3 Comments
User's avatar
Marius Laurusevicius's avatar

The supply-side number is the one worth putting into a governance plan. The Cloud Security Alliance research note of 30 May 2026 reports eight in ten employees using AI tools their organisation has not approved, while only 37 percent of enterprises have any AI governance policy at all. The same note reports that when organisations provision sanctioned tools, unauthorised use drops by 89 percent. That reverses the usual order of work. A written ban is cheap to produce and weak in effect. Buying an approved tool that actually does the top three jobs does most of the reduction. The note does not say how long that drop holds.

Nesibe | AI Governance Expert's avatar

Agreed. Demand-side controls only go so far when employees can access a rapidly expanding supply of tools outside approved channels. A credible governance plan has to address discovery, procurement, identity, data boundaries, and usable alternatives together.

Marius Laurusevicius's avatar

Article 4 already puts one thread of that list on a statutory footing. Providers and deployers must take measures on AI literacy for their staff and other persons dealing with the operation and use of AI systems on their behalf. That scope follows the person and the task, not the approved tool register, which is where shadow use actually sits. The same article says nothing about discovery or procurement, so those two stay a management choice rather than a legal duty.