Select Page

A colleague showed me something recently that gave me two reactions in the space of a minute.

She’d used AI to analyse a dataset that normally takes her half a day of manual effort. Minutes, not hours, and the insights were good. My first reaction was delight. This is a person who isn’t deeply technical, who has always had to queue for IT’s help with analysis because demand for our data team always exceeds supply. She’d just served herself using our approved AI tools.

My second reaction was, to be honest, “oh no”. Because I could immediately see the other side: transactional data flowing out of governed systems into spreadsheets, analysed outside every control we’ve built, feeding decisions with numbers nobody else had verified.

Both reactions are correct. That’s the uncomfortable truth of shadow AI.

The traditional response is to pick the second reaction and prohibit. I think that’s a mistake, for a simple reason: this is going to happen anyway. The tools are on every device and embedded in every product. The real choice isn’t between shadow AI and no shadow AI. It’s between shadow AI with effective guardrails and engagement, or shadow AI without either.

So we’re taking a federated approach. We do prohibit the use of non-approved AI tools, but we make sure everyone has access to GenerativeAI tools where we have the right levels of observability and security. We have guardrails where some things must come through governed pathways, no exceptions: anything feeding regulatory reporting, anything touching customer data, anything informing a safety-critical decision. That’s the non-negotiable core. Around it sits a much larger space where we empower people to self-serve, with education about verification, clear rules about what data can go where, and an open door. Show us what you built. Tell us what you need.

The open door matters most. Every “look what I made” conversation is one that, under prohibition, would have happened in secret or not at all, often using tools that were unmonitored and unmanaged. By accepting Shadow AI will always exist and engaging those doing it without fear of punishment it teaches us where demand actually is, and where our governance may need tweaking.

Where’s the line between empower and control in your organisation? If you haven’t drawn it deliberately, your people are drawing it for you right now.