Do You Have Shadow AI in Your Organisation? Learn From It.

Shadow AI grows in the gap between what employees need and what organisations provide.

What Is Shadow AI?

Shadow AI refers to the use of artificial intelligence tools, most commonly large language models (LLMs) such as ChatGPT, Gemini, and others, by employees without the knowledge, approval, or oversight of their organisation. The idea being it is the use of AI in the shadows: unsanctioned, un-managed, and often invisible to the very teams responsible for data security and governance.

If this sounds familiar, it should. We have been here before.

Shadow AI grows in the gap between what employees need and what organisations provide

From Shadow IT to Shadow AI

Cast your mind back to the days when the BlackBerry was the de facto mobile email device. At some point, smartphones started appearing in organisations, often in the other hand of staff. At times, that person was the CEO.

IT departments have often decried the dangers of what is known as Shadow IT. The term covers all manner of unapproved devices: personal smartphones, tablets, and even WiFi extenders that staff helpfully plugged into office networks to boost their signal range.

The mental model with which members of these teams approach such situations goes something like this: a user is making use of a device, tool, or piece of software that is not permitted. This is the problem. Instead of: a user has identified an important need in their workflow that we are not adequately addressing. Let us find out more so we can make their worklife, and the organisation, better.

BYOD – Bring Your Own Device

BYOD, or Bring Your Own Device, was an attempt at compromise between the IT department and everybody else. The deal was deceptively simple: you can bring your phone, but software would need to be installed to ensure that no viruses or other harmful software might be inadvertently introduced to the organisation’s network & systems by an unprotected device. This approach had limited success. Where it was implemented well, it worked. Where it was not, it did not.

IT teams that had actively listened to the needs being expressed through the bringing in of other devices saw that this was more than a desire to use something new and flashy. They could see that staff were getting real value from their smart devices: being able to open many more attachment types, having larger screens, and generally enjoying a wider-ranging, more efficient utility from their personal devices than the company-issued BlackBerrys provided. These teams eventually came up with ways of securely connecting non-BlackBerry devices to their systems, including phasing out BlackBerrys entirely.

On the flip side was the organisations and IT teams that fought the smartphone wave. They only started migrating to non-BlackBerry systems when it became clear that BlackBerry, the company, was moving out of the mobile device space. The shift for those organisations was arguably messier, more disruptive, and at times, more costly.

Looking Into the Shadows

One of the parallels that can be drawn from such situations then and now is that looking into the shadows of IT can be beneficial. How? Those organisations that saw Shadow IT not simply as a problem, but rather as an expression of an unmet need, benefitted. Some of them consulted directly with users to better understand the ‘why’ behind the reasons these users preferred their smartdevices and offered in-house alternatives, company-purchased and managed iPhones and Samsung Galaxy phones, for instance.

As organisations now face the reality that Shadow AI is here, they have the same choice: face this challenge head on, or pretend it is not happening.

The Challenge Is Real

At the recent Infosecurity Europe event, Shadow AI and Data Sovereignty were major topics. Vendors were positioning themselves as having the solutions, and they were doing so because the problem is real and growing. As many highly publicised — and not so well-known — cases show, Shadow AI can have serious negative consequences for an organisation, not least the leaking of confidential data via an unsanctioned LLM.

In many cases, employees will use free versions of these tools — or rather, versions that are provided at no monetary charge. These free-tier services often train their models using data from those users. The cost is not zero; it is simply paid by other means.

BYOL – Bring Your Own LLM

Now imagine an organisation in which any staff member can use the Large Language Model (LLM) of their choice. The organisation would not need to sign up for contracts that cover all users (some vendors will often offer licences based on headcount rather than actual product users); only licences actually used would be paid for. The LLMs would be fully managed by the IT department, which would be responsible for all aspects of their care, including licence and data management.

A context layer would be available that retains all context relating to user LLM sessions, even when a user switches from one model to another. Crucially, this context layer would be LLM-agnostic, meaning that a user could, for instance, use ChatGPT for part of a project and switch to Mistral for another. The context layer would ensure the new LLM is fully up to speed with what was discussed previously.

As you can imagine, such a system would need careful configuration and management to handle the risks around data loss and leakage. It would also likely be popular with users, who would no longer be restricted to one or two LLMs that are not aware of each other.

For now, though, most organisations have to rely on mandates around LLM use, including which LLMs can be used and full bans on unapproved models. The BYOL concept remains a vision, but it is one worth working towards.

Clearer AI policies mean less shadow AI: Innovation will often happen, however when done in the shadows, the organisation benefits less as cooperation and collaboration is hindered by the inevitable silos created in an organisational culture that fosters shadow AI. (Image created using Gemini)

How to Create and Magnify Shadow AI

If your goal was to maximise Shadow AI in your organisation, here is the playbook:

  1. Do not have any policies governing the use of AI in the organisation.
  2. If AI policies do exist, do not share them with staff.
  3. If you do share them, do not enforce them. They can be handy for showing auditors, though, so it is worth having a copy somewhere.

Eliminating Shadow AI

On the other hand, if an organisation wants to eliminate or reduce Shadow AI, the following steps help:

  1. Develop AI policies that are clear, practical, and relevant to how staff actually work.
  2. Share and promote those policies. Emphasise the benefits to employees and the organisation of keeping the data entrusted to them safe.
  3. Treat the AI policies as living documents, adapted to keep pace with developments and changes in the field.

Learning From Shadow AI

Just as organisations and IT departments that quickly adapted to what they were hearing from staff around mobile device needs benefitted; moving away from the BlackBerry ecosystem where they could see the advantages of the smartphones now available, there are clear advantages for organisations that are open to listening to employees who are engaging in Shadow AI.

Why are they doing it? Why are they going out and using these models? What benefits are they seeking? What tangible benefits are they finding from their use of these unapproved models?

Most users would only be engaging in shadow AI if there were benefits. Understanding those needs, and what employees find valuable in the tools they are using, explains why they turn to unsanctioned solutions. The chances of someone taking the risk of performing career-limiting manoeuvres (CLMs) are high, so the tools must offer real value.

Once an organisation understands what employees are using and why, it can start to plan ahead. Rather than taking a rigid approach, it becomes possible to adapt; to embrace the tools that are most beneficial to the most employees. This would, of course, mean having an infrastructure setup that allows for deploying and managing multiple models as needed.

This is of course not practical for all organisations. But what would be harmful is pretending Shadow AI does not exist, or that all needs are being met. That approach will only push employees deeper into the shadows, using company data in systems the organisation knows nothing about, risking data leakage through unmanaged accounts.

An organisation with an open environment, one that encourages discussion around these topics, is in a far stronger position. When employees have ideas, they need to know they will be heard. Across teams, staff who discover tools that could benefit the organisation should not feel they can only share them in closed groups, which can become echo chambers where colleagues encourage each other to use unsanctioned tools, multiplying risk. Instead, organisations should encourage open discussion. Even if requests are not immediately granted, employees should know their needs have been heard and will be considered as part of the organisation’s plan.

Training

Sometimes the gap is not in the tooling; it is in the training. Understanding the needs of staff can also inform the type and focus of AI training provided in an organisation. At times, employees may simply be more familiar with their favourite AI tool than the one the organisation has made available. Knowing what they are trying to achieve and then showing them how to do so using the sanctioned tools, where those tools have the features to support it, can go a long way towards reducing the level of Shadow AI.

Shining a Light on Shadow AI

Think about literal shadows. A shadow grows longer and wider when the light source is distant and at an angle, not directly above. The same is true with AI policy: the less clear and direct the guidance, the greater the shadow.

When the light is directly overhead, the shadow is smallest. Clear, well-communicated AI guidelines, where employees know exactly where the guardrails are, minimise the space in which Shadow AI can grow. Uncertainty and lack of clarity lead to confusion, which in turn lowers the level of innovation in an organisation. People stop experimenting not because they do not want to, but because they are not sure what is allowed.

This is why Shadow AI is worth paying attention to. Not just as a risk to be managed, but as a signal to be understood. Organisations that create room for flexibility, that listen to what their employees are telling them through their behaviour, and that respond with clear, adaptive policies will be the ones best positioned to harness AI safely and effectively.

The shadows have something to teach us; if we are willing to look.