Shadow AI is often a sign that the official tools are not good enough

Shadow AI, the unsanctioned use of AI tools by employees without approval or oversight from their organization’s IT or security teams, is usually treated as a security problem. Employees use unauthorised tools, paste sensitive data into public services, and create risks that IT teams cannot see or control.

However, Aptean’s latest research suggests another explanation worth taking seriously: shadow AI can also be a signal that the organisation’s approved tools do not meet the operational needs of staff.

The study of 1,535 business decision-makers found that 40% use AI tools at work without formal organisational approval. At the same time, 77% said general-purpose AI cannot handle the complexity of large operations, while 88% called purpose-built, industry-specific AI critical to their business. 

That does not excuse unsanctioned AI use. It changes the focus of leaders.

A workaround is often a message

When staff use an unsanctioned AI tool, they may be trying to save time, complete a task more effectively, or compensate for a gap in company systems.

For example, a planner may need help interpreting demand data, a customer-service agent may want a faster way to summarise a complex account history, while a supply-chain manager may be attempting to extract insight from a spreadsheet that no existing system makes easy to analyse.

The instinctive response is to block the tool.

That may be necessary, particularly where intellectual property, personal information or regulated data is involved. But blocking access without understanding the underlying workflow risks treating the symptom while preserving the cause.

Shadow AI is often a form of unofficial product research.

Governance still matters

Aptean’s findings show the problem is not simply one of employee behaviour. While 96% of respondents said a formal AI governance framework is necessary, 36% had not established one. Three quarters described a lack of governance as a major obstacle to AI success.

That leaves organisations in an uncomfortable position. 

Employees are adopting tools independently, while the organisation has not yet decided which uses are permitted, who owns the decisions made by AI, or how outputs should be reviewed.

The governance gap becomes more serious as AI moves beyond drafting and summarising into forecasting, planning and customer-facing decisions. Aptean found that 88% of organisations already allow AI to make at least some decisions without human sign-off.

Better tools, clearer boundaries

The answer is not to approve every AI product employees discover. Nor is it to assume that a generic corporate chatbot will meet every operational need.

Organisations should identify where shadow AI is appearing, examine the task employees are trying to complete and decide whether a purpose-built tool can solve it with the right controls. This should include data-access rules, human oversight, audit trails and clear accountability.

We have previously examined why shadow AI is becoming the bigger enterprise risk and what shadow AI means for organisations.

The lesson is clear. 

Shadow AI is a governance problem. But it can also reveal where the official technology stack is falling short.

About The Author

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.