1. Why AI needs governing
Shadow AI: the tools you don't know about
Shadow AI is the AI equivalent of shadow IT: staff using AI tools that the organisation hasn't approved, often on personal accounts, usually with good intentions and no malice at all. Someone is behind on a report, a free tool is one browser tab away, and the report gets finished. From their point of view, they've been resourceful.
Why it happens
Shadow AI is almost always a symptom rather than a character flaw. It happens when the organisation either hasn't provided an approved tool, hasn't told anyone what the rules are, or has made the official route so slow or restrictive that the unofficial route wins. Banning AI outright is one of the most reliable ways to create shadow AI, because the demand doesn't disappear, it just goes underground where you can't see it.
Why it matters
- You lose visibility. You can't protect data you don't know is leaving the building, and you can't answer a client or regulator honestly about how AI is used in your work.
- Consumer-tier tools on personal accounts typically lack the contractual data protection, admin controls, and audit capability of a managed enterprise agreement.
- Work product becomes tangled with personal accounts. If the person leaves, their chat history, prompts, and any uploaded documents leave with them.
- Inconsistency creeps in. Two people doing the same job apply completely different standards to what they share and what they verify.
The manager's response
Treat discovered shadow AI as information, not primarily as a disciplinary matter. It tells you where the genuine demand is. The fix is usually to provide a sanctioned alternative that's good enough that people actually want to use it, communicate the rules plainly, and make it easy to ask "is this tool okay?" and get a fast answer.
› Course contents
Why AI needs governing
The regulatory landscape
Building your AI policy and approving tools
Running AI day to day