On shadow AI, most companies swing to one of two ends: an absolute ban, or unlimited freedom. Both sides present their own choice as a strategic decision. “We banned it, because we take data security seriously.” Or the reverse: “We don’t ban it, because we want our people to learn these tools.”
Both sound reasonable. Both are missing the same thing, which is governance. Banning isn’t a governance answer. Most of the time it’s a compliance control.
A ban can give you the feeling of control. Usage carries on either way, with less oversight than before.
When I start work with a company we begin with a current-state analysis, and one of the first stops is shadow AI. The proud “we banned it” answer comes mostly from large multinationals, usually the ones with the most mature security function. The other end shows up in fast-growing companies and in markets with no binding AI instrument yet: a few contractual commitments, then usage left largely to the employee’s own initiative. In both models, once we get down to what is actually happening, there are surprises.
PagerDuty’s June survey of companies with more than $500 million in annual revenue found that two-thirds of professionals had used AI tools their own company policy forbids. Executives included.
So the ban often moves risk out of the company’s field of vision instead of reducing it. Use continues, but it isn’t in your inventory and it isn’t in your logs. You don’t know which tool was used with which data, for what purpose. You have no evidence. Your obligations stay exactly where they were.
What does the EU AI Act mean for shadow AI?
The AI literacy duty in Article 4 has applied since 2 February 2025, although the obligation itself changed in July 2026. Providers and deployers must now take measures to support the development of AI literacy among staff and others operating or using AI systems on their behalf, taking account of their knowledge, experience, training and the context in which those systems are used.
Shadow AI creates an obvious problem with that last part: the context you need to account for may be the part of AI use you cannot see. If employees are using unapproved tools with customer data, analysing contracts or automating parts of their work through personal accounts, the people facing the most relevant risks may receive the least relevant guidance. A blanket ban may tell employees what they cannot do. It does not tell the governance function what they are actually doing.
The problem becomes more consequential as the use case changes.
Article 50’s transparency regime began applying on 2 August 2026. The Digital Omnibus changed the high-risk timelines rather than generally postponing Article 50. Article 50(2) has a narrower transition: relevant generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with its machine-readable marking requirement.
The high-risk regime now applies from 2 December 2027 for Annex III systems and 2 August 2028 for systems covered through Annex I.
Most everyday shadow AI use will not fall within the high-risk regime. Where it does, however, Article 26 deployer duties can become relevant, including the requirement to retain automatically generated logs to the extent those logs are under the deployer’s control.
Article 25 introduces a different governance problem. If an organisation changes the intended purpose of a previously non-high-risk system in a way that makes it high-risk, the deployer can assume provider obligations.
An employee stretching an approved tool into a new consequential use does not automatically trigger Article 25. It can, however, leave the organisation unable to answer the questions that determine whether its position has changed: who authorised the new purpose, when the use changed, and whether the organisation knew it had changed.
This is why shadow AI cannot be reduced to a policy violation. You need enough visibility into actual AI use to know which governance and legal obligations attach to it in the first place.
Underneath all of this sits the GDPR. If an employee pastes customer data into a consumer AI account, the processing does not fall outside the organisation's responsibilities simply because the tool was never approved. The activity may sit outside the organisation's record of processing activities. The organisation may never have established the provider's role or the contractual basis for the processing, including Article 28 terms where the provider acts as a processor. The security implications under Article 32 may never have been assessed.
The organisation may therefore still have to demonstrate compliance for processing it failed to see, assess or document. A ban gives you a rule. It does not give you that evidence.
A ban gives you a rule. It does not give you that evidence.
What are the US legal risks of shadow AI?
There is no single federal instrument that makes shadow AI illegal, which is why US-headquartered companies often read their risk as lower than it is.
Trade secret protection under the Defend Trade Secrets Act requires reasonable measures to keep information secret.
A written prohibition can form part of those measures. Persistent unauthorised disclosure through unmanaged AI tools can make the operational picture much harder to defend, particularly where proprietary information has been transferred to third parties outside approved corporate arrangements.
You also made commitments to customers. Many enterprise contracts include confidentiality, security, data-use and approved-subprocessor commitments. Shadow AI can breach those commitments silently where the relevant disclosure or processing is not permitted.
The FTC can treat materially inaccurate statements about privacy or data-security practices as deceptive under Section 5. Shadow AI is not automatically an FTC violation. The exposure arises when customer-facing, contractual or public security representations do not match the organisation’s actual operational controls.
The employment side is where I would look first. When AI output starts feeding hiring, promotion or termination decisions through unapproved tools, you have an employment decision process nobody designed or documented, and one you cannot reconstruct if it is challenged. Discovery makes this worse. Litigation holds and preservation obligations become much harder to execute when relevant prompts, inputs, outputs and decision records are dispersed across unmanaged tools and personal accounts.
For a company operating across both regimes, a ban travels badly. One employee working on one customer file can sit inside EU obligations built around demonstrable accountability and US exposures that turn on evidence of actual controls. A prohibition, by itself, proves very little about either.
We aren’t discussing this hypothetically anymore. Samsung employees entered internal source code and sensitive corporate information into ChatGPT on their own initiative, rather than through a corporate tool the company had approved. It was a textbook shadow AI case, and it ended with the company restricting generative AI use.
Read shadow AI as evidence about the company, not only about the employee. When capable people repeatedly route around the approved tool, they are giving you a needs assessment for free. Perhaps the tool is too slow. Perhaps it cannot work with the data the job requires. Perhaps it does not perform the task at all. Perhaps the employee simply does not know which alternative is approved. Those are four different governance problems. Recording all four as “policy violations” throws away the distinction.
How we govern shadow AI in practice
I’ve seen enough of what tightening a ban produces. Use does not necessarily stop. Some of it simply moves beyond the records the company relies on to govern it.
Every AI governance practitioner works differently. Mine comes from three professional reflexes. The lawyer in me looks for risk, responsibility and evidence. The sociologist looks at what people actually do once a policy meets their work. The technology side asks whether the organisation has given them a usable alternative.
That changes where I start.
First, I want to know where people are leaving the approved system, and why. We map the tools actually being used, the purposes they serve, the data employees put into them and the approved alternative, if one exists. Shadow AI discovery without a needs assessment gives you a list of violations. The combination tells you whether you have a conduct problem, an access problem, a procurement problem or a badly designed control.
Then we decide what should be possible. That means assigning decision rights: who can use which tool, for which purpose, with which data class; who can approve a new use; when legal, security or another function has to enter the decision; and where human review remains mandatory. Frameworks such as ISO/IEC 42001 and the NIST AI RMF can give that structure a common reference point, but the control still has to reflect the actual use case. Summarising a public document and analysing a customer contract should not travel through the same approval path.
Where a rule matters enough, I try not to leave it as a sentence in a policy. If certain data cannot enter a system, the stronger answer is an access restriction, DLP rule or enterprise setting wherever technically possible. If a team needs an AI capability to do its work, the company needs an approved tool that can realistically perform that job. Training matters, but “please don’t paste sensitive data here” is a weak final control for a predictable behaviour.
And none of those decisions are permanent.
A low-risk tool can acquire a new integration. A provider can change its model, processing terms or retention practices. An employee can turn an approved assistant into part of a consequential decision process. Any of those changes can alter the assessment that justified approval in the first place.
So the governance system needs reassessment triggers as well as approval gates: what change reopens the assessment, who receives an incident, who can suspend use, and what has to happen when a tool leaves the organisation. Removing access, integrations, stored data and ownership is part of AI governance too. Otherwise a system can remain inside the company long after anyone has responsibility for it.
Good governance creates the right friction for the level of risk rather than the largest number of rules. Applying the same control across the whole company helps nobody. If someone is summarising a public document, three committees and four approvals only produce delay. If they’re using customer data, evaluating candidates or turning AI output into part of a real decision, the same freedom can’t extend. The low-risk path has to be fast enough that no one sees a reason to open a personal account. When risk rises, control rises with it.
That’s why shadow AI is such a valuable signal. It shows you where the risk is, and it shows you where the system you built isn’t working. If employees keep stepping outside the approved tool at the same point, recording it as a violation throws away the information. Maybe you bought the wrong tool. Maybe your access policy is stricter than the work allows. Maybe your approval mechanism can’t keep up with the pace of the job. Maybe the employee doesn’t know which tool they’re allowed to use. Each has a different fix, and answering all of them with a prohibition only makes the problem invisible.
That is the balance I try to build into AI governance: enough freedom for low-risk use to stay inside the system, and enough control for higher-risk use to remain visible, accountable and reviewable.
💬 Let’s Connect:
🔗 LinkedIn: [linkedin.com/in/nesibe-kiris]
🐦 Twitter/X: [@nesibekiris]
📸 Instagram: [@nesibekiris]
🔔 New here? Subscribe for weekly updates on AI governance, ethics, and policy! no hype, just what matters.




The supply-side number is the one worth putting into a governance plan. The Cloud Security Alliance research note of 30 May 2026 reports eight in ten employees using AI tools their organisation has not approved, while only 37 percent of enterprises have any AI governance policy at all. The same note reports that when organisations provision sanctioned tools, unauthorised use drops by 89 percent. That reverses the usual order of work. A written ban is cheap to produce and weak in effect. Buying an approved tool that actually does the top three jobs does most of the reduction. The note does not say how long that drop holds.