
Shadow AI has become something of a buzzword and much of the content has focused on employee behaviour. Are people using unauthorised AI tools? What data are they uploading? How can companies stop them? However, evidence suggests the debate is no longer if employees are using unauthorised AI tools. It’s whether organisations understand the extent to which they are already embedded in everyday work.
The scale of that shift is difficult to ignore. Analysis conducted for Omnissa’s State of Digital Workspace 2026 report found that AI assistants were the fastest-growing application category in the workplace last year, increasing by almost 1,000%. Growth at that level tells a compelling story. That AI adoption is no longer happening through carefully controlled pilots or procurement programmes. It is happening organically, driven by employees finding practical uses for these tools in their day-to-day work.
Recent research from Thomson Reuters reinforces the point. Nearly half of professionals using AI at work said they would continue doing so even if their employer explicitly prohibited it. Combined with findings from Adaptive Security that 80% of employees already use unapproved generative AI applications at work, it paints a picture of a workforce that has moved beyond the permission stage.
The path of least resistance
The problem is that most technology governance frameworks were built for a different era. An era when software procurement followed a predictable path. IT evaluated applications, security teams assessed risk, contracts were signed and employees used what they were given. The process could take weeks or months, but the organisation maintained control. That model depended on technology moving at the speed of governance.
Today, an employee can discover a new AI tool on Monday morning, create an account before lunch and make it part of their workflow by the end of the day. There is no procurement cycle, no formal evaluation process and often no interaction with IT at all. The distance between discovering a tool and using it productively has collapsed.
While this can be perceived as non-compliance, the reality is that employees are simply choosing the path of least resistance and adopting the tools they believe help them work most effectively.
Policy: The fine line between pragmatic and problematic
Unsurprisingly, many organisations have responded with tighter controls, broader restrictions and more formal approval processes. In some cases, access to public AI tools has been limited, uploads blocked and additional governance layers introduced before employees can experiment with emerging models. The instinct is understandable because AI introduces genuine risks. Sensitive information can be exposed, intellectual property can be shared inadvertently and regulatory obligations can be compromised. Research from Okta shows that more than half of businesses report experiencing an AI-related security incident or near miss during the past year.
Alongside those concerns sits an increasingly complex regulatory environment. The EU AI Act is beginning to reshape expectations around transparency, accountability and risk management, particularly for organisations deploying AI at scale. Yet there is a flaw in the assumption that stricter rules will solve the problem. In many organisations, governance frameworks are still being written while employees are already using AI every day.
This is leading to a ‘doom loop’ – leadership believes technology adoption happens through official channels but employees know it tends to happen through convenience. When a worker can solve a problem in thirty seconds using an external AI assistant, they are unlikely to wait three weeks for a procurement review. From an employee perspective, it’s pragmatic, not problematic.
This is why Shadow AI should be viewed as a governance challenge rather than a disciplinary one. The issue is not that employees are finding workarounds. Employees have always found workarounds. The issue is that many organisations lack visibility into what those workarounds look like, where they are occurring and what risks they introduce. Without that visibility, leaders are left managing assumptions rather than reality.
Innovation does not wait for permission
The conversation, therefore, needs to move beyond the simplistic question of whether employees should be allowed to use AI. Instead, it needs to be around understanding how AI is actually being used across the organisation. Which tools are gaining traction? Which departments are adopting them fastest? What data is being shared? Where are the genuine risks? These are observability questions, not policy questions.
The most effective governance models are increasingly focused on visibility first and enforcement second. They recognise that understanding behaviour creates better outcomes than attempting to prohibit it. That approach also acknowledges a basic truth about modern work. That innovation does not wait for permission.
Rather than treating every instance of Shadow AI as a policy violation, leaders should pay closer attention to what that behaviour reveals. In many cases, employees are using AI because it helps them complete tasks faster, reduce repetitive work or access information more efficiently. Those are outcomes most organisations actively want. The challenge, therefore, is to harness that behaviour and understand it well enough to encourage the benefits while managing the risks.
What Shadow AI is really telling us
For years, organisations assumed technology adoption could be directed from the centre. Shadow AI suggests something different. Adoption now happens at the edge of the organisation, driven by employees solving immediate problems long before governance frameworks catch up. It is not evidence that employees have stopped following the rules. It is evidence that the rules no longer reflect how work gets done.



