ICYMI
• Should You Add a Bot to Your Board? – The risk is not that a machine joins the board, but that directors stop reading once it has.
• Is AI Blunting Your Strategy? – As strategy development relies increasingly on LLMs, true differentiation from competitors is becoming more elusive.
On 17 January 1920, the Volstead Act closed America’s saloons. The Act did not stop Americans drinking. Consumption initially fell, but illicit drinking pushed the trade underground. Illegal speakeasies grew to replace the licensed saloon trade. In June 1932 John D. Rockefeller Jr., who had poured a fortune into the temperance cause, admitted he had been wrong. Eighteen months later the country repealed the ban.
Many companies are now running a version of Prohibition, restricting which AI tools staff can use. While most allow some AI use, the most powerful and familiar models are often unavailable to employees. As with Prohibition, this creates more problems than it solves. Shadow AI, the unsanctioned and unmanaged use of AI by employees, is not Shadow IT with a new badge, but something far more dangerous.
Shadow IT versus Shadow AI
A long-recognised issue, Shadow IT exists when staff reach for unsanctioned technology tools. Typically, this is born not of malice but rather from frustration at not being provided with the right tools for the job. For example, a colleague on a deadline may use an unsanctioned file transfer tool to send a large file to a supplier, if the corporate email system limits the size of attachments.
Shadow AI is a newer and faster-growing threat. Many employees already use AI both in their personal lives and at work. Meanwhile, most organisations have introduced strict limitations on which AI can be used. In Littler’s 2024 C-suite survey, 44 per cent of respondents said their organisation had a generative-AI policy, of which 55 per cent restricted use to specific groups or purposes.
If the enterprise restricts access to AI tools, or provides access to less capable AI models, the temptation to log in to a personal account may overpower any concerns about a policy breach.
Shadow AI is not restricted to chatbots such as ChatGPT. Software engineers may reach for coding tools, designers for auto-generators and recruiters for candidate-screening tools. Harder to spot are browser plug-ins that provide access to a suite of AI models. Finally, there are citizen-developed tools, where employees use vibe-coding platforms to build bespoke tools.
Shadow AI is already a real problem. Netskope’s 2026 report found that 47 per cent of people using AI at work route through personal accounts. And Shadow AI introduces new categories of risk that go well beyond the known risks of Shadow IT.
Exfiltration
The first risk presented by Shadow AI is exfiltration of data to unauthorised third parties. Most company-approved systems have built-in controls that flag bulk data transfers. No such controls exist when the system is unauthorised.
Shadow AI amplifies that risk, because (unlike conventional software), AI tools can be improved by training on user data, so tool providers have incentives to collect data. In many consumer tools, data sharing is enabled by default.
Infiltration
The second risk of Shadow AI is infiltration, and it comes in two forms. The first form is found in new classes of malware. LayerX catalogued at least sixteen Chrome extensions posing as ChatGPT tools and designed to steal identities. IBM’s 2025 analysis found that, among breached organisations, 20 per cent had an incident involving Shadow AI.
The second, subtler form of infiltration is the entry of incorrect or biased AI output into decision flows, as I described in The Plausibility Crisis. A 2025 study by KPMG and the University of Melbourne found that 57 per cent of workers admit to hiding their use of AI and presenting its output as their own. Sanctioned tool output can be checked and audited, but Shadow IT output cannot.
Subversion
The third risk of Shadow AI removes the human from the loop entirely. Autonomous agents now hold credentials of their own, including API keys. These risks can be managed with appropriate controls. But unsanctioned agents bypass them all.
Most organisations have no grip on this. CyberArk counted 82 machine identities for every human, 42 per cent of them with privileged access, and reports that 47 per cent of organisations cannot secure their Shadow AI usage.
Espionage
A fourth concern is potential exposure to foreign legal regimes and state actors. Data hosted by Chinese providers may be subject to PRC national-security obligations, leading many firms to block Chinese models including DeepSeek. Shadow AI imposes no controls on data residency, which may be obscured by model brokers that route requests across hundreds of models. On OpenRouter, one such broker, Chinese open-weight models averaged 13 per cent of weekly token usage.
Bans are not the answer
It is tempting to try to reduce risks through stronger bans. But the evidence suggests that doesn’t work. In Software AG’s 2024 survey, 46 per cent of staff said they would keep using personal AI tools even if forbidden outright. Senior staff are the most likely to ignore policy, with 69 per cent of the C-suite agreeing that the speed was worth the risk, according to a 2025 BlackFog study.
Firms are now moving away from blanket bans. Cisco’s reports the share of organisations with bans or strict limits on use of GenAI tools falling from 28 per cent to 7 per cent year on year.
The challenge for organisations, then, is to make approved use easier, safer, and more observable than the unofficial route.
Getting the balance right
Following Prohibition, the United States did not give up on managing alcohol. It moved to licensing, taxation, and inspection. Firms need the same shift in posture towards AI, adopting a balanced strategy that unleashes the technology’s value while managing the risks set out above. Six moves make up that strategy:
1. Maintain a live picture of which tools and models are in use, through which accounts, and which jurisdictions they reach.
2. Compete with Shadow AI by providing equally capable AI tools. People abandon the sanctioned path when the tools are weaker than those available through a personal account.
3. Place controls where the work happens and scale them to the risk. Brokers can route around firewalls, so verification belongs where AI output enters a decision or an agent takes action. A marketing brainstorm need not face the same scrutiny as an autonomous agent with database access.
4. Treat the non-human actors as actors. Agents that hold credentials need their own identities and permissions scoped to the task.
5. Control the supply chain, not just the end-user. Contract carefully with providers over how your data is handled.
6. Strengthen accountability. Name an executive owner and treat the whole thing as a standing capability with adequate budget and regular reviews.
Monday Morning Actions for Executives
• Request an audit. Understand which AI tools and models are in use, through which accounts.
• Close the capability gap. Upgrade models so that staff are not tempted into the shadows.
• Inventory the agents. List every non-human identity with the access it has.
• Offer an amnesty. Let people declare the tools they already use, without penalty.
Questions for Board Members’ Back Pockets
• Do we know which AI tools our people actually use, through which accounts, and which models and jurisdictions they reach?
• Are our sanctioned tools as capable as those we have banned?
• When AI output enters a decision, who verifies it?
• Do our access controls extend to the agents now acting on our behalf?
Just as Prohibition drove drinking underground, AI bans drive usage into the shadows. A more nuanced approach can unleash AI’s power without creating new risks.
Footnotes & Sources
• Source caveat. Several figures below come from vendor telemetry or commissioned surveys, so the precise percentages should be read as directional rather than universal.
• Prohibition. The Eighteenth Amendment and National Prohibition (Volstead) Act took effect on 17 January 1920; the Twenty-first Amendment repealed Prohibition in December 1933. John D. Rockefeller Jr., a major funder of the temperance cause, reversed his position in a public letter published in the New York Times on 7 June 1932, writing that “respect for all law has been greatly lessened.” Alcohol consumption initially fell, but enforcement failures pushed the trade underground. New York speakeasy estimates range widely, from about 20,000 to 100,000.
• Littler, Generative AI in the Workplace (2024 survey of 330+ C-suite executives). 44% had a generative-AI policy, up from 10% in 2023; of those, only 3% prohibit generative AI entirely, while 55% restrict AI tools to specific groups.
• Netskope, Cloud and Threat Report 2026 (telemetry, October 2024 to October 2025). 47% of AI users access via personal or unmanaged accounts; generative-AI data-policy violations more than doubled. Netskope sells data-loss-prevention tooling.
• OpenAI data controls. OpenAI says it does not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or the API platform for training by default. OpenAI’s Help Center says ChatGPT Free, Plus and Pro users in personal workspaces have data sharing enabled by default, but can opt out for new conversations.
• Malicious AI browser extensions. LayerX Research identified at least 16 malicious Chrome extensions posing as ChatGPT tools and stealing session tokens for connected services such as Slack and GitHub. OX Security (29 December 2025) separately identified two Chrome extensions impersonating a legitimate AI sidebar, more than 900,000 installs between them, exfiltrating users’ ChatGPT and DeepSeek conversations and open-tab URLs to attacker-controlled servers; one carried Google’s ‘Featured’ badge. OX Security and LayerX sell security products.
• IBM, Cost of a Data Breach Report 2025 (Ponemon Institute; 600 organisations; breaches March 2024 to February 2025). High Shadow AI exposure added $670,000 to the average breach; 20% suffered a breach due to incidents involving Shadow AI. Separately, among organisations reporting an AI-related breach involving AI models or applications, 97% lacked proper AI access controls. IBM sells AI-governance and security products.
• University of Melbourne and KPMG, Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025. Survey of 48,000+ workers across 47 countries. 57% admit hiding their use of AI at work and presenting AI-generated content as their own; 66% do not evaluate AI outputs for accuracy; 48% admit using AI in ways that breach company policy, including uploading sensitive company information into public tools. Self-reported.
• CyberArk, 2025 Identity Security Landscape (Vanson Bourne; 2,600 security decision-makers; organisations of 500+ staff; released April 2025). 82 machine identities for every human; 42% with privileged access; 68% lack identity security controls for AI and 47% say they cannot secure their Shadow AI usage. CyberArk sells identity-security tooling.
• Netskope, Cloud and Threat Report: Generative AI 2025 (telemetry across 3,500+ organisations). At DeepSeek’s peak, 91% of organisations had users attempting access and 75% blocked it entirely; about 43% still block it in the 2026 report. Netskope sells data-loss-prevention and blocking tooling.
• OpenRouter, State of AI 2025 (with Andreessen Horowitz; about 13 months to November 2025; 300+ models, 60+ providers). Chinese open-weight models averaged 13% of weekly tokens, peaking near 30% in some weeks. Separate 2026 snapshots reported much higher shares among the top-used models; the figures use different denominators.
• PRC National Intelligence Law (2017, amended 2018), Article 7 (China Law Translate). Requires organisations and citizens to “support, assist and cooperate with” state intelligence work. Legal scholar Jeremy Daum argues the provision lacks an enforcement mechanism and is bounded by “in accordance with law.”
• BlackFog and Sapio Research (fieldwork November 2025; 2,000 respondents, UK and US, firms of 500+ employees). 49% use unsanctioned AI; 69% of the C-suite said speed outweighed privacy and security. BlackFog sells anti-data-exfiltration tooling.
• Cisco 2026 Data and Privacy Benchmark Study (9th edition; 5,200+ professionals; fielded September 2025). The share of organisations reporting outright bans and/or strict limits on data entry into GenAI tools fell from 28% to 7% year on year, a 21-point drop. The study’s chart groups outright bans with limits on data entry. Cisco sells security and AI-governance products.
• Software AG, 2024 (6,000 knowledge workers, US, UK, and Germany). 46% would continue using personal AI tools even if banned outright. Software AG is a software vendor.

