Before anyone put the words shadow and AI in the same breath, the same instinct was already loose inside office buildings, wearing older clothes. Somewhere a team kept a database built by hand on one analyst's desktop, because the official system took six weeks to add a single field and the work would not wait six weeks. A finance group leaned on a tangle of macros that no one in IT had ever seen. It held for years. Then one day it broke, and the breaking was the moment leadership discovered the thing had been carrying a real process the whole time. The tool itself was never the scandal; what unsettled people was how long it had gone unseen.
That old habit has a new engine now, one that runs faster than the last, even as the instinct underneath it stays exactly what it was.
Most executive conversations still treat AI as a question of adoption. How do we get our people to use it, and which platform should we standardize on. While that conversation happens in the room, the answer has already been settled down the hall. Adoption arrived without a memo and without anyone raising a hand in a meeting.
The numbers that exist describe absence more than activity. In its 2025 Cost of a Data Breach report, conducted independently by the Ponemon Institute, IBM found that 63 percent of the breached organizations it studied had no governance policy in place for AI, and only 37 percent ran any approval or oversight process at all. The sample matters here: every figure in that report comes from companies that already suffered a breach, so read it as a description of what went wrong in those buildings rather than a census of everyone else.1 Shadow AI, meaning the tools employees reach for without approval or oversight, turned up in one breached organization out of five, and where that shadow use ran deep it added roughly 670,000 dollars on top of an average breach cost of 4.44 million.1 IBM sells security, so read the framing with that in mind, though the fieldwork underneath it belongs to Ponemon.
What the workaround is telling you
The reflex, when a leader first meets these numbers, is to reach for discipline. Careless people, loose with company data, in want of a firmer policy and a sterner reminder. One figure seems to back the reflex up: among organizations that suffered a security incident involving AI, 97 percent lacked basic access controls around the tools.1 Read fast, that sounds like negligence on the part of employees.
Look again and it points the other way. Nobody circumvents a control that is not standing in their way. The person copying a customer record into an unsanctioned model is almost never the one who does not care about the work. It is usually the one under a deadline, trying to finish something the approved tools make slower than it ought to be. The most capable people in a building tend to find the shortest route to done, and when the official route runs long, they build a shorter one of their own.
When your best people are routing around a control, the honest first question is what that control is costing them.
Governance built for a slower technology
There is a structural reason the official route runs long, and it has nothing to do with laziness. Researchers at MIT's Center for Information Systems Research argue that generative AI needs a different approach to governance, one that manages the risk without stalling the work, and they call the answer minimum viable governance.2 My own read on why the older approach struggles is that it assumes three things this technology does not offer. A tool that holds still long enough to be assessed. Consequences you can predict before you permit it. And a volume of requests a central committee can actually work through. A model shifts character from one quarter to the next, and the number of people who want to use it outruns any review board's capacity to take them one at a time.
I spent years in agile coaching watching a version of this same collision, well before the current tools existed. A governance process built for one tempo meets work that moves at another, and the work wins every time, because the work is what keeps the lights on. I wrote earlier this summer about a rollout that was really just an email, a tool handed down from the top to people no one had asked. Shadow AI is that failure turned upside down. The tool rose up from the floor, and this time it was leadership that never got asked.
What actually closes the gap
The temptation after reading all this is to write a policy, publish it, and feel the matter handled. A policy that arrives after the behavior, and moves slower than the behavior, changes very little. People did not wait for approval the first time, and they will not wait for the second memo either. The gap does not close by forbidding the workaround. It closes when the approved path becomes faster than the workaround, and when someone in charge is willing to ask, without getting defensive, why the people doing the work felt they had to leave the building to get it done.
That question is uncomfortable, because the answer is seldom about the employees. It is about a review cycle designed for a calmer decade, and a leadership team still debating whether to permit a thing that is already open on half the laptops in the company. The exposure is real and the breach cost is real, and none of it grows smaller by pretending the adoption has not already happened. So the more useful question this week is not how do we get our people to use AI. It is a harder one. What are our people already using, and why did we make the honest path the slow one?
If this hit a nerve, it is because the deeper issue was never the tool. It is what happens to accountability when the people doing the work and the people setting the rules are running on different clocks. That gap is the whole subject of Agile Sucks! (When You Do It Wrong), where James and I get into what real ownership looks like once you stop trying to control your way to it and start earning it instead. If you want the fuller version of the argument, the book is linked just below.
Read Agile Sucks! (When You Do It Wrong) →References
- IBM Security, & Ponemon Institute. (2025). Cost of a data breach report 2025: Navigating the AI rush without sidelining security. IBM. (Findings are drawn from organizations that experienced a breach, so percentages describe that sample rather than all companies. IBM sells security products and services; the fieldwork was conducted independently by the Ponemon Institute.) https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai ↩
- van der Meulen, N., Jewer, J., & Levallet, N. (2026, March 19). Minimum viable governance for generative AI. MIT Center for Information Systems Research. (The full research briefing is restricted to CISR member organizations; only the summary framing is publicly readable, and this piece cites it only for that.) https://cisr.mit.edu/publication/2026_0319_TalkingPoints_MinimumViableGovernance ↩