Shadow AI & unsanctioned use

What employees are already running that nobody approved.

19documents on this topic
14organizations represented
3issues named
9sourced citations
2sourced statistics

The state of it

One of 7 topics within Governance & oversight.

This is the thinnest topic in the research - 19 documents from 14 organizations - and the thinness is itself worth stating plainly. Shadow AI is mentioned across the tier-1 material almost entirely in passing, as a risk to note rather than a problem anyone has sized, surveyed or built a programme around. That is a gap in the evidence, not a finding that the problem is small.

What is here points in one direction. The Institute of Directors puts 86% of businesses running AI somewhere the board cannot see, and 80% of boards with no way to audit their own use of it. EY describes the specific mechanism - employees pasting customer data or proprietary code into unsecured tools. Deloitte, unusually, frames it first as a spend problem: untagged, unchargeable consumption building unchecked before anyone treats it as a security matter.

The Cloud Security Alliance offers the most useful counter-intuitive point. Its argument is that formalized governance is what prevents shadow AI, because it makes adoption structured rather than restricted - restriction being what produces the behaviour in the first place.

The issues, by agreement

How many independent organizations name each issue as a problem. An issue is only as real as the number of separate publishers that identify it, so the count is the ranking. Bars are organizations, not documents. Where the count reads ours, no publisher here states the issue and the analysis is our own.

Who takes which position

The chart above counts positions; this shows whose they are. Read down a column for what one organization holds across the whole topic, and across a row for who lines up on one issue. Where a cell carries more than one position, the strongest is shown and the rest are in the tooltip.

Ddisputes it Qqualifies it Nnames it as a problem Pproposes a fix
Shadow AI & unsanctioned use: 3 issues against the 5 organizations cited on them. The number under each name is how many of these issues it is cited on.
Issue Anthropic · 2 Cloud Security Alliance · 2 Deloitte · 2 EY · 1 Institute of Directors · 1
Most organizations are already running AI the board has never seen N N N N N
Blocking tools produces unsanctioned use rather than abstention N N N · ·
It shows up as untracked spend before it shows up as a breach · · · · ·

A dot means this organization is not cited on that issue. It does not mean they are silent on it: an organization is cited where its document takes a position we could locate, and the absence of a citation is the absence of a finding, not a finding of absence. Who is represented lists everyone working on this topic, including those not cited above.

Where they disagree

No contradictions recorded on this topic yet.

The issues in full

Each issue carries the organizations that name it, the numbers behind it, and the remedies proposed - with the concrete steps under each. Every citation points at a section of a named document, so any count here can be checked.

Issue 015 organizations name itnewest evidence Jul 2026

Most organizations are already running AI the board has never seen

Use has outrun visibility. The systems under governance and the systems in use are different sets, and nobody has measured the difference.

80%Boards with no process to audit their use of AIInstitute of Directors · Jan 2022
86%Businesses using AI without the board being awareInstitute of Directors · Sep 2025
How to fix it — 1 approach, 3 steps

Ask, without penalty, before you go looking

An amnesty survey finds more than telemetry does, because the tools people use personally never touch corporate networks.

Done when A no-penalty survey of the AI tools staff use for work, including personal accounts, has been cross-checked against SaaS telemetry and expense claims, and the total including the unsanctioned share has gone to the board once in full.

  1. Run a no-penalty survey asking staff which AI tools they use for work, including personal accounts.0-30 daysCIO
  2. Cross-check against SaaS and network telemetry and expense claims; the delta is the shadow estate.0-30 daysCISO
  3. Report the total to the board once, in full, including the unsanctioned share.30-90 daysCIO
The evidence — 5 documents
OrganizationDocumentPosition
AnthropicFrontier lab · July 2026Anthropic’s CISO guide to agentic AIOur reading Names the likeliest breach as a leak created by personal agents stitching unrelated systems together unsupervised, treating the shadow estate as an architecture rather than a rule broken.Governing internal risksnames it
Cloud Security AllianceInstitution · December 2025The State of AI Security and GovernanceOur reading Defines shadow AI as unsanctioned or unmanaged use introducing compliance and data privacy risks, and treats its rise as a live governance concern.Governance as a countermeasurenames it
DeloitteConsultancyNavigating AI spend dynamicsOur reading Describes shadow AI costs building unchecked through unsanctioned solutions in the absence of tagging and chargeback.Visibility into spendnames it
EYConsultancy · October 2025Five forces redefining CTO mandatesOur reading Describes the everyday mechanism - customer records and source code pasted into whatever tool is to hand - compounding what external services already expose.Data exposure from AI usenames it
Institute of DirectorsInstitutionAI in the boardroomOur reading Puts 86% of businesses running AI somewhere the board cannot see, and an IoD members' survey finding 80% of boards with no process to audit their use of AI.Executive summarynames it

Issue 023 organizations name itnewest evidence Jul 2026

Blocking tools produces unsanctioned use rather than abstention

The instinctive control - cut off access - moves the behaviour somewhere with no logging, no data controls and no visibility at all.

The Cloud Security Alliance makes the argument most directly: robust governance is what helps organizations avoid the rise of shadow AI, because formalizing it makes adoption encouraged and structured rather than restricted. This sits in direct tension with the most common enterprise response recorded in the regulatory material, where shutting off access to specific tools is a standard reaction to uncertainty.

How to fix it — 1 approach, 3 steps

Make the sanctioned route the easiest route

Shadow use is a demand signal. The durable control is a permitted path that is faster than the unsanctioned one.

Done when The top three unsanctioned tools and the task each serves are identified, a sanctioned equivalent with logging and data controls is available with immediate access, and migration off each is measured rather than assumed.

  1. Identify the top three unsanctioned tools from the inventory and what task each serves.0-30 daysCIO
  2. Provide a sanctioned equivalent with logging and data controls, and make access immediate.30-90 daysCIO
  3. Measure migration off the unsanctioned tool; if it does not move, the sanctioned route is worse.90-180 daysCISO
The evidence — 4 documents
OrganizationDocumentPosition
AnthropicFrontier lab · July 2026Anthropic’s CISO guide to agentic AIOur reading Sets out the trade without hedging: refuse the request and the work moves somewhere unmonitored that cannot be turned off; approve it without controls and you get incidents. Written by a frontier lab's own deputy CISO about internal practice.Opening: saying no produces shadow adoptionnames it
Cloud Security AllianceInstitution · December 2025The State of AI Security and GovernanceOur reading Argues formalized governance makes AI adoption encouraged and structured rather than restricted, reducing the pull toward unsanctioned use.Governance as a countermeasure to shadow AInames it
DeloitteConsultancy · August 2024State of generative AI in the enterpriseOur reading Records shutting off access to specific generative AI tools as one of the risk-related actions executives described, drawn from interviews rather than measured across a sample.How organizations are preparing for regulatory changesnames it
DeloitteConsultancyNavigating AI spend dynamicsOur reading Proposes caps, alerts and limits as the discipline mechanism - constraining consumption rather than prohibiting use.Guardrailsproposes a fix

Issue 03Our analysis

It shows up as untracked spend before it shows up as a breach

Unsanctioned consumption accumulates on cards and in cloud bills long before it causes a security incident - which makes finance an earlier detector than security.

How to fix it — 1 approach, 3 steps

Tag consumption and charge it back

Chargeback converts invisible consumption into a line somebody owns, which surfaces the estate without a security investigation.

Done when All AI consumption is tagged by business unit with chargeback enabled, budget alerts and usage caps make unexplained growth visible within a month, and untagged spend is reviewed as a shadow-AI indicator rather than an accounting error.

  1. Tag all AI consumption by business unit and enable chargeback.0-30 daysCFO
  2. Set budget alerts and usage caps so unexplained growth is visible within a month.30-90 daysCFO
  3. Review untagged or unattributable spend as a shadow-AI indicator, not an accounting error.ongoingCFO
The evidence — 0 documents
OrganizationDocumentPosition

Who is represented

This dossier is drawn from 16 organizations working on the subject, 5 of which are cited directly in the issues above.

Consultancy — 7

Deloitte 2 EY 1 McKinsey & Company 3 Accenture 1 Gartner 1 Genpact 1 Infosys 1

Institution — 3

Cloud Security Alliance 3 Institute of Directors 1 FinOps Foundation 1

Hyperscaler — 3

Microsoft 2 Google Cloud 1 IBM 1

Frontier lab — 1

Anthropic 1

Vendor — 1

Palo Alto Networks 1

Other — 1

Dario Amodei (Anthropic) 1