What employees are already running that nobody approved.
19documents on this topic
14organizations represented
3issues named
9sourced citations
2sourced statistics
The state of it
One of 7 topics within Governance & oversight.
This is the thinnest topic in the research - 19 documents from 14 organizations - and the thinness is itself worth stating plainly. Shadow AI is mentioned across the tier-1 material almost entirely in passing, as a risk to note rather than a problem anyone has sized, surveyed or built a programme around. That is a gap in the evidence, not a finding that the problem is small.
What is here points in one direction. The Institute of Directors puts 86% of businesses running AI somewhere the board cannot see, and 80% of boards with no way to audit their own use of it. EY describes the specific mechanism - employees pasting customer data or proprietary code into unsecured tools. Deloitte, unusually, frames it first as a spend problem: untagged, unchargeable consumption building unchecked before anyone treats it as a security matter.
The Cloud Security Alliance offers the most useful counter-intuitive point. Its argument is that formalized governance is what prevents shadow AI, because it makes adoption structured rather than restricted - restriction being what produces the behaviour in the first place.
The issues, by agreement
How many independent organizations name each issue as a problem. An issue is only as real as the number of separate publishers that identify it, so the count is the ranking. Bars are organizations, not documents. Where the count reads ours, no publisher here states the issue and the analysis is our own.
The chart above counts positions; this shows whose they are. Read down a column for what one organization holds across the whole topic, and across a row for who lines up on one issue. Where a cell carries more than one position, the strongest is shown and the rest are in the tooltip.
Ddisputes itQqualifies itNnames it as a problemPproposes a fix
Shadow AI & unsanctioned use: 3 issues against the 5 organizations cited on them. The number under each name is how many of these issues it is cited on.
A dot means this organization is not cited on that issue. It does not mean they are silent on it: an organization is cited where its document takes a position we could locate, and the absence of a citation is the absence of a finding, not a finding of absence. Who is represented lists everyone working on this topic, including those not cited above.
Where they disagree
No contradictions recorded on this topic yet.
The issues in full
Each issue carries the organizations that name it, the numbers behind it, and the remedies proposed - with the concrete steps under each. Every citation points at a section of a named document, so any count here can be checked.
Issue 015 organizations name itnewest evidence Jul 2026
Most organizations are already running AI the board has never seen
Use has outrun visibility. The systems under governance and the systems in use are different sets, and nobody has measured the difference.
An amnesty survey finds more than telemetry does, because the tools people use personally never touch corporate networks.
Done when A no-penalty survey of the AI tools staff use for work, including personal accounts, has been cross-checked against SaaS telemetry and expense claims, and the total including the unsanctioned share has gone to the board once in full.
Run a no-penalty survey asking staff which AI tools they use for work, including personal accounts.0-30 daysCIO
Cross-check against SaaS and network telemetry and expense claims; the delta is the shadow estate.0-30 daysCISO
Report the total to the board once, in full, including the unsanctioned share.30-90 daysCIO
The evidence — 5 documents
Organization
Document
Position
AnthropicFrontier lab · July 2026
Anthropic’s CISO guide to agentic AIOur reading Names the likeliest breach as a leak created by personal agents stitching unrelated systems together unsupervised, treating the shadow estate as an architecture rather than a rule broken.Governing internal risks
names it
Cloud Security AllianceInstitution · December 2025
The State of AI Security and GovernanceOur reading Defines shadow AI as unsanctioned or unmanaged use introducing compliance and data privacy risks, and treats its rise as a live governance concern.Governance as a countermeasure
names it
DeloitteConsultancy
Navigating AI spend dynamicsOur reading Describes shadow AI costs building unchecked through unsanctioned solutions in the absence of tagging and chargeback.Visibility into spend
names it
EYConsultancy · October 2025
Five forces redefining CTO mandatesOur reading Describes the everyday mechanism - customer records and source code pasted into whatever tool is to hand - compounding what external services already expose.Data exposure from AI use
names it
Institute of DirectorsInstitution
AI in the boardroomOur reading Puts 86% of businesses running AI somewhere the board cannot see, and an IoD members' survey finding 80% of boards with no process to audit their use of AI.Executive summary
names it
Issue 023 organizations name itnewest evidence Jul 2026
Blocking tools produces unsanctioned use rather than abstention
The instinctive control - cut off access - moves the behaviour somewhere with no logging, no data controls and no visibility at all.
The Cloud Security Alliance makes the argument most directly: robust governance is what helps organizations avoid the rise of shadow AI, because formalizing it makes adoption encouraged and structured rather than restricted. This sits in direct tension with the most common enterprise response recorded in the regulatory material, where shutting off access to specific tools is a standard reaction to uncertainty.
Shadow use is a demand signal. The durable control is a permitted path that is faster than the unsanctioned one.
Done when The top three unsanctioned tools and the task each serves are identified, a sanctioned equivalent with logging and data controls is available with immediate access, and migration off each is measured rather than assumed.
Identify the top three unsanctioned tools from the inventory and what task each serves.0-30 daysCIO
Provide a sanctioned equivalent with logging and data controls, and make access immediate.30-90 daysCIO
Measure migration off the unsanctioned tool; if it does not move, the sanctioned route is worse.90-180 daysCISO
The evidence — 4 documents
Organization
Document
Position
AnthropicFrontier lab · July 2026
Anthropic’s CISO guide to agentic AIOur reading Sets out the trade without hedging: refuse the request and the work moves somewhere unmonitored that cannot be turned off; approve it without controls and you get incidents. Written by a frontier lab's own deputy CISO about internal practice.Opening: saying no produces shadow adoption
names it
Cloud Security AllianceInstitution · December 2025
The State of AI Security and GovernanceOur reading Argues formalized governance makes AI adoption encouraged and structured rather than restricted, reducing the pull toward unsanctioned use.Governance as a countermeasure to shadow AI
names it
DeloitteConsultancy · August 2024
State of generative AI in the enterpriseOur reading Records shutting off access to specific generative AI tools as one of the risk-related actions executives described, drawn from interviews rather than measured across a sample.How organizations are preparing for regulatory changes
names it
DeloitteConsultancy
Navigating AI spend dynamicsOur reading Proposes caps, alerts and limits as the discipline mechanism - constraining consumption rather than prohibiting use.Guardrails
proposes a fix
Issue 03Our analysis
It shows up as untracked spend before it shows up as a breach
Unsanctioned consumption accumulates on cards and in cloud bills long before it causes a security incident - which makes finance an earlier detector than security.
Chargeback converts invisible consumption into a line somebody owns, which surfaces the estate without a security investigation.
Done when All AI consumption is tagged by business unit with chargeback enabled, budget alerts and usage caps make unexplained growth visible within a month, and untagged spend is reviewed as a shadow-AI indicator rather than an accounting error.
Tag all AI consumption by business unit and enable chargeback.0-30 daysCFO
Set budget alerts and usage caps so unexplained growth is visible within a month.30-90 daysCFO
Review untagged or unattributable spend as a shadow-AI indicator, not an accounting error.ongoingCFO
The evidence — 0 documents
Organization
Document
Position
Who is represented
This dossier is drawn from 16 organizations working on the subject, 5 of which are cited directly in the issues above.
Consultancy — 7
Deloitte 2EY 1McKinsey & Company 3Accenture 1Gartner 1Genpact 1Infosys 1
Institution — 3
Cloud Security Alliance 3Institute of Directors 1FinOps Foundation 1