Shadow AI is the use of AI tools for work outside the route your organisation has approved: a personal ChatGPT account, a free Gemini login, a browser extension nobody reviewed. A policy on its own does not stop it. A policy changes what people are willing to tell you, and unless the approved route is faster than the unapproved one, that is mostly all it changes.
What decides whether shadow AI happens is friction, not rules. When the sanctioned tool is slower to reach, worse at the task, or blocked from the systems the work actually lives in, people route around it. Writing a prohibition down does not alter the arithmetic they are doing at four in the afternoon with something due.
The evidence has moved sharply on this. Security incidents involving shadow AI more than doubled in a year, to 43% from 20%, according to the Cost of a Data Breach Report 2026, conducted by Ponemon Institute and published by IBM across 602 breached organisations in 16 countries. Over the same period the share of organisations using strict approval processes for AI fell from 45% to 38%, and regular audits for unsanctioned AI fell from 34% to 29%. Companies did not stop caring about this. They wrote the document and skipped the operational half.
Does an AI policy stop shadow AI use?
Not on its own, and the case for expecting it to is stronger than the contrarian version usually admits. Clear rules, a named owner and real consequences do change behaviour across every other compliance domain a business runs.
Nobody argues that expenses fraud is a friction problem to be solved by making the expenses system nicer. Health and safety rules work. Information security policies work well enough that most staff will not email a client list to a personal address, even when it would be quicker. Data protection obligations changed the behaviour of entire industries, and they did it through written rules and enforcement rather than user experience.
There is no obvious property of AI that should exempt it from that pattern. A policy also does things nothing else can: it sets the standard an owner interprets, it is what a client or a regulator asks to see, and it is the document that makes enforcement possible at all. Anyone telling you policy is theatre is selling something.
Why do employees use unapproved AI tools anyway?
Because the approved option costs them something the unapproved one does not, and the cost is usually time. The behavioural data on this is unusually direct.
In the largest study of its kind, KPMG and Melbourne Business School surveyed 48,000 people across 47 countries between November 2024 and January 2025. They found that 57% of employees hide their use of AI and present AI-generated work as their own, that almost half admit to using AI in ways that contravene company policy, including putting confidential information into free public tools, and that only 40% say their workplace has any policy or guidance on generative AI at all.
That 57% is the finding that matters, and it is not a figure about ignorance. Concealment is not what somebody does when they have not heard the rule. It is what somebody does when they know the rule, have weighed it, and decided the compliant route costs more than the risk of being caught. A policy landing in that situation does not remove the behaviour. It moves the behaviour somewhere you cannot see it, which is worse than where it started, because you have lost the one thing that was helping you: visibility.
What causes shadow AI when the rules already exist?
Three frictions, and each has a different fix. In organisations that have written a policy and still see personal accounts in use, the cause is almost always one of these rather than a failure of communication.
Approval is slower than the deadline. A request goes into a queue with no stated turnaround while the work is due on Thursday. This is the friction most companies have made worse rather than better, which is what the fall in strict approval processes from 45% to 38% describes. The route did not get faster. It got rarer.
The sanctioned tool is worse at the actual job. Often this is a licensing decision nobody framed as one. A team is given an entry tier with a short context window and no file uploads, discovers it cannot do the thing they need, and goes back to the account that can. What a free seat, a paid seat and an enterprise agreement each commit to is a real difference, and it is worth knowing which one you bought before concluding your staff are being difficult. We cover that ground in detail in what company data you can and cannot put into ChatGPT.
Access is blocked, so the compliant path does not exist. This is the one we see most often at ivee and the one least likely to appear in a policy review, because it looks like a security success rather than a governance failure. The approved assistant cannot reach the internal platform where the work lives, so somebody exports the data and pastes it into a tool that has no such restriction. The control worked exactly as designed and produced the outcome it was built to prevent.
How do you make the approved route the fast one?
Five decisions, all of which a COO or head of operations can take this month without a programme of work behind them.
Publish a turnaround time and measure yourself against it. Five working days is defensible. Two is better. The number matters less than tracking your actual response time, because when it drifts past the published figure that is the leading indicator of people going around you. The mechanics of running that intake sit in our guide to building an approved AI tools list.
Give one named person the authority to say yes. Not a committee. A committee with no decision rights is worse than no committee, because it converts a delay into a process.
Buy the tier that does the job. If the sanctioned tool cannot handle the documents people work with daily, the licence is the problem and no amount of policy will fix it.
Fix access before you tighten rules. Where a sanctioned assistant is blocked from an internal system, treat it as an integration backlog item with an owner and a date, not as a permanent security posture.
Open a route for people already using something. If the only way to declare an unapproved tool is through a disciplinary conversation, nobody declares anything and the 57% stays at 57%. A stated amnesty window, with the tool assessed rather than the person, converts invisible use into a decision you can make.
None of these require you to trust your staff more than you currently do. They require the compliant path to be the path of least resistance, which is the only condition under which compliance is reliable in any domain.
So is an AI policy worth writing?
Yes, and this argument collapses without one. A policy is necessary and insufficient at the same time, which is an uncomfortable thing to hold but an accurate one.
The policy is what defines the standard the approval route is applying. Without it, a fast yes is just an unrecorded opinion, and the person giving it has nothing to point at when the answer is no. It is also the artefact your clients, insurers and auditors will ask for, and increasingly the one your enterprise customers require before they sign. If you have not written yours, or the one you have is a page of prohibitions with no owner, start with our guide to developing an AI policy.
What does not work is treating the document as the intervention. The policy sets the rule. Approval speed, licensing and access decide whether anyone can follow it.
Where this argument stops holding
In regulated functions, where the constraint is a legal obligation rather than convenience. Making the approved route faster does not create permission that was never available. A firm handling FCA-regulated advice, clinical records or privileged legal material is not choosing between a fast internal process and a slow one. It is working inside a boundary that speed cannot move, and there the correct answer really is a hard block plus an internally hosted alternative.
The argument also weakens wherever personal data is involved, which is more often than people assume. The Information Commissioner's Office has been explicit that there are no carve-outs or sweeping exemptions for generative AI, and that data protection law applies regardless of whether the processing is incidental or unintentional. A staff member who did not mean to put customer data into a public tool has still put customer data into a public tool. A faster approval queue does not change that analysis.
And friction is the dominant cause of shadow AI, not the only one. Some unapproved use is careless rather than rational, and no amount of process design reaches the person who simply did not think about it. That is what training is for, and it is a different problem with a different fix.
A policy that is not working is rarely a badly written policy. Find out how long your last AI tool request took to answer, and whether the person who raised it waited for you. That number will tell you more than another circulation email. If the answer is uncomfortable, our AI strategy and governance work exists for exactly that, and it starts with your approval queue rather than your document.




