Insight · August 12, 2026
You cannot ban
your way out.
Most of your company already uses AI you never approved. Blocking it moves the work somewhere you cannot see. The fix is a faster sanctioned path, not a longer blocklist.
01 · The reality
The tools arrived before the policy did.
Employees reached for AI the moment it was useful, which was immediately. Adoption ran ahead of every review process built to gate it. In Verizon’s 2026 Data Breach Investigations Report, the share of employees classed as regular AI users on their work devices rose from 15 percent in the 2025 dataset to 45 percent in 2026. That is a tripling in a single year. Two thirds of that activity runs through personal accounts the company cannot see.
This is what shadow AI means. Not a rogue project. The ordinary knowledge worker pasting a contract into a chat window to summarize it, because the sanctioned tool is three approvals away and the deadline is today.
The instinct is to call this a compliance problem and write a memo. It is not. Every one of those pastes is a person trying to finish their work with the fastest tool in reach. Shame does not change that math. A faster sanctioned tool does.
02 · The cost
The invisible part is where the loss lives.
IBM’s Cost of a Data Breach 2025 report put a number on it. Shadow AI was involved in 20 percent of the breaches studied. Those breaches cost about 670,000 dollars more than the average incident, because no one could tell what data had left or where it went. Ninety seven percent of the breaches that involved AI happened at organizations with no proper access controls on it. Sixty three percent had no AI governance policy at all.
The global average breach cost actually fell that year, to 4.44 million dollars, the first decline in five years. Shadow AI ran the other way. The exposure was never the tool itself. It was the absence of any record of what the tool touched. A governed system logs the request. A shadow one leaves nothing behind.
The one line to keep
“Shadow AI is not a security failure. It is a product review your employees are running on you, one paste at a time.”
03 · Why the sanctioned path loses
Employees are not reckless. They are routing.
Every shadow AI decision is a small comparison. The person picks the path that gets the work done. When the sanctioned tool loses that comparison, it loses for reasons you can name.
01
Speed
The approved tool sits behind a request queue. The public one opens in a tab. Friction decides the winner, and friction favors the shadow.
02
Fit
The sanctioned tool does one thing well. The work in front of the person needs another. They reach for whatever covers the gap today.
03
Silence
The rules were never communicated, and often never written. In IBM’s 2025 study only 34 percent of organizations ran regular audits to detect shadow AI at all.
04
Habit
They already use the tool at home. Bringing it to work is not a decision they weigh. It is a reflex they never notice.
04 · The instinct that makes it worse
A blocklist moves the problem. It does not solve it.
The first reaction is to block the domains. It feels like control. It is not. Blocking the visible tools pushes the same behavior onto personal phones, home laptops, and accounts the company has no view into. The data still leaves. The record gets worse, because now it happens entirely off the network.
Verizon’s 2026 report already shows where this goes. Shadow AI is now the third most common insider action with no bad intent behind it, across its data loss dataset. When the report ranked what employees actually uploaded to these tools, source code came first by a wide margin. None of that stops when you block a URL. It just stops being visible.
05 · One request, two systems
The same task, governed and ungoverned.
Take one ordinary job. A manager needs a customer contract summarized. In the shadow path she pastes it into a public chat window. The summary is good. The contract now sits in a system with no agreement covering it, no log, and no way to recall it.
In the governed path she uses a tool wired to the company’s own models, with the request logged, the data kept inside the boundary, and access scoped to her role. Same summary. One of them can be audited. The other cannot even be found.
Multiply that by a company. Thousands of small requests, each one reasonable, none of them recorded. The exposure is not a single careless act. It is the sum of ordinary work happening on a path no one can see.
GOVERNED PATH · the default has to be the fast one route every AI request through one internal gateway log who asked, what data, which model, when scope access to the person's role, nothing wider allow the tools people actually want, inside the boundary
The goal is not fewer tools · it is the same tools on a path you can see
06 · The product response
Make the governed path the path of least resistance.
Governance that only says no gets routed around. Governance that ships a better default gets used. The work is a product problem before it is a policy problem. Give people one place to make an AI request. Put the approved models behind it. Log every call. Scope every permission. Then make that path faster than opening a browser tab, because if it is slower, you are back where you started.
This is where design carries the weight. The gateway has to feel like the shortcut, not the checkpoint. The logging has to be invisible to the person and complete for the auditor. The list of allowed tools has to move as fast as the tools do, or the gap reopens and the shadow returns. Governance is not a page in a handbook. It is an interface people would choose even if nobody made them.
07 · What this is really measuring
Shadow AI is a demand signal. Read it as one.
Every unsanctioned tool in your company is a vote. It tells you exactly which task people needed help with and could not get sanctioned in time. That is a roadmap. The teams that treat shadow AI as intelligence, rather than insubordination, learn what to build next. The ones that treat it as a crime learn nothing, and keep losing the same data.
The goal is not zero shadow AI. It is a company where the sanctioned path is good enough that no one needs the shadow one. You get there by watching what people reach for, then making the safe version of it the easy one.
None of this is soft. The gateway is real infrastructure, the logs are real records, the scoping is real access control. What changes is the posture. You stop policing the symptom and start building the thing people wanted, which is the only version of governance that survives contact with a deadline.
Closing
The tools are already inside. The only question is whether you can see them.
Start with one visible gateway for one team. Log every request. Make it faster than the workaround. Then widen it, until the shadow has nowhere left to be.
IBM Cost of a Data Breach 2025 · Verizon 2026 Data Breach Investigations Report · figures cited as reported by each study
Share this perspective
More insights
Adjacent perspectives.
Bttr. Field Brief
The brief Bttr. writes for senior buyers.
Monthly. One signal worth your time on Brand Operating Systems, AI search visibility, and the infrastructure buildout. No filler.