WRWriting

Shadow AI Is Just Shadow IT With Better Marketing

Twenty-two years of IT operations taught me one eternal truth: users route around slow IT. Now it's source code and patient data pasted into browser tabs. Same pattern, higher stakes, and the old answers still apply.

AI / CybersecuritySeptember 23, 20269 min read

A dark corporate office at night with a locked glowing front door, while luminous streams of data flow out through an open side door into floating AI chat windows waiting in the shadows.

Twenty-two years in IT operations teaches you a small number of eternal truths. Here is one of them: users will always route around IT.

It was true when sales started expensing Dropbox because the file server took three days and a ticket to share a folder. It was true when marketing ran the company newsletter from a personal Gmail account because the approved platform required a change request. It was true when half the hospital carried a personal phone with patient photos on it because the secure messaging app took eleven taps to send one picture. The technology changes. The behavior does not.

Now the behavior has a new name, shadow AI, and the industry is treating it like an unprecedented crisis. It is not unprecedented. It is shadow IT with better marketing. I have watched this movie three times. I know how it ends, and I know which responses work.

The eternal truth of IT operations

Every shadow IT wave follows the same script. First, a tool appears that is obviously useful and obviously outside the approved stack. Second, adoption spreads faster than governance can respond, because the tool solves a real pain and the official alternative is slower, worse, or nonexistent. Third, security discovers the scale of it and panics. Fourth, leadership demands it be blocked. Fifth, blocking fails, because the tool is now load-bearing for actual work. Sixth, and this is the part everyone forgets, the organization quietly sanctions a version of it, builds guardrails, and moves on.

Dropbox went through all six stages. So did personal smartphones, consumer messaging apps, and SaaS sprawl generally. Each time, the security team learned the same lesson: you cannot govern what you cannot see, and you cannot block what the business has already decided it needs. The winning move was never prohibition. It was discovery, then a sanctioned alternative good enough that the shadow version withered, then proportional guardrails around the sanctioned path.

Shadow AI is at stage three right now. The panic is underway. Whether organizations reach stage six gracefully or learn it the hard way is the open question.

The same pattern wearing a new interface

The mechanics are identical to every previous wave, just faster. An employee has a deadline. The approved AI tool, if one exists, requires a request, a license, a training module, or simply does not do the thing they need. So they open a browser tab, paste in the thing, and get the answer. The thing they paste is the difference this time: it is not a lunch order. It is source code, revenue figures, acquisition targets, compensation data, customer records with PII, product roadmaps, pending litigation details. In my world, it is patient data.

This is the part where the stakes genuinely are higher than the Dropbox era, and I want to be honest about that rather than force the analogy further than it goes. When someone put a file in Dropbox, the risk was where the data sat. When someone pastes data into an AI tool, the risk is what the tool does with it: retained for training, logged, subpoenaed, breached, or simply sitting on infrastructure the company has no contract with and no visibility into. The data does not just leave the building. It enters someone else's product.

And the tools have grown teeth. This is no longer just copy-paste into a chatbot. The 2026 State of Agent Security report analyzed 500 MCP servers, the connectors that give AI agents hands, and found half of them can execute shell commands on the host, 62 percent can read local data and reach the internet in a single package, and two in five hold the full set: command execution, file access, and network egress together. Individually, each capability is unremarkable. Combined, the report warned, they form the exfiltration bridge a prompt injection payload chains into a complete attack. The shadow AI problem is merging with the agentic AI problem, and the blast radius is growing accordingly.

The numbers are not subtle anymore

For a while, "shadow AI" was a phrase security teams used to gesture at a vague worry. In 2026 it became a measured category, and the measurements are stark.

Verizon's 2026 Data Breach Investigations Report found regular AI use on corporate devices tripling in a single year, from 15 to 45 percent of employees, and shadow AI has become the third most common non-malicious insider action in breach data. Salesforce's 2026 workforce survey put the broader number at 67 percent of employees using AI tools at work in some form, against only 18 percent of organizations with a formal AI security policy. Two-thirds of the workforce is doing it. Fewer than one in five organizations has written down what doing it safely means.

The visibility gap is the real story. One 2026 analysis found the average enterprise has 14 distinct AI tools in active use, of which IT knows about four or five. Another found 80 percent of AI tools (browser extensions, MCP servers, personal accounts) run with no IT oversight at all, even as nearly 80 percent of traditional SaaS is authorized. Shadow AI is now outpacing shadow IT at the very moment IT believes it has SaaS sprawl under control. Small and mid-size companies average around 414 unsanctioned AI tools per 1,000 employees. The organizations with the fewest resources to vet them are running the most.

And the data flowing through the blind spot is not trivial. Cyberhaven's 2026 research found the average employee inputs sensitive data into an AI tool roughly once every three working days. An industry consortium briefing put it more bluntly: 63 percent of employees who used AI tools in 2025 pasted sensitive company data into personal chatbot accounts, and 86 percent of organizations have no visibility into their AI data flows. Gartner found 69 percent of organizations already suspect employees are using prohibited public generative AI tools. The DTEX/Ponemon 2026 report puts the average annual cost of insider-risk incidents at $19.5 million, up 20 percent in two years. Shadow AI did not invent insider risk. It gave every employee a frictionless new channel for it.

The plot twist is in the C-suite

Here is the finding that should end the "rogue employee" framing forever. A 2026 TrustedTech survey of 2,001 UK and US employees found that 65 percent of senior decision-makers use shadow AI tools, and at C-level, the number jumps to 73 percent. Only 31 percent of rank-and-file employees admit to it. The most frequent users of unauthorized AI tools are not junior staff cutting corners. They are the executives.

Read that again, because it inverts the entire governance conversation. The people signing the acceptable-use policies are the biggest violators of them. A VP quoted in the research put it plainly: if your governance strategy is built around monitoring junior staff, you are pointing the telescope in the wrong direction. The exposure is concentrated at the top, which is exactly where the most sensitive data lives. Board materials, M&A discussions, compensation decisions, unannounced financials: the data executives paste into personal AI accounts is the data that moves markets and triggers breach notifications.

This is not an awareness problem. It is a trust and convenience problem. Fifty-six percent of decision-makers said they were concerned about shadow AI in their organizations, and used it anyway. They are not confused about the policy. They have decided the policy costs more than it protects. That is the market signal IT should be reading: when the C-suite routes around you, the problem is not the users. It is the offering.

Why blocking always fails

The instinct, at stage three of every shadow IT wave, is prohibition. Block the domains. Ban the tools. Write a stricter policy. I have watched this fail on a loop for two decades, and the data says it is failing again: a PagerDuty survey found 66 percent of office professionals at large companies used AI tools despite believing it was against company policy. Two-thirds looked at the ban and kept typing.

Blocking fails for three reasons, and they are the same three as always. First, the tools are genuinely useful. Prohibition asks people to be less effective at their jobs, which is not a durable ask. Second, enforcement is asymmetric: IT can block the corporate network, but it cannot block the personal phone, the home laptop, or the browser tab that looks like any other HTTPS traffic. Third, and most important, blocking drives the behavior underground, where you lose the one thing you actually need: visibility. An employee using a sanctioned AI tool with logging and DLP is a managed risk. An employee using a banned tool on a personal account is an invisible one. The ban does not reduce the risk. It reduces your knowledge of the risk.

There is a healthcare version of this that I have lived. Clinicians will always choose the workflow that lets them care for the patient in front of them. Tell a nurse she cannot use the fast tool and she will not stop. She will hide it. Every guardrail that ignores workflow reality becomes a secret. In regulated environments, the shadow is more dangerous than the tool.

The old answers still apply

The good news is that we have a playbook. It is the same one that tamed SaaS sprawl, and it has three parts.

Discovery before governance. You cannot govern what you cannot see. The first investment is visibility: CASB-style discovery for AI tools, browser-level telemetry, DLP tuned for AI endpoints. The 86-percent-no-visibility number is the emergency, not the usage itself. Most organizations are not choosing to accept this risk. They do not know they have it.

A sanctioned alternative good enough to win. This is the Dropbox lesson. Dropbox did not die because IT banned it; it withered where organizations deployed an enterprise file-sharing tool that was actually pleasant to use. The sanctioned AI path has to be the path of least resistance: provisioned accounts, SSO, data boundaries, DLP, retention controls, and fast approval. Every day the sanctioned path requires a ticket and the shadow path requires a browser tab, the shadow path wins. Make the safe road the fast road.

Proportional guardrails, not blanket bans. Not all AI use carries the same risk. Summarizing a public document is not pasting patient data. A tiered approach (open use for low-sensitivity work, monitored use with DLP for internal data, blocked or heavily gated use for regulated data) respects both the reality of the work and the reality of the risk. The 92-percent statistic is instructive here: of organizations that suffered an AI-related breach, 92 percent had no proper AI access controls in place. The failure was not too little blocking. It was no architecture at all.

There is a fourth part, and it is the uncomfortable one: the C-suite has to follow the same policy. A governance regime the executives exempt themselves from is not governance. It is theater, and the workforce can tell the difference. The TrustedTech finding is an opportunity disguised as an embarrassment: get the executives onto the sanctioned platform first, and adoption follows authority.

My takeaway

Shadow AI is not an AI problem. It is the same IT governance problem I have watched cycle for twenty-two years, wearing a new interface. Users route around friction. Data follows the workflow. Prohibition creates invisibility. The sanctioned path has to be the easy path. None of this is new, and that is precisely the point.

What is new is the speed and the stakes. SaaS sprawl took a decade to reach the scale shadow AI hit in two years. The data in question is more sensitive, the tools retain more of it, and the newest connectors give the tools hands (file access, shell execution, network calls) that turn a data leak into a system compromise. The pattern is familiar. The blast radius is not.

The organizations that learned the shadow IT lesson have the playbook already: discover, sanction, tier the guardrails, and make the safe path the fast one. The organizations that did not learn it are about to pay the tuition again, this time with training data instead of file shares.

I know which group I would rather be in. We have done this before. There is no excuse for doing it badly a fourth time.