Skip to content
Novyant
All insights
  • Governance
  • Data Governance

Shadow AI is already in your operation. The question is what it has read.

Roughly two thirds of employees use AI at work and roughly a fifth of employers have a policy about it. Banning the tools does not close that gap. It just moves the usage somewhere you cannot see.

By Roberto Sanson5 min read
An illustrated office where documents drift out through a window into an unseen elsewhere

We have written about agents outrunning their governance, systems an organization deliberately deployed and then failed to watch.

This is the other half, and it is larger. Shadow AI is not something IT rolled out. It is what your staff started doing on their own, months ago, for entirely reasonable motives.

The surveys vary in the way surveys do, but they converge on an uncomfortable shape. Salesforce's 2026 workforce research puts employee AI use at work at 67% while only around 18% of organizations have a formal AI security policy. Other 2026 estimates of unsanctioned tool use land between 45% and 66%. Deloitte found worker access to AI rose by half during 2025, with roughly one company in five operating a mature governance model.

IBM's breach research attaches a number to the consequence: incidents involving shadow AI carry roughly $670,000 in additional cost, and about a fifth of organizations reported a breach tied to it, while only around 37% have any detection or governance in place at all.

The mechanism is boring, which is why it works

Nobody sets out to exfiltrate company data. The sequence is always the same, and it is not a security failure in the usual sense.

Someone has a report due. The system that holds the numbers is slow, or the export is awkward, or the template is in a shared drive nobody has reorganised since 2021. They paste the contents into a chat window, get a clean draft in forty seconds, and file it.

It worked. It saved them an hour. They will do it again tomorrow, and they will tell a colleague.

What has happened is that a customer list, a claims file, a set of student records or a supplier contract has left your control permanently, into a service with no agreement in place, no defined retention, and no answer to the question a regulator would ask.

The healthcare version of this is the starkest: a 2026 survey found 57% of healthcare professionals had encountered or used unauthorised AI tools, with clinicians drafting notes and synthesising treatment plans in general-purpose assistants, processing protected health information with no business associate agreement anywhere in the chain.

Why banning it does not work

The instinct is a policy that prohibits the tools. We have watched several organizations try this, and the outcome is consistent.

Usage does not stop. It moves to personal devices, personal accounts and personal phones, where you have no logs, no visibility, and no ability to discover it during an incident. You have converted a governance problem into an invisible governance problem, and made your own numbers look better while making your actual exposure worse.

There is also a plainly commercial cost. The productivity is real. An organization that successfully bans these tools while its competitors use them carefully has chosen a slower operation in exchange for a false sense of control.

The only approach we have seen work is to make the sanctioned path faster than the unsanctioned one. People route around friction, reliably and without malice. If the approved tool is slower, they will not use it, and no policy document changes that.

Read shadow AI as a diagnostic

This is the part most security-led responses miss, and it is where the actual value is.

Every instance of shadow AI is a precise, unsolicited signal about where your systems are failing the people using them. Somebody pasted a spreadsheet into a chatbot because assembling that report by hand was intolerable. Somebody drafted correspondence in an assistant because your template process is worse.

That is a free operational audit, delivered by the people closest to the work.

When we walk into an organization now, "which AI tools are people using, and for what" is one of the first questions we ask, not because we are auditing compliance, but because the answers map directly onto the workflows worth fixing. The tasks people reach for a chatbot to do are, almost without exception, the tasks their systems should have been doing for them.

Treated as a security incident, shadow AI produces a policy nobody reads. Treated as a symptom, it produces a roadmap.

The specific exposure, in Mexico and elsewhere

For our clients this is not abstract, and the ground has moved.

Mexico's March 2025 reform dissolved INAI and moved personal-data enforcement to Transparencia para el Pueblo under the federal anticorruption ministry. The obligations did not soften; the institution changed, and the enforcement posture is still settling. In that environment, "we are not certain which third-party services our staff pasted personal data into" is a genuinely bad position, and it is the position most organizations are currently in.

The commercial version arrives sooner than the regulatory one. A carrier's audit team, a university's privacy officer or an enterprise client's security questionnaire will ask which AI services process their data. There are two possible answers, and only one of them keeps the contract.

What to do in the next thirty days

Not a programme. Four steps, in this order, because the order is what makes it achievable.

1. Find out, without punishing anyone. Ask, in a way that makes honesty safe: which tools, for which tasks, how often. An amnesty produces an accurate map. An investigation produces a clean survey and an unchanged reality.

2. Sanction something good, quickly. One approved tool, with an actual agreement covering data handling, available to everyone who needs it, this quarter. The single biggest driver of shadow AI is the absence of a legitimate option.

3. Draw one bright line people can remember. Not a taxonomy. Something like: no client-identifying data, no personal data, no unreleased financials leave approved tools. A rule staff can recall under time pressure beats a comprehensive policy they have never opened, and remember that only about a quarter of employees in these surveys know their employer has a policy at all.

4. Fix the top three workflows the shadow usage exposed. This is the step that reduces the behaviour, because it removes the reason for it.

The bottom line

Your organization is already using AI. That decision was made months ago, by people trying to finish their work, without a meeting.

The governance question is not whether to permit it. It is whether the version your staff are using is one you can describe, bound and defend, or whether you will find out what it processed during a breach notification.

And the strategic question is the more interesting one: every workaround your people invented is a specific, well-evidenced statement about which of your systems is not good enough. That information is worth more than the policy.

Working out which of those workflows deserve a real system is the diagnostic we start every engagement with: that is what a first conversation covers, and where AI automation pays is the framework we use to decide which ones are worth automating at all.

Working on something like this?

We spend the first conversation understanding what you run on today. No pitch, and no obligation to build anything.

Book a call