Skip to content

2026 05 08 shadow ai behavioral drivers governance effectiveness

github-actions[bot] edited this page May 9, 2026 · 1 revision

What are the primary behavioural and structural drivers of unsanctioned AI adoption after official tool rollout, and how effective are current governance mechanisms at containing unsanctioned AI systems that can call tools or take multi-step actions compared to earlier shadow IT waves?

Research Question

What are the primary behavioural and structural drivers of shadow Artificial Intelligence (AI) adoption, meaning unsanctioned use of AI tools without formal approval or oversight, in enterprises after official tools have been rolled out, and what is the causal relationship between sanctioned tool provision and shadow usage, specifically, do provided tools reduce shadow AI or normalise bypass behaviours? How effective are current governance mechanisms, policies, Data Loss Prevention (DLP), and monitoring, at containing shadow AI systems that can call tools or take multi-step actions, referred to below as agentic AI, compared to earlier shadow Information Technology (IT) adoption waves?

Scope

In scope:

  • Empirical evidence on behavioural and structural drivers of shadow AI in enterprises post-official tool deployment, across knowledge work and regulated or high-risk domains
  • Causal analysis of whether provisioning sanctioned AI tools reduces shadow usage or inadvertently normalises bypass behaviour when quality and review are not enforced
  • Comparison of current governance effectiveness for shadow AI systems that can call tools or take multi-step actions with earlier shadow IT governance approaches, cloud, bring-your-own-device (BYOD), and robotic process automation (RPA)
  • New observability approaches, telemetry, behavioural analytics, anomaly detection, and discovery, required for agentic AI that were not needed for earlier shadow IT
  • Capability gaps and process friction as drivers of shadow adoption

Out of scope:

  • Deliberate insider threat or malicious data exfiltration, handled in security threat model research
  • Consumer-tier AI product use outside enterprise contexts
  • Full DLP vendor product comparison
  • Legal or regulatory compliance per jurisdiction

Constraints:

  • Ground all claims in observable enterprise patterns and flag inferences clearly
  • Expand all acronyms on first use
  • Distinguish causal from correlational findings
  • Prior research on incentive misalignment and governance culture provides foundational context, and this item must extend rather than duplicate it

Context

Existing repository research has established that reward structures, weak sanctioned delivery paths, and brittle review designs drive shadow AI and governance circumvention. [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html]

The remaining gap is a causal analysis of why shadow AI persists or accelerates even after official tools are provisioned, and whether current governance instruments are structurally fit to contain agentic AI given higher autonomy, broader data access, and faster action cycles than earlier shadow IT waves. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html]

Approach

  1. Sub-question 1 - Behavioural and structural drivers: What empirical studies or surveys document the specific behavioural and structural reasons employees bypass official AI tools in favour of unsanctioned alternatives? How do capability gaps, process friction, and tool inadequacy compare as drivers?

  2. Sub-question 2 - Causal relationship between sanctioned tools and shadow adoption: Is there empirical evidence that provisioning official AI tools reduces shadow usage? Or do they normalise a faster-is-better culture that increases bypass when quality gates are absent?

  3. Sub-question 3 - Governance mechanism effectiveness: What evidence exists on the comparative effectiveness of policy, DLP, and monitoring controls for shadow AI systems that can call tools or take multi-step actions versus earlier shadow IT waves? What new observability approaches are being developed for agentic contexts?

Sources

Starting points and follow-on sources:


Research Skill Output

(Full output from running the research skill, retained verbatim in the completed item. Sections 0 to 5 are the investigation, and section 6 seeds the Findings section below.)

§0 Initialise

  • Question: Which behavioural and structural conditions keep unsanctioned AI use alive after sanctioned rollout, and how effective are current governance mechanisms at containing AI systems that can call tools or take multi-step actions relative to earlier shadow IT?
  • Scope: Enterprise and regulated-enterprise post-rollout behaviour, causal interpretation of sanctioned-tool effects, and comparison of policy, DLP, monitoring, and discovery controls across earlier shadow IT and current unsanctioned AI use.
  • Constraints: Observable enterprise patterns first, explicit distinction between fact and inference, acronym expansion on first use, and direct comparison with prior completed corpus items rather than restating them.
  • Output: knowledge.
  • [fact; source: https://www.ibm.com/think/topics/shadow-ai; https://www.ibm.com/think/topics/agentic-ai] Working definitions: shadow AI is the unsanctioned use of AI tools without formal approval or oversight, and agentic AI refers to AI systems that can pursue specific goals with limited supervision and can use tools or multistep workflows.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Prior completed items already establish that governance circumvention is driven by incentives, weak sanctioned delivery paths, shared AI and low-code failure modes, and missing telemetry, so this item extends the corpus by testing what changes after official AI rollout and where current containment still fails.
  • [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The central empirical test is whether sanctioned AI provision changes actual user behaviour, or whether it mainly legitimises AI use while workers continue choosing whatever tool best reduces local friction.

§1 Question Decomposition

  • Root question: Why does shadow AI persist after official rollout, and what control model can actually contain shadow agentic behaviour?
  • A. Behavioural and structural drivers
    • A1. What recurring causes did earlier shadow-IT research identify?
    • A2. Which current enterprise-AI sources show the same causes persisting after rollout?
    • A3. Which AI-specific conditions, instant consumer access, model quality differences, and workload pressure, intensify those causes?
  • B. Sanctioned-tool causal effect
    • B1. Is there evidence that sanctioned rollout suppresses unofficial use?
    • B2. Is there evidence that sanctioned rollout normalises AI use while unofficial use remains high?
    • B3. Under what conditions does sanctioned rollout appear to work better?
  • C. Governance effectiveness
    • C1. Which controls are effective inside sanctioned enterprise-agent platforms?
    • C2. Which controls can discover or deter off-rail shadow AI?
    • C3. Which agentic-AI risks remain insufficiently contained by policy, DLP, or discovery alone?
  • D. Comparison with earlier waves
    • D1. Which shadow-IT governance lessons still hold?
    • D2. What makes shadow AI systems that can call tools or take multi-step actions harder to contain than earlier shadow IT, cloud, or robotic process automation?
  • E. Synthesis
    • E1. What behavioural model best explains post-rollout shadow AI?
    • E2. What governance design follows if the goal is containment plus adoption of the sanctioned lane?

§2 Investigation

Prior completed-item sweep

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] The nearest completed items already connect governance bypass to incentives, show that scaled AI weakens human pacing and review, define shared AI and low-code failure classes, and argue that agentic risk requires richer runtime evidence than ordinary operational telemetry.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] The remaining gap is not whether circumvention exists, but whether sanctioned rollout changes the underlying incentives enough to displace shadow usage and whether enterprise controls can still see or stop behaviour once workers move off managed rails.

A. Behavioural and structural drivers after rollout

  • [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] Earlier shadow-IT research consistently identifies slow responsiveness, long development or procurement cycles, poor business-IT alignment, lack of agility, weak policies, and unmet user needs as recurring causes of workaround adoption.
  • [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] The same shadow-IT literature also identifies lack of restrictions and lack of awareness as contributing factors, which means weak enforcement and risk unawareness matter, but they appear alongside agility and unmet-need drivers rather than replacing them.
  • [fact; source: https://www.microsoft.com/en-us/worklab/work-trend-index/will-ai-fix-work; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Microsoft's survey evidence shows the demand side of that pattern is strong in AI specifically, because 64% of people report lacking the time and energy to do their jobs, 70% in 2023 said they would delegate as much work as possible to AI, and 75% of knowledge workers were already using AI at work by 2024.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.ibm.com/think/topics/shadow-ai] IBM reports that workers turn to shadow AI when company-provided solutions fail to meet their needs, that nearly 40% prefer external AI solutions for better features, and that the core motivators are faster execution, easier workflows, and immediate utility.
  • [fact; source: https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Cyberhaven's telemetry on 3 million workers shows that the amount of corporate data workers put into AI tools increased 485% between March 2023 and March 2024 and that sensitive data exposure rose with adoption, which indicates that usage is not marginal experimentation but embedded work behaviour.
  • [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The strongest post-rollout drivers are therefore not new in kind, they are the same structural frictions seen in earlier shadow IT, but AI lowers adoption friction further because workers can reach useful consumer tools immediately and can see rapid productivity gains before governance responds.

B. Causal relationship between sanctioned rollout and shadow usage

  • [fact; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Microsoft's 2024 Work Trend Index reports that 75% of knowledge workers use AI at work and that 78% of AI users are bringing their own tools to work, which is direct evidence that widespread official adoption does not imply exclusive sanctioned use.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] IBM reports that 80% of surveyed office workers use AI in their roles, but only 22% rely exclusively on employer-provided tools, which means most usage remains mixed or unofficial even after enterprise AI investment has begun.
  • [fact; source: https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Cyberhaven reports that although OpenAI launched ChatGPT Enterprise in August 2023 and OpenAI says 80% of Fortune 500 companies have teams using corporate accounts, 73.8% of workplace ChatGPT accounts remained non-corporate, which is strong post-rollout evidence that sanctioned availability does not displace personal-account use.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] IBM also reports that only 39% of users have received AI training from their company and that 60% say hands-on learning would boost usage, while Microsoft reports only 39% have received company AI training, which shows that provision without fit, workflow integration, and training leaves the unofficial path comparatively attractive.
  • [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The best-supported causal reading is that sanctioned rollout often normalises AI as expected work, although incomplete rollout coverage and limited access to sanctioned accounts also contribute, because unofficial use remains high even where enterprise accounts and official teams are already present.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Sanctioned rollout appears more likely to reduce shadow usage only when it is coupled with strong internal platforms, clear workflow integration, policy clarity, and training, because AI amplifies the quality of the surrounding system of work rather than compensating for its weaknesses.

C. Governance mechanism effectiveness and limits

  • [fact; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] Current sanctioned enterprise-agent platforms can apply meaningful controls inside the managed lane, including real-time data-policy enforcement, authentication requirements, restrictions on knowledge sources, connectors, Hypertext Transfer Protocol (HTTP) requests, triggers, and publishing channels, plus audit visibility through Microsoft Purview and Microsoft Sentinel.
  • [fact; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery] Microsoft Entra shadow AI discovery adds a newer governance layer by using network traffic analysis to identify unsanctioned AI applications, show users, usage statistics, bytes transferred, and risk scores, which directly addresses the inventory blind spot that earlier policy-only governance could not solve.
  • [fact; source: https://www.ibm.com/reports/data-breach; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] IBM and Ponemon Institute report that 97% of organisations with an AI-related security incident lacked proper AI access controls and 63% lacked AI governance policies to manage AI or prevent shadow AI, while NIST treats inventory, role clarity, training, and ongoing monitoring as core governance outcomes rather than optional add-ons.
  • [fact; source: https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://genai.owasp.org/llmrisk/llm01-prompt-injection/] Agentic AI also creates control gaps that are qualitatively harder than classical application DLP alone, because indirect prompt injection can cause data exfiltration or unintended actions through tool use, and OWASP explicitly states that prompt injection does not have foolproof prevention, making least privilege and human approval for high-risk actions necessary.
  • [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] Current governance mechanisms therefore provide enforceable constraints for sanctioned agents inside managed platforms and useful discovery for unmanaged use, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because network discovery reveals that something is happening, not the full prompt, reasoning, tool-plan, or autonomous decision chain needed for prevention or reconstruction.

D. Comparison with earlier shadow IT waves

  • [fact; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf] Earlier shadow-IT studies already showed that banning or monitoring alone was insufficient and that reducing unmet demand, improving responsiveness, and modernising sanctioned systems were central governance responses.
  • [fact; source: https://www.ibm.com/think/topics/shadow-ai; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery] Microsoft's and IBM's current definitions preserve that continuity, because shadow AI is still a subclass of shadow IT, but the new risk surface includes model outputs, decision quality, and uncontrolled tool activity rather than only unapproved software presence or data location.
  • [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] Shadow agentic AI is harder to contain than earlier shadow IT because organisations must now govern not just unsanctioned application use, but also hidden prompt content, semantic outputs, delegated actions, model-to-tool transitions, and machine-speed failure propagation that ordinary application discovery and classic DLP cannot fully interpret.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] The comparison therefore resolves as follows: the behavioural root causes are largely the same as earlier shadow IT, but the containment model must be stronger because agentic AI requires continuous inventory, attributed telemetry, prompt and tool traceability on managed rails, and pre-action controls for high-consequence actions.

§3 Reasoning

  • [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] The causal mechanism is best explained as unmet demand plus low-friction alternatives: when the official lane does not meet speed, capability, or usability needs, workers route around it even after the organisation signals that AI use is legitimate.
  • [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] Weak enforcement and risk unawareness remain relevant alternative explanations, but the reviewed evidence treats them as contributing conditions rather than the primary explanation, because the strongest repeated signals concern agility gaps, unmet needs, and better external features.
  • [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The evidence is stronger for the claim that sanctioned rollout normalises AI use than for the claim that rollout independently reduces shadow usage, because all three post-rollout sources show high official adoption coexisting with high personal-account or unofficial-tool use.
  • [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://genai.owasp.org/llmrisk/llm01-prompt-injection/] Governance effectiveness must therefore be separated by layer: policy and DLP can constrain configured sanctioned agents, discovery can reveal many unsanctioned apps, but off-rail prompt semantics and autonomous tool use remain partially opaque until work is moved back onto managed surfaces.
  • [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The correct comparison with earlier shadow IT is continuity in root cause and discontinuity in control difficulty, because AI amplifies the same organisational weaknesses while adding action-level and cognition-level risk that older governance stacks were not designed to observe.

§4 Consistency Check

  • [fact; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Microsoft, IBM, and Cyberhaven are directionally consistent on the core behavioural picture, high demand for AI, meaningful unofficial use after rollout, and persistent use of personal or better-fitting tools.
  • [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://www.ibm.com/reports/data-breach] The apparent tension between available governance controls and continued governance failure is resolved by distinguishing control availability from enterprise-wide containment, because strong controls can exist on managed platforms while most incidents still arise where access controls, policy coverage, or sanctioned adoption are incomplete.
  • [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] The comparison claim has therefore been narrowed to avoid overstatement: current governance is not universally weaker than earlier shadow-IT governance, but it is weaker at enterprise-wide containment once unsanctioned agentic activity moves outside managed execution surfaces.

§5 Depth and Breadth Expansion

  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Organisationally, shadow AI is better interpreted as a systems-design signal than as isolated rule breaking, because AI amplifies platform quality, workflow clarity, and policy legibility rather than replacing them.
  • [inference; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Behaviourally, workers appear to rationalise unofficial AI use when they believe the productivity benefit is immediate and the governance cost is distant or unclear, which is consistent with prior corpus findings on incentive misalignment and circumvention.
  • [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Technically, no single control surface is sufficient, because discovery, configuration-time restriction, and runtime action control each see different parts of the problem and agentic risk crosses all three.
  • [inference; source: https://www.ibm.com/reports/data-breach; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] From a governance-design perspective, the most credible containment model is risk-tiered enablement, where the sanctioned path is made easier for low-risk work while high-risk uses are forced onto managed rails with stronger identity, telemetry, and pre-action intervention.

§6 Synthesis

Executive summary:

Sanctioned AI rollout does not, by itself, materially suppress unsanctioned AI use, referred to below as shadow AI, a term IBM defines as AI use without formal approval or oversight; it more often normalises AI use while employees continue choosing faster or better-fitting unofficial tools. [inference; source: https://www.ibm.com/think/topics/shadow-ai; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The strongest drivers remain the same structural frictions that powered earlier shadow IT, slow sanctioned delivery, poor business-IT fit, weak workflow integration, and unmet demand, while weak enforcement and risk unawareness act mainly as contributing rather than primary drivers. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/] Current governance mechanisms provide enforceable constraints inside sanctioned platforms, where authentication, tool restrictions, channel restrictions, and real-time DLP are available, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because off-rail prompt semantics, tool plans, and delegated actions remain only partly visible. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Compared with earlier shadow IT waves, the behavioural problem is continuous but the containment problem is harder, because AI systems that can plan and act across multiple steps, a capability IBM uses to define agentic AI, require discovery, attributed telemetry, and pre-action controls rather than policy and app inventory alone. [inference; source: https://www.ibm.com/think/topics/agentic-ai; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]

Key findings:

  1. Post-rollout shadow AI is driven primarily by the same unmet-demand and workflow-friction conditions that drove earlier shadow IT, namely slow official delivery paths, weak business-IT fit, and sanctioned tools that do not match real work needs, while weak enforcement and risk unawareness remain secondary contributors. ([inference]; high confidence; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/)
  2. Sanctioned rollout does not reliably displace unofficial AI use, because Microsoft, IBM, and Cyberhaven all show high enterprise adoption coexisting with persistent Bring Your Own AI, personal-account use, and unofficial tool selection. ([inference]; high confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk)
  3. The best-supported causal interpretation is that official rollout often legitimises AI as normal work infrastructure, although incomplete rollout coverage and limited sanctioned-account access also contribute, because unofficial use remains high even where enterprise accounts and official teams are already present. ([inference]; medium confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)
  4. Managed enterprise-agent platforms support real-time policy enforcement over authentication, tools, knowledge sources, channels, and triggers, plus audit logging and security-status feedback, which means sanctioned deployments can be governed through explicit control surfaces rather than policy documents alone. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention)
  5. Those same mechanisms are only partially effective against shadow AI systems that can call tools or take multi-step actions, because discovery can reveal unsanctioned app usage and traffic volume, but it cannot by itself reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)
  6. Shadow AI systems that can call tools or take multi-step actions are harder to contain than earlier shadow IT because the risk surface now includes hidden prompt injection, model-mediated exfiltration, and unintended tool execution, which means classic DLP and application inventory are necessary but insufficient controls. ([inference]; high confidence; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://www.ibm.com/think/topics/shadow-ai)
  7. The most credible governance design is therefore enablement plus containment: make the sanctioned lane lower-friction and better-trained for routine work, while forcing high-risk agentic use onto managed rails with discovery, attributed telemetry, least privilege, and pre-action approval or hold controls. ([inference]; medium confidence; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)

Evidence map:

Claim Source Confidence Notes
[inference] Post-rollout shadow AI is driven mainly by unmet demand and workflow friction rather than by simple policy ignorance. https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/ high continuity with shadow IT
[fact] High enterprise adoption coexists with persistent Bring Your Own AI, personal-account use, and unofficial tool selection. https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk high strongest post-rollout evidence
[inference] Official rollout often legitimises AI use without eliminating shadow behaviour, although incomplete rollout coverage and limited sanctioned-account access also contribute. https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report medium normalization plus rollout gaps
[inference] Managed enterprise-agent platforms provide explicit governance control surfaces through real-time policy, tool, and publishing controls plus auditability. https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention medium control availability
[inference] Discovery improves visibility into shadow AI but does not fully reconstruct agentic behaviour. https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html medium discovery is not full forensics
[inference] Agentic AI extends shadow-IT risk into prompt-mediated exfiltration and unintended tool execution, making containment harder than ordinary app discovery alone. https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://www.ibm.com/think/topics/shadow-ai high autonomy changes control problem
[inference] Governance should combine low-friction sanctioned enablement with stronger managed-rail controls for high-risk uses. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html medium design synthesis

Assumptions:

  • [assumption; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Microsoft survey data, IBM survey data, and Cyberhaven telemetry were treated as collectively representative enough to support direction-of-travel claims across enterprise knowledge work. Justification: the three sources independently report the same persistence pattern after rollout.
  • [assumption; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Microsoft Copilot Studio was treated as a representative example of current sanctioned enterprise-agent governance surfaces rather than as a unique outlier. Justification: the control categories align with NIST's governance, inventory, monitoring, and role-control expectations.
  • [assumption; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Off-rail personal-account use was treated as only partially observable at enterprise level. Justification: the reviewed discovery sources expose app traffic, users, and bytes transferred, but not a full prompt-to-action trace for unmanaged tools.

Analysis:

  • [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The most persuasive evidence on sanctioned-tool effects came from post-rollout sources that directly measured behaviour rather than only describing risk, because those sources show official availability and shadow persistence at the same time.
  • [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] Earlier shadow-IT literature was weighted heavily for mechanism, because it explains why users route around governance, while current AI sources were weighted heavily for changed speed and scale.
  • [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://genai.owasp.org/llmrisk/llm01-prompt-injection/] The governance synthesis separates control efficacy by surface, managed-lane controls can be strong, discovery can be useful, but unmanaged agentic actions remain harder to interpret and stop than unmanaged app use in older shadow-IT settings.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] The recommended design favours system improvement over prohibition, because the evidence suggests organisations need better internal platforms and stronger managed-rail containment together, not either one alone.

Risks, gaps, uncertainties:

  • [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] The evidence for sanctioned rollout causing more shadow use is observational rather than experimental, so the strongest conclusion is persistence and normalisation, not a quantified universal causal uplift.
  • [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention] Official Microsoft documentation proves control availability but does not, on its own, prove cross-enterprise effectiveness rates for each control in production.
  • [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Discovery and network telemetry reduce visibility gaps, but they do not eliminate the residual risk from unmanaged personal accounts, encrypted traffic, or prompt-level semantics that remain outside full enterprise inspection.
  • [assumption; source: https://www.gartner.com/; https://www.mcafee.com/] Inaccessible Gartner and McAfee seeded pages may contain additional quantitative detail, but the core conclusions here do not depend on them because accessible Microsoft, IBM, Cyberhaven, NIST, and shadow-IT literature already support the main findings.

Open questions:

  • [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] What specific platform-quality and workflow-integration changes most reliably convert high-demand Bring Your Own AI users into sustained sanctioned-platform users?
  • [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Which telemetry fields are minimally sufficient to distinguish benign unsanctioned experimentation from high-risk off-rail agentic use without creating disproportionate privacy or data-minimisation concerns?
  • [inference; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html] What is the most usable enterprise pattern for pre-action approval or verification hold that contains agentic risk without pushing routine workers back into shadow channels?

§7 Recursive Review

  • Labels and source audit: complete
  • Acronym expansion audit: complete
  • Findings and Section 6 parity: aligned
  • Residual uncertainty: observational evidence on sanctioned-tool causal effect remains medium confidence

Findings

Executive Summary

Sanctioned AI rollout does not, by itself, materially suppress unsanctioned AI use, referred to below as shadow AI; it more often normalises AI use while employees continue choosing faster or better-fitting unofficial tools. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]

The strongest drivers remain the same structural frictions that powered earlier shadow IT, slow sanctioned delivery, poor business-IT fit, weak workflow integration, and unmet demand, while weak enforcement and risk unawareness act mainly as contributing rather than primary drivers. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/]

Current governance mechanisms provide materially stronger constraints inside sanctioned platforms, where authentication, tool restrictions, channel restrictions, and real-time DLP are available, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because off-rail prompt semantics, tool plans, and delegated actions remain only partly visible. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks]

Compared with earlier shadow IT waves, the behavioural problem is continuous but the containment problem is harder, because agentic AI adds cognition, autonomy, and machine-speed action risk that require discovery, attributed telemetry, and pre-action controls rather than policy and app inventory alone. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]

Key Findings

  1. Post-rollout shadow AI is driven primarily by the same unmet-demand and workflow-friction conditions that drove earlier shadow IT, namely slow official delivery paths, weak business-IT fit, and sanctioned tools that do not match real work needs, while weak enforcement and risk unawareness remain secondary contributors. ([inference]; high confidence; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/)
  2. Sanctioned rollout does not reliably displace unofficial AI use, because Microsoft, IBM, and Cyberhaven all show high enterprise adoption coexisting with persistent Bring Your Own AI, personal-account use, and unofficial tool selection. ([inference]; high confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk)
  3. The best-supported causal interpretation is that official rollout often legitimises AI as normal work infrastructure while leaving employees free to choose faster or better-fitting shadow tools when the sanctioned lane remains narrow, poorly integrated, or weakly trained. ([inference]; medium confidence; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)
  4. Managed enterprise-agent platforms expose materially stronger control surfaces than unmanaged tools, because official control surfaces support real-time policy enforcement over authentication, tools, knowledge sources, channels, and triggers, plus audit logging and security-status feedback. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention)
  5. Those same mechanisms are only partially effective against shadow AI systems that can call tools or take multi-step actions, because discovery can reveal unsanctioned app usage and traffic volume, but it cannot by itself reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous. ([inference]; medium confidence; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)
  6. Shadow agentic AI is harder to contain than earlier shadow IT because the risk surface now includes hidden prompt injection, model-mediated exfiltration, and unintended tool execution, which means classic DLP and application inventory are necessary but insufficient controls. ([inference]; high confidence; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://www.ibm.com/think/topics/shadow-ai)
  7. The most credible governance design is therefore enablement plus containment: make the sanctioned lane lower-friction and better-trained for routine work, while forcing high-risk agentic use onto managed rails with discovery, attributed telemetry, least privilege, and pre-action approval or hold controls. ([inference]; medium confidence; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html)

Evidence Map

Claim Source Confidence Notes
[inference] Post-rollout shadow AI is driven mainly by unmet demand and workflow friction rather than by simple policy ignorance. https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/ high continuity with shadow IT
[fact] High enterprise adoption coexists with persistent Bring Your Own AI, personal-account use, and unofficial tool selection. https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk high strongest post-rollout evidence
[inference] Official rollout often legitimises AI use without eliminating shadow behaviour. https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report medium causal reading remains observational
[inference] Managed enterprise-agent platforms expose materially stronger control surfaces than unmanaged tools because they offer real-time policy, tool, and publishing controls plus auditability. https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention medium control availability, not measured efficacy
[inference] Discovery improves visibility into shadow AI but does not fully reconstruct agentic behaviour. https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html medium discovery is not full forensics
[inference] Agentic AI extends shadow-IT risk into prompt-mediated exfiltration and unintended tool execution, making containment harder than ordinary app discovery alone. https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://www.ibm.com/think/topics/shadow-ai high autonomy changes control problem
[inference] Governance should combine low-friction sanctioned enablement with stronger managed-rail controls for high-risk uses. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html medium design synthesis

Assumptions

  • [assumption; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk] Microsoft survey data, IBM survey data, and Cyberhaven telemetry were treated as collectively representative enough to support direction-of-travel claims across enterprise knowledge work. Justification: the three sources independently report the same persistence pattern after rollout.
  • [assumption; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Microsoft Copilot Studio was treated as a representative example of current sanctioned enterprise-agent governance surfaces rather than as a unique outlier. Justification: the control categories align with NIST's governance, inventory, monitoring, and role-control expectations.
  • [assumption; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks] Off-rail personal-account use was treated as only partially observable at enterprise level. Justification: the reviewed discovery sources expose app traffic, users, and bytes transferred, but not a full prompt-to-action trace for unmanaged tools.

Analysis

  • The most persuasive evidence on sanctioned-tool effects came from post-rollout sources that directly measured behaviour rather than only describing risk, because those sources show official availability and shadow persistence at the same time. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
  • Earlier shadow-IT literature was weighted heavily for mechanism, because it explains why users route around governance, while current AI sources were weighted heavily for changed speed and scale. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks]
  • A pure-enforcement explanation is weaker than the mixed fit-and-friction explanation, because earlier shadow-IT studies already treat lack of restrictions and lack of awareness as contributing factors, while IBM and Cyberhaven still show heavy unofficial use even after official tools and policy attention are present. [inference; source: https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf; https://jitm.ubalt.edu/XXX-4/article1.pdf; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
  • The governance synthesis separates control efficacy by surface, managed-lane controls provide stronger constraints, discovery can be useful, but unmanaged agentic actions remain harder to interpret and stop than unmanaged app use in older shadow-IT settings. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention; https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://genai.owasp.org/llmrisk/llm01-prompt-injection/]
  • The recommended design favours system improvement over prohibition, because the evidence suggests organisations need better internal platforms and stronger managed-rail containment together, not either one alone. [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]

Risks, Gaps, and Uncertainties

  • The evidence for sanctioned rollout causing more shadow use is observational rather than experimental, so the strongest conclusion is persistence and normalisation, not a quantified universal causal uplift. [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk]
  • Official Microsoft documentation proves control availability but does not, on its own, prove cross-enterprise effectiveness rates for each control in production. [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention]
  • Discovery and network telemetry reduce visibility gaps, but they do not eliminate the residual risk from unmanaged personal accounts, encrypted traffic, or prompt-level semantics that remain outside full enterprise inspection. [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks]
  • Inaccessible Gartner and McAfee seeded pages may contain additional quantitative detail, but the core conclusions here do not depend on them because accessible Microsoft, IBM, Cyberhaven, NIST, and shadow-IT literature already support the main findings. [assumption; source: https://www.gartner.com/; https://www.mcafee.com/; https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks]

Open Questions

  • What specific platform-quality and workflow-integration changes most reliably convert high-demand Bring Your Own AI users into sustained sanctioned-platform users? [inference; source: https://news.microsoft.com/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report]
  • Which telemetry fields are minimally sufficient to distinguish benign unsanctioned experimentation from high-risk off-rail agentic use without creating disproportionate privacy or data-minimisation concerns? [inference; source: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-shadow-ai-discovery; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html]
  • What is the most usable enterprise pattern for pre-action approval or verification hold that contains agentic risk without pushing routine workers back into shadow channels? [inference; source: https://genai.owasp.org/llmrisk/llm01-prompt-injection/; https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacks; https://davidamitchell.github.io/Research/research/2026-04-28-uelgf-agentic-ai-specific-risks-runtime-monitoring.html]

Output

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally