AI governance

Shadow AI has become the quietest open secret in modern workplaces

Employees are not waiting for a strategy. They are already pasting sensitive information into public AI tools to get their work done. Why it happens, what it really puts at risk, and how to make the safe way the easy way.

Shadow AI has become the quietest open secret in modern workplaces, and right now it is reshaping how knowledge work gets done faster than most leadership teams realise. Employees are not waiting for strategy decks or steering committees; they are already piping sensitive information into public tools to get their jobs done, often with zero guardrails and a dangerously optimistic view of the risks.

What shadow AI actually looks like

Shadow AI is simply employees using unapproved AI tools to get work done, outside the visibility and control of IT or security teams. It is the AI-era sequel to “shadow IT”, but with higher stakes because what moves into these tools is not just files or workflows – it is live customer data, product roadmaps, pricing models and contracts.

The scale is no longer marginal behaviour at the edges of the organisation. Multiple recent studies show that the majority of employees who use AI at work are doing so via unapproved tools, often because official options feel slow, clunky or locked behind process. In other words, this is not a technology problem first; it is a product-market fit problem between the tools companies provide and the jobs employees are actually trying to get done.

Why smart people take bad risks

On the surface, the behaviour is rational. Knowledge workers are drowning in information and administrivia, and AI gives them an instant speed boost. Summarise this report, translate that email, draft a proposal, refactor some code – all offloaded in seconds to a tool that never complains, never sleeps and rarely asks awkward questions about data classification.

Underneath that, there is a very human set of drivers:

  • Convenience beats compliance when deadlines loom and headcount is tight.
  • There is a quiet assumption that “everyone else is doing it and nothing bad has happened yet”, which creates social cover for risky behaviour.
  • Many employees genuinely do not understand how AI tools handle their inputs, or that they may be training future models with sensitive data.

Psychologists have described this as a kind of “tech optimism bias”: people systematically overestimate the upside of AI in their day-to-day work and underestimate the downside for their employer.

The risk is bigger than a data breach

The obvious concern is data leakage: confidential code, client details, HR cases and strategy documents leaving your environment and landing on external infrastructure you do not control. That alone is enough to trigger regulatory, contractual and reputational fallout, especially in regulated industries where AI usage is rapidly becoming a supervision topic for auditors and regulators.

But the more subtle risks can be just as damaging:

  • Compliance and legal exposure, particularly around GDPR and sector-specific rules, when personal or regulated data is processed in ways the organisation cannot evidence or audit.
  • Quality and reliability issues when teams ship AI-generated content that has not been properly checked, from hallucinated facts in board papers to incorrect numbers in investor decks.
  • Strategic fragmentation, where different teams quietly standardise on different AI tools, creating parallel processes, inconsistent outputs and a messy tangle of vendor risk.

The net result is a strange organisational split-screen: one part of the business is desperately trying to manage AI risk and deliver a coherent roadmap, while another part quietly builds its own informal AI stack in the shadows.

Why “just say no” will fail

It is tempting to respond with bans, blocks and scary all-hands emails. The problem is that blunt prohibition rarely survives first contact with reality. If a policy says “no AI”, but targets keep rising and headcount does not, people will route around the rules – usually with more creativity than your security team can keep up with.

Employees are not the enemy here; they are signalling a gap. When smart, capable people bypass official tools, they are telling you something important:

  • The approved stack is not intuitive enough for non-technical users.
  • The governance story is either unclear, impractical, or buried in policy documents nobody reads.
  • The value narrative (“AI will transform our business”) is disconnected from the lived experience of the average employee (“this thing just slows me down”).

Treating shadow AI purely as a disciplinary issue misses the point. It is a design problem in your AI operating model.

Brian Daly, Kunavv

Building an AI operating model people will actually use

The organisations that will win this phase of the AI shift are not the ones with the longest policy documents, but the ones that make “the safe way” also the easiest and most useful way. That means designing the AI experience with the same discipline you would apply to any customer-facing product.

A practical, grown-up approach typically has five components:

  1. Clear, task-level guidance. Move beyond generic “do and don’t” lists to concrete patterns like “You can use this tool for summarisation and translation of non-sensitive content; you must not use it for customer PII, contracts under NDA, or unpublished financials.”
  2. Approved, high-utility tools. Provide AI capabilities where people already work – in productivity suites, CRMs, ticketing systems – so they do not need to copy-paste sensitive content into random websites.
  3. Opinionated guardrails. Use technical controls (data classification, DLP, logging, access control) to constrain how AI can interact with your most sensitive systems and data.
  4. Visible leadership behaviour. When senior leaders model responsible AI usage and talk openly about both benefits and limits, it normalises “asking first” instead of quietly experimenting on live customer data.
  5. Continuous education. Short, scenario-based training that shows people real-world failure modes – from hallucinations to subtle data leakage paths – is far more effective than another compliance module.

Done well, this shifts the conversation from “don’t use AI” to “here is exactly how we use AI to do better work, safely”.

Where platforms like Kunavv fit

There is a missing layer in most AI strategies today: something that sits between the raw model providers and the messy reality of day-to-day business workflows. That layer needs to orchestrate models, centralise controls and make it easy for teams to build useful AI-driven experiences without reinventing the governance wheel every time.

Platforms like Kunavv are being built for precisely that gap. The goal is to give organisations:

  • centralised control over which AI capabilities are available, and under what data policies;
  • a secure way to expose AI to employees without sending sensitive information to unmanaged public endpoints;
  • a scalable foundation for rapid experimentation – so teams can prototype, test and deploy AI use cases quickly, while staying within a consistent governance framework.

If shadow AI is the symptom, this kind of platform approach is a big part of the cure: it lets people keep the speed and creativity they want from AI, but inside an environment the organisation can actually trust. One of our use cases shows what that looks like in practice: an internal chat where personal data is filtered out before any prompt reaches the model.

The real question for leadership

Shadow AI is not going away; if anything, the gap between formal strategy and informal reality will widen as tools become more capable and easier to access. The real question is whether leadership chooses to treat that gap as a compliance problem to suppress, or as a product problem to solve.

In practice, that means asking some uncomfortable but necessary questions:

  • Do employees know, in plain language, what is in-bounds and out-of-bounds for AI at work?
  • Are the official tools good enough that people actually want to use them?
  • Is there a clear path for teams to propose and test new AI use cases without going rogue?

Organisations that can answer “yes” to those questions will not just reduce their risk profile; they will move faster, learn quicker and turn AI from something employees sneak in through the side door into something that is deliberately woven into how the business operates.

Sources

  • BBC News coverage of employees “smuggling” AI into work and associated organisational risks.
  • Reporting and analysis on UK workplace AI adoption, productivity impact and AI strategy gaps.
  • Industry guidance on shadow AI, hidden AI tools and associated data protection and compliance risks.
  • BBC reporting on employees and organisations who are cautious or resistant about AI adoption.

About the author

Brian Daly

Co-founder and Chief Product Officer at Kunavv. More than 25 years in payments, identity and anti-fraud: building payment gateways at First Data, card-present products at Mastercard, and leading product at 4Stop through its acquisition by Jumio. Now builds Kunavv’s AI governance products, so teams can use AI without putting sensitive data at risk.

Brian on LinkedIn

First published on Brian’s Substack on . Last updated:

Keep reading

Assessment

Free AI readiness check

Twenty-three questions, about five minutes, including how AI tools reach your team today.