-
Notifications
You must be signed in to change notification settings - Fork 0
2026 05 08 shadow ai behavioral drivers governance effectiveness
What are the primary behavioural and structural drivers of unsanctioned AI adoption after official tool rollout, and how effective are current governance mechanisms at containing unsanctioned AI systems that can call tools or take multi-step actions compared to earlier shadow IT waves?
What are the primary behavioural and structural drivers of shadow Artificial Intelligence (AI) adoption, meaning unsanctioned use of AI tools without formal approval or oversight, in enterprises after official tools have been rolled out, and what is the causal relationship between sanctioned tool provision and shadow usage, specifically, do provided tools reduce shadow AI or normalise bypass behaviours? How effective are current governance mechanisms, policies, Data Loss Prevention (DLP), and monitoring, at containing shadow AI systems that can call tools or take multi-step actions, referred to below as agentic AI, compared to earlier shadow Information Technology (IT) adoption waves?
In scope:
- Empirical evidence on behavioural and structural drivers of shadow AI in enterprises post-official tool deployment, across knowledge work and regulated or high-risk domains
- Causal analysis of whether provisioning sanctioned AI tools reduces shadow usage or inadvertently normalises bypass behaviour when quality and review are not enforced
- Comparison of current governance effectiveness for shadow AI systems that can call tools or take multi-step actions with earlier shadow IT governance approaches, cloud, bring-your-own-device (BYOD), and robotic process automation (RPA)
- New observability approaches, telemetry, behavioural analytics, anomaly detection, and discovery, required for agentic AI that were not needed for earlier shadow IT
- Capability gaps and process friction as drivers of shadow adoption
Out of scope:
- Deliberate insider threat or malicious data exfiltration, handled in security threat model research
- Consumer-tier AI product use outside enterprise contexts
- Full DLP vendor product comparison
- Legal or regulatory compliance per jurisdiction
Constraints:
- Ground all claims in observable enterprise patterns and flag inferences clearly
- Expand all acronyms on first use
- Distinguish causal from correlational findings
- Prior research on incentive misalignment and governance culture provides foundational context, and this item must extend rather than duplicate it
Existing repository research has established that reward structures, weak sanctioned delivery paths, and brittle review designs drive shadow AI and governance circumvention. [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html]
The remaining gap is a causal analysis of why shadow AI persists or accelerates even after official tools are provisioned, and whether current governance instruments are structurally fit to contain agentic AI given higher autonomy, broader data access, and faster action cycles than earlier shadow IT waves. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html]
-
Sub-question 1 - Behavioural and structural drivers: What empirical studies or surveys document the specific behavioural and structural reasons employees bypass official AI tools in favour of unsanctioned alternatives? How do capability gaps, process friction, and tool inadequacy compare as drivers?
-
Sub-question 2 - Causal relationship between sanctioned tools and shadow adoption: Is there empirical evidence that provisioning official AI tools reduces shadow usage? Or do they normalise a faster-is-better culture that increases bypass when quality gates are absent?
-
Sub-question 3 - Governance mechanism effectiveness: What evidence exists on the comparative effectiveness of policy, DLP, and monitoring controls for shadow AI systems that can call tools or take multi-step actions versus earlier shadow IT waves? What new observability approaches are being developed for agentic contexts?
Starting points and follow-on sources:
- McAfee (n.d.) McAfee homepage - seeded shadow-IT source, returned 403 in this session, not used for downstream factual support
- Gartner (n.d.) Gartner homepage - seeded analyst source, returned 403 in this session, not used for downstream factual support
- Belanger and Crossler (2011) Privacy in the Digital Age: A Review of Information Privacy Research in Information Systems - corrected record for the seeded DOI, checked but not used for downstream factual support
- Microsoft WorkLab (2023) Will AI Fix Work? - workload-pressure baseline for why workers want AI assistance
- Microsoft and LinkedIn (2024) Work Trend Index on the state of AI at work - post-rollout Bring Your Own AI (BYOAI) evidence
- IBM (2025) Is rising AI adoption creating shadow AI risks? - survey evidence on unofficial use, feature gaps, and training demand
- IBM (n.d.) Shadow AI - definitional comparison between shadow AI and shadow IT, plus productivity and governance framing
- IBM and Ponemon Institute (2025) Cost of a Data Breach Report, The AI oversight gap - governance-gap indicators for incidents, access controls, and shadow AI policy absence
- Cyberhaven Labs (2024) Shadow AI: How employees are leading the charge in AI adoption and putting company data at risk - enterprise telemetry on personal accounts, sensitive data, and persistence after enterprise rollout
- Klotz et al. (2019) Causing factors, outcomes, and governance of Shadow IT and business-managed IT - shadow-IT baseline on slowness, unmet needs, and governance response
- Kopper et al. (2019) Shadow IT and Business-managed IT: Practitioner Perceptions and Their Comparison to Literature - practitioner baseline on business-IT misalignment, agility gaps, and policy weakness
- National Institute of Standards and Technology (NIST) (2023) AI Risk Management Framework Core - cross-cutting governance, inventory, training, monitoring, and role-clarity baseline
- Microsoft Learn (2025) Copilot Studio security and governance - sanctioned-platform control surfaces and auditability
- Microsoft Learn (2025) Configure data policies for agents in Copilot Studio - real-time DLP enforcement and configurable restrictions over tools, knowledge, channels, authentication, and triggers
- Microsoft Learn (2025) Shadow AI discovery in Microsoft Entra Global Secure Access - network-based discovery and usage analytics for unsanctioned AI apps and tools
- Microsoft Security Response Center (2025) How Microsoft defends against indirect prompt injection attacks - action and exfiltration risks that exceed classic DLP-only framing
- Open Worldwide Application Security Project (OWASP) (2025) LLM01 Prompt Injection - why prompt injection remains incompletely preventable and why least privilege and human approval remain necessary
- Google Cloud DORA (2025) Announcing the 2025 DORA report - evidence that AI amplifies existing workflow and platform weaknesses
- Mitchell (2026) How do organisational incentives, culture, and behaviour influence adherence to governance in AI and low-code environments? - prior repository synthesis on governance circumvention drivers
- Mitchell (2026) What capability and control design is needed to mitigate incentive misalignment, shadow AI, rail bypass, and skill decay at enterprise scale? - prior repository synthesis on interacting failure modes and scaled controls
- Mitchell (2026) What are the primary failure modes in enterprise AI and low-code deployments, and how can governance systems be designed to mitigate them? - prior repository synthesis on failure classes and control mapping
- Mitchell (2026) What observability and telemetry model is required to govern AI and low-code systems at scale? - prior repository synthesis on telemetry and reconstruction requirements
- Mitchell (2026) UELGF extension: agentic AI-specific risks and runtime monitoring for non-deterministic behaviour - prior repository synthesis on precursor monitoring for agentic risk
(Full output from running the research skill, retained verbatim in the completed item. Sections 0 to 5 are the investigation, and section 6 seeds the Findings section below.)
- Question: Which behavioural and structural conditions keep unsanctioned AI use alive after sanctioned rollout, and how effective are current governance mechanisms at containing AI systems that can call tools or take multi-step actions relative to earlier shadow IT?
- Scope: Enterprise and regulated-enterprise post-rollout behaviour, causal interpretation of sanctioned-tool effects, and comparison of policy, DLP, monitoring, and discovery controls across earlier shadow IT and current unsanctioned AI use.
- Constraints: Observable enterprise patterns first, explicit distinction between fact and inference, acronym expansion on first use, and direct comparison with prior completed corpus items rather than restating them.
- Output: knowledge.
- [fact; source: https://www.ibm.com/think/topics/shadow-ai; https://www.ibm.com/think/topics/agentic-ai] Working definitions: shadow AI is the unsanctioned use of AI tools without formal approval or oversight, and agentic AI refers to AI systems that can pursue specific goals with limited supervision and can use tools or multistep workflows.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Prior completed items already establish that governance circumvention is driven by incentives, weak sanctioned delivery paths, shared AI and low-code failure modes, and missing telemetry, so this item extends the corpus by testing what changes after official AI rollout and where current containment still fails.
- [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The central empirical test is whether sanctioned AI provision changes actual user behaviour, or whether it mainly legitimises AI use while workers continue choosing whatever tool best reduces local friction.
- Root question: Why does shadow AI persist after official rollout, and what control model can actually contain shadow agentic behaviour?
-
A. Behavioural and structural drivers
- A1. What recurring causes did earlier shadow-IT research identify?
- A2. Which current enterprise-AI sources show the same causes persisting after rollout?
- A3. Which AI-specific conditions, instant consumer access, model quality differences, and workload pressure, intensify those causes?
-
B. Sanctioned-tool causal effect
- B1. Is there evidence that sanctioned rollout suppresses unofficial use?
- B2. Is there evidence that sanctioned rollout normalises AI use while unofficial use remains high?
- B3. Under what conditions does sanctioned rollout appear to work better?
-
C. Governance effectiveness
- C1. Which controls are effective inside sanctioned enterprise-agent platforms?
- C2. Which controls can discover or deter off-rail shadow AI?
- C3. Which agentic-AI risks remain insufficiently contained by policy, DLP, or discovery alone?
-
D. Comparison with earlier waves
- D1. Which shadow-IT governance lessons still hold?
- D2. What makes shadow AI systems that can call tools or take multi-step actions harder to contain than earlier shadow IT, cloud, or robotic process automation?
-
E. Synthesis
- E1. What behavioural model best explains post-rollout shadow AI?
- E2. What governance design follows if the goal is containment plus adoption of the sanctioned lane?
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] The nearest completed items already connect governance bypass to incentives, show that scaled AI weakens human pacing and review, define shared AI and low-code failure classes, and argue that agentic risk requires richer runtime evidence than ordinary operational telemetry.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The remaining gap is not whether circumvention exists, but whether sanctioned rollout changes the underlying incentives enough to displace shadow usage and whether enterprise controls can still see or stop behaviour once workers move off managed rails.
- [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] Earlier shadow-IT research consistently identifies slow responsiveness, long development or procurement cycles, poor business-IT alignment, lack of agility, weak policies, and unmet user needs as recurring causes of workaround adoption.
- [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] The same shadow-IT literature also identifies lack of restrictions and lack of awareness as contributing factors, which means weak enforcement and risk unawareness matter, but they appear alongside agility and unmet-need drivers rather than replacing them.
- [fact; source: https://www.microsoft.com/en-us/worklab/work-trend-index/will-ai-fix-work; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Microsoft's survey evidence shows the demand side of that pattern is strong in AI specifically, because 64% of people report lacking the time and energy to do their jobs, 70% in 2023 said they would delegate as much work as possible to AI, and 75% of knowledge workers were already using AI at work by 2024.
- [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.ibm.com/think/topics/shadow-ai] IBM reports that workers turn to shadow AI when company-provided solutions fail to meet their needs, that nearly 40% prefer external AI solutions for better features, and that the core motivators are faster execution, easier workflows, and immediate utility.
- [fact; source: https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Cyberhaven's telemetry on 3 million workers shows that the amount of corporate data workers put into AI tools increased 485% between March 2023 and March 2024 and that sensitive data exposure rose with adoption, which indicates that usage is not marginal experimentation but embedded work behaviour.
- [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The strongest post-rollout drivers are therefore not new in kind, they are the same structural frictions seen in earlier shadow IT, but AI lowers adoption friction further because workers can reach useful consumer tools immediately and can see rapid productivity gains before governance responds.
- [fact; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Microsoft's 2024 Work Trend Index reports that 75% of knowledge workers use AI at work and that 78% of AI users are bringing their own tools to work, which is direct evidence that widespread official adoption does not imply exclusive sanctioned use.
- [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] IBM reports that 80% of surveyed office workers use AI in their roles, but only 22% rely exclusively on employer-provided tools, which means most usage remains mixed or unofficial even after enterprise AI investment has begun.
- [fact; source: https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Cyberhaven reports that although OpenAI launched ChatGPT Enterprise in August 2023 and OpenAI says 80% of Fortune 500 companies have teams using corporate accounts, 73.8% of workplace ChatGPT accounts remained non-corporate, which is strong post-rollout evidence that sanctioned availability does not displace personal-account use.
- [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] IBM also reports that only 39% of users have received AI training from their company and that 60% say hands-on learning would boost usage, while Microsoft reports only 39% have received company AI training, which shows that provision without fit, workflow integration, and training leaves the unofficial path comparatively attractive.
- [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The best-supported causal reading is that sanctioned rollout often normalises AI as expected work, although incomplete rollout coverage and limited access to sanctioned accounts also contribute, because unofficial use remains high even where enterprise accounts and official teams are already present.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Sanctioned rollout appears more likely to reduce shadow usage only when it is coupled with strong internal platforms, clear workflow integration, policy clarity, and training, because AI amplifies the quality of the surrounding system of work rather than compensating for its weaknesses.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] Current sanctioned enterprise-agent platforms can apply meaningful controls inside the managed lane, including real-time data-policy enforcement, authentication requirements, restrictions on knowledge sources, connectors, Hypertext Transfer Protocol (HTTP) requests, triggers, and publishing channels, plus audit visibility through Microsoft Purview and Microsoft Sentinel.
- [fact; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery] Microsoft Entra shadow AI discovery adds a newer governance layer by using network traffic analysis to identify unsanctioned AI applications, show users, usage statistics, bytes transferred, and risk scores, which directly addresses the inventory blind spot that earlier policy-only governance could not solve.
- [fact; source: https://www.ibm.com/reports/data-breach; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] IBM and Ponemon Institute report that 97% of organisations with an AI-related security incident lacked proper AI access controls and 63% lacked AI governance policies to manage AI or prevent shadow AI, while NIST treats inventory, role clarity, training, and ongoing monitoring as core governance outcomes rather than optional add-ons.
- [fact; source: https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://genai.owasp.org/llmrisk/llm01-prompt-injection/] Agentic AI also creates control gaps that are qualitatively harder than classical application DLP alone, because indirect prompt injection can cause data exfiltration or unintended actions through tool use, and OWASP explicitly states that prompt injection does not have foolproof prevention, making least privilege and human approval for high-risk actions necessary.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] Current governance mechanisms therefore provide enforceable constraints for sanctioned agents inside managed platforms and useful discovery for unmanaged use, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because network discovery reveals that something is happening, not the full prompt, reasoning, tool-plan, or autonomous decision chain needed for prevention or reconstruction.
- [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] Earlier shadow-IT studies already showed that banning or monitoring alone was insufficient and that reducing unmet demand, improving responsiveness, and modernising sanctioned systems were central governance responses.
- [fact; source: https://www.ibm.com/think/topics/shadow-ai; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery] Microsoft's and IBM's current definitions preserve that continuity, because shadow AI is still a subclass of shadow IT, but the new risk surface includes model outputs, decision quality, and uncontrolled tool activity rather than only unapproved software presence or data location.
- [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] Shadow agentic AI is harder to contain than earlier shadow IT because organisations must now govern not just unsanctioned application use, but also hidden prompt content, semantic outputs, delegated actions, model-to-tool transitions, and machine-speed failure propagation that ordinary application discovery and classic DLP cannot fully interpret.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] The comparison therefore resolves as follows: the behavioural root causes are largely the same as earlier shadow IT, but the containment model must be stronger because agentic AI requires continuous inventory, attributed telemetry, prompt and tool traceability on managed rails, and pre-action controls for high-consequence actions.
- [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] The causal mechanism is best explained as unmet demand plus low-friction alternatives: when the official lane does not meet speed, capability, or usability needs, workers route around it even after the organisation signals that AI use is legitimate.
- [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] Weak enforcement and risk unawareness remain relevant alternative explanations, but the reviewed evidence treats them as contributing conditions rather than the primary explanation, because the strongest repeated signals concern agility gaps, unmet needs, and better external features.
- [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The evidence is stronger for the claim that sanctioned rollout normalises AI use than for the claim that rollout independently reduces shadow usage, because all three post-rollout sources show high official adoption coexisting with high personal-account or unofficial-tool use.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://genai.owasp.org/llmrisk/llm01-prompt-injection/] Governance effectiveness must therefore be separated by layer: policy and DLP can constrain configured sanctioned agents, discovery can reveal many unsanctioned apps, but off-rail prompt semantics and autonomous tool use remain partially opaque until work is moved back onto managed surfaces.
- [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The correct comparison with earlier shadow IT is continuity in root cause and discontinuity in control difficulty, because AI amplifies the same organisational weaknesses while adding action-level and cognition-level risk that older governance stacks were not designed to observe.
- [fact; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Microsoft, IBM, and Cyberhaven are directionally consistent on the core behavioural picture, high demand for AI, meaningful unofficial use after rollout, and persistent use of personal or better-fitting tools.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://www.ibm.com/reports/data-breach] The apparent tension between available governance controls and continued governance failure is resolved by distinguishing control availability from enterprise-wide containment, because strong controls can exist on managed platforms while most incidents still arise where access controls, policy coverage, or sanctioned adoption are incomplete.
- [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] The comparison claim has therefore been narrowed to avoid overstatement: current governance is not universally weaker than earlier shadow-IT governance, but it is weaker at enterprise-wide containment once unsanctioned agentic activity moves outside managed execution surfaces.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Organisationally, shadow AI is better interpreted as a systems-design signal than as isolated rule breaking, because AI amplifies platform quality, workflow clarity, and policy legibility rather than replacing them.
- [inference; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Behaviourally, workers appear to rationalise unofficial AI use when they believe the productivity benefit is immediate and the governance cost is distant or unclear, which is consistent with prior corpus findings on incentive misalignment and circumvention.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Technically, no single control surface is sufficient, because discovery, configuration-time restriction, and runtime action control each see different parts of the problem and agentic risk crosses all three.
- [inference; source: https://www.ibm.com/reports/data-breach; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] From a governance-design perspective, the most credible containment model is risk-tiered enablement, where the sanctioned path is made easier for low-risk work while high-risk uses are forced onto managed rails with stronger identity, telemetry, and pre-action intervention.
Executive summary:
Sanctioned AI rollout does not, by itself, materially suppress unsanctioned AI use, referred to below as shadow AI, a term IBM defines as AI use without formal approval or oversight; it more often normalises AI use while employees continue choosing faster or better-fitting unofficial tools. [inference; source: https://www.ibm.com/think/topics/shadow-ai; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The strongest drivers remain the same structural frictions that powered earlier shadow IT, slow sanctioned delivery, poor business-IT fit, weak workflow integration, and unmet demand, while weak enforcement and risk unawareness act mainly as contributing rather than primary drivers. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Current governance mechanisms provide enforceable constraints inside sanctioned platforms, where authentication, tool restrictions, channel restrictions, and real-time DLP are available, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because off-rail prompt semantics, tool plans, and delegated actions remain only partly visible. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Compared with earlier shadow IT waves, the behavioural problem is continuous but the containment problem is harder, because AI systems that can plan and act across multiple steps, a capability IBM uses to define agentic AI, require discovery, attributed telemetry, and pre-action controls rather than policy and app inventory alone. [inference; source: https://www.ibm.com/think/topics/agentic-ai; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]
Key findings:
- Post-rollout shadow AI is driven primarily by the same unmet-demand and workflow-friction conditions that drove earlier shadow IT, namely slow official delivery paths, weak business-IT fit, and sanctioned tools that do not match real work needs, while weak enforcement and risk unawareness remain secondary contributors. ([inference]; high confidence; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/)
- Sanctioned rollout does not reliably displace unofficial AI use, because Microsoft, IBM, and Cyberhaven all show high enterprise adoption coexisting with persistent Bring Your Own AI, personal-account use, and unofficial tool selection. ([inference]; high confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk)
- The best-supported causal interpretation is that official rollout often legitimises AI as normal work infrastructure, although incomplete rollout coverage and limited sanctioned-account access also contribute, because unofficial use remains high even where enterprise accounts and official teams are already present. ([inference]; medium confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)
- Managed enterprise-agent platforms support real-time policy enforcement over authentication, tools, knowledge sources, channels, and triggers, plus audit logging and security-status feedback, which means sanctioned deployments can be governed through explicit control surfaces rather than policy documents alone. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention)
- Those same mechanisms are only partially effective against shadow AI systems that can call tools or take multi-step actions, because discovery can reveal unsanctioned app usage and traffic volume, but it cannot by itself reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)
- Shadow AI systems that can call tools or take multi-step actions are harder to contain than earlier shadow IT because the risk surface now includes hidden prompt injection, model-mediated exfiltration, and unintended tool execution, which means classic DLP and application inventory are necessary but insufficient controls. ([inference]; high confidence; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://www.ibm.com/think/topics/shadow-ai)
- The most credible governance design is therefore enablement plus containment: make the sanctioned lane lower-friction and better-trained for routine work, while forcing high-risk agentic use onto managed rails with discovery, attributed telemetry, least privilege, and pre-action approval or hold controls. ([inference]; medium confidence; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)
Evidence map:
Assumptions:
- [assumption; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Microsoft survey data, IBM survey data, and Cyberhaven telemetry were treated as collectively representative enough to support direction-of-travel claims across enterprise knowledge work. Justification: the three sources independently report the same persistence pattern after rollout.
- [assumption; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Microsoft Copilot Studio was treated as a representative example of current sanctioned enterprise-agent governance surfaces rather than as a unique outlier. Justification: the control categories align with NIST's governance, inventory, monitoring, and role-control expectations.
- [assumption; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Off-rail personal-account use was treated as only partially observable at enterprise level. Justification: the reviewed discovery sources expose app traffic, users, and bytes transferred, but not a full prompt-to-action trace for unmanaged tools.
Analysis:
- [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The most persuasive evidence on sanctioned-tool effects came from post-rollout sources that directly measured behaviour rather than only describing risk, because those sources show official availability and shadow persistence at the same time.
- [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] Earlier shadow-IT literature was weighted heavily for mechanism, because it explains why users route around governance, while current AI sources were weighted heavily for changed speed and scale.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://genai.owasp.org/llmrisk/llm01-prompt-injection/] The governance synthesis separates control efficacy by surface, managed-lane controls can be strong, discovery can be useful, but unmanaged agentic actions remain harder to interpret and stop than unmanaged app use in older shadow-IT settings.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] The recommended design favours system improvement over prohibition, because the evidence suggests organisations need better internal platforms and stronger managed-rail containment together, not either one alone.
Risks, gaps, uncertainties:
- [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The evidence for sanctioned rollout causing more shadow use is observational rather than experimental, so the strongest conclusion is persistence and normalisation, not a quantified universal causal uplift.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] Official Microsoft documentation proves control availability but does not, on its own, prove cross-enterprise effectiveness rates for each control in production.
- [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Discovery and network telemetry reduce visibility gaps, but they do not eliminate the residual risk from unmanaged personal accounts, encrypted traffic, or prompt-level semantics that remain outside full enterprise inspection.
- [assumption; source: https://www.gartner.com/; https://www.mcafee.com/] Inaccessible Gartner and McAfee seeded pages may contain additional quantitative detail, but the core conclusions here do not depend on them because accessible Microsoft, IBM, Cyberhaven, NIST, and shadow-IT literature already support the main findings.
Open questions:
- [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] What specific platform-quality and workflow-integration changes most reliably convert high-demand Bring Your Own AI users into sustained sanctioned-platform users?
- [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Which telemetry fields are minimally sufficient to distinguish benign unsanctioned experimentation from high-risk off-rail agentic use without creating disproportionate privacy or data-minimisation concerns?
- [inference; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] What is the most usable enterprise pattern for pre-action approval or verification hold that contains agentic risk without pushing routine workers back into shadow channels?
- Labels and source audit: complete
- Acronym expansion audit: complete
- Findings and Section 6 parity: aligned
- Residual uncertainty: observational evidence on sanctioned-tool causal effect remains medium confidence
Sanctioned AI rollout does not, by itself, materially suppress unsanctioned AI use, referred to below as shadow AI; it more often normalises AI use while employees continue choosing faster or better-fitting unofficial tools. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
The strongest drivers remain the same structural frictions that powered earlier shadow IT, slow sanctioned delivery, poor business-IT fit, weak workflow integration, and unmet demand, while weak enforcement and risk unawareness act mainly as contributing rather than primary drivers. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/]
Current governance mechanisms provide materially stronger constraints inside sanctioned platforms, where authentication, tool restrictions, channel restrictions, and real-time DLP are available, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because off-rail prompt semantics, tool plans, and delegated actions remain only partly visible. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks]
Compared with earlier shadow IT waves, the behavioural problem is continuous but the containment problem is harder, because agentic AI adds cognition, autonomy, and machine-speed action risk that require discovery, attributed telemetry, and pre-action controls rather than policy and app inventory alone. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]
- Post-rollout shadow AI is driven primarily by the same unmet-demand and workflow-friction conditions that drove earlier shadow IT, namely slow official delivery paths, weak business-IT fit, and sanctioned tools that do not match real work needs, while weak enforcement and risk unawareness remain secondary contributors. ([inference]; high confidence; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/)
- Sanctioned rollout does not reliably displace unofficial AI use, because Microsoft, IBM, and Cyberhaven all show high enterprise adoption coexisting with persistent Bring Your Own AI, personal-account use, and unofficial tool selection. ([inference]; high confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk)
- The best-supported causal interpretation is that official rollout often legitimises AI as normal work infrastructure while leaving employees free to choose faster or better-fitting shadow tools when the sanctioned lane remains narrow, poorly integrated, or weakly trained. ([inference]; medium confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)
- Managed enterprise-agent platforms expose materially stronger control surfaces than unmanaged tools, because official control surfaces support real-time policy enforcement over authentication, tools, knowledge sources, channels, and triggers, plus audit logging and security-status feedback. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention)
- Those same mechanisms are only partially effective against shadow AI systems that can call tools or take multi-step actions, because discovery can reveal unsanctioned app usage and traffic volume, but it cannot by itself reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)
- Shadow agentic AI is harder to contain than earlier shadow IT because the risk surface now includes hidden prompt injection, model-mediated exfiltration, and unintended tool execution, which means classic DLP and application inventory are necessary but insufficient controls. ([inference]; high confidence; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://www.ibm.com/think/topics/shadow-ai)
- The most credible governance design is therefore enablement plus containment: make the sanctioned lane lower-friction and better-trained for routine work, while forcing high-risk agentic use onto managed rails with discovery, attributed telemetry, least privilege, and pre-action approval or hold controls. ([inference]; medium confidence; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)
- [assumption; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Microsoft survey data, IBM survey data, and Cyberhaven telemetry were treated as collectively representative enough to support direction-of-travel claims across enterprise knowledge work. Justification: the three sources independently report the same persistence pattern after rollout.
- [assumption; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Microsoft Copilot Studio was treated as a representative example of current sanctioned enterprise-agent governance surfaces rather than as a unique outlier. Justification: the control categories align with NIST's governance, inventory, monitoring, and role-control expectations.
- [assumption; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Off-rail personal-account use was treated as only partially observable at enterprise level. Justification: the reviewed discovery sources expose app traffic, users, and bytes transferred, but not a full prompt-to-action trace for unmanaged tools.
- The most persuasive evidence on sanctioned-tool effects came from post-rollout sources that directly measured behaviour rather than only describing risk, because those sources show official availability and shadow persistence at the same time. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
- Earlier shadow-IT literature was weighted heavily for mechanism, because it explains why users route around governance, while current AI sources were weighted heavily for changed speed and scale. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks]
- A pure-enforcement explanation is weaker than the mixed fit-and-friction explanation, because earlier shadow-IT studies already treat lack of restrictions and lack of awareness as contributing factors, while IBM and Cyberhaven still show heavy unofficial use even after official tools and policy attention are present. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
- The governance synthesis separates control efficacy by surface, managed-lane controls provide stronger constraints, discovery can be useful, but unmanaged agentic actions remain harder to interpret and stop than unmanaged app use in older shadow-IT settings. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://genai.owasp.org/llmrisk/llm01-prompt-injection/]
- The recommended design favours system improvement over prohibition, because the evidence suggests organisations need better internal platforms and stronger managed-rail containment together, not either one alone. [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]
- The evidence for sanctioned rollout causing more shadow use is observational rather than experimental, so the strongest conclusion is persistence and normalisation, not a quantified universal causal uplift. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
- Official Microsoft documentation proves control availability but does not, on its own, prove cross-enterprise effectiveness rates for each control in production. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention]
- Discovery and network telemetry reduce visibility gaps, but they do not eliminate the residual risk from unmanaged personal accounts, encrypted traffic, or prompt-level semantics that remain outside full enterprise inspection. [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks]
- Inaccessible Gartner and McAfee seeded pages may contain additional quantitative detail, but the core conclusions here do not depend on them because accessible Microsoft, IBM, Cyberhaven, NIST, and shadow-IT literature already support the main findings. [assumption; source: https://www.gartner.com/; https://www.mcafee.com/; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks]
- What specific platform-quality and workflow-integration changes most reliably convert high-demand Bring Your Own AI users into sustained sanctioned-platform users? [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report]
- Which telemetry fields are minimally sufficient to distinguish benign unsanctioned experimentation from high-risk off-rail agentic use without creating disproportionate privacy or data-minimisation concerns? [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html]
- What is the most usable enterprise pattern for pre-action approval or verification hold that contains agentic risk without pushing routine workers back into shadow channels? [inference; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]
- Type: knowledge
- Description: Behavioural and governance synthesis on why sanctioned rollout does not eliminate shadow AI and why shadow AI systems that can call tools or take multi-step actions need discovery plus managed execution controls, not policy alone. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks]
- Links:
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson