT started. The part that’s different is what happens next.
Why this isn’t just shadow IT with better branding
The playbook from the SaaS era was built on assumptions that no longer hold.
Data leaves in a single prompt, not a slow sync. Shadow IT often leaked data slowly enough that you had a chance of spotting the mess. Shadow AI doesn’t give you that luxury. One prompt can move a customer list, a legal draft, or a financial projection outside your control before anyone has even raised a ticket. There is no “slowly” to catch.
Outputs get acted on, not just stored. A rogue SaaS tool mostly stored files you wished were somewhere else. A rogue AI tool writes the email that goes to the regulator, drafts the clause that ends up in the contract, scores the candidate who does or doesn’t get the interview. When the output is wrong, it isn’t just sitting in a folder; it’s already downstream, in decisions that are increasingly expensive to unwind.
The tool itself changes behaviour without a changelog. You could audit Dropbox once and know roughly what Dropbox did. Foundation models update constantly, get fine-tuned quietly, and behave differently on the same prompt week to week. “We evaluated this tool last quarter” means less than it used to.
You can audit a SaaS vendor. You can’t audit what an LLM did last Tuesday. With SOC 2 reports, data processing addendums and security questionnaires the entire apparatus of SaaS governance assumes the vendor can tell you what happened. Most LLM providers can’t give you a granular, per-employee, per-prompt history of what your data did inside their system. The audit artifact you need largely doesn’t exist unless you create it yourself.
Regulation asks questions shadow AI can’t answer. SaaS governance grew up in a world where the main questions were where the data lived, who had access to it, and what happened if it leaked. AI governance is different. You now need to know what the system is being used for, whether humans are meaningfully involved, what evidence supports the output, and whether anyone is monitoring it after approval. Every framework assumes the company can produce an accurate list of what it is running. For most companies right now, that assumption is generous.
Why the old chokepoints don’t catch AI
Shadow IT got contained because most SaaS tools eventually flowed through a small number of chokepoints: the network edge, the identity provider, the expense system. CASBs, SSO, and finance controls meant that even if a tool slipped in unapproved, you could usually see it within a quarter.
AI breaks every one of those chokepoints.
The network edge is porous because AI lives on an employee’s phone, on personal hardware, in browser tabs the company doesn’t manage. The identity provider is less useful than people assume. Not because SSO has stopped mattering, but because the risky AI behaviour is often happening inside tools you already approved. And the expense system is blind, because most of this usage is free.
The governance layer can’t stay at the network edge. It has to move up the stack, closer to the work itself, it has to move to the prompt, the document, the decision. That’s a harder engineering problem than the last generation of security teams had to solve, and it’s the one most companies are quietly avoiding.
The useful lesson from Shadow IT
Here’s the part worth sitting with. The companies that survived shadow IT weren’t the ones that said no the loudest. They were the ones that got visible the fastest, made the sanctioned path genuinely better than the unsanctioned one, and treated employees using unapproved tools as a signal about internal gaps rather than a threat to be punished.
That’s the test arriving now for AI. The leaders who pass it will be the ones who stop pretending they can ban their way out and start asking better questions.
What are our people actually doing with AI today?
What would make the approved path easier and/or more useful than the shortcut?
What can we see or do this quarter that we couldn’t see last quarter?
The companies that handle this well will not be the ones with the strictest memo. They will be the ones that can see what people are already doing, understand why they are doing it, and make the approved route less painful than the workaround.