Request a scoping call Contact
← Research

Shadow AI is a measurement problem before it is a policy problem

Unsanctioned AI use needs a proportionate view of the tools, tasks and information involved. Use that evidence to provide workable approved routes, target controls and review whether the response changes behaviour.

Governance / Conceptual study
Trace the evidence.
  1. Sources
  2. Evidence links
  3. Decision record

Keep sources linked to the record used for review. The diagram does not represent automatic approval.

An acceptable-use policy should explain both the boundary and the approved route for useful work. If employees need help analysing a document or drafting a response, the organisation needs to understand how they currently obtain it. A prohibition alone does not establish that the underlying task has a safe, practical alternative.

Unsanctioned use can arise for several reasons: an unavailable tool, slow approval, unclear rules or deliberate disregard of them. Establish which reasons apply before selecting the response. Do not assume that every user is careless or that every use can be resolved through easier access.

Measure the relevant use and unmet needs, then design policy and controls around that evidence. Some immediate restrictions may be necessary before measurement is complete. The aim is to make the longer-term response proportionate to actual tasks, data and exposure.

The scale of the thing being governed

IBM’s 2025 Cost of a Data Breach study reported shadow-AI involvement in 20% of the breached organisations it examined. Its separate 97% access-control finding concerned organisations with an AI-related security incident, not solely the shadow-AI subgroup. The report and its methodology matter when interpreting both figures. These are findings from a breach-study sample, not an estimate that one in five organisations in the wider economy has experienced such a breach.

Use the study as a reason to investigate the local exposure. It does not tell a particular employer which tools staff use, what information they submit or why they bypass approved routes. Those questions need evidence from the organisation’s own work.

What measurement actually looks like

Start with records that can lawfully and proportionately answer the question. A tool inventory may combine service traffic, identity information, purchases and voluntary reporting. Each source has limits. Network records can miss personal devices, while a subscription record does not establish what information was submitted.

Establishing what is actually in use, in order of cost and intrusiveness Fig. 01
  1. Step 01 Egress and DNS records Which AI services are being reached from the corporate network, and at what volume. Use existing lawful records where available.
  2. Step 02 Identity and expense records Personal accounts on corporate email, and subscriptions appearing on expense claims. A possible signal of tool demand.
  3. Step 03 Browser and endpoint telemetry Which tools are used, and by which function. Needs a stated purpose and a consultation, not a silent rollout.
  4. Step 04 A structured amnesty Ask people what they use and why, with an explicit undertaking that answering is not a disciplinary matter.
  5. Step 05 Data-class sampling For the highest-volume services, what categories of information are leaving. Assess information classes and the limits of the sample.

Ask employees which tasks they are trying to complete and what blocks the approved route. Telemetry can identify a service without explaining that need. If the organisation offers a non-disciplinary reporting exercise, define its scope and honour the commitment. Use the resulting task descriptions to prioritise alternatives and guidance.

From measurement to a control that holds

The response combines usable approved services, clear restrictions and enforcement. Select the controls against the measured tasks and information classes. A policy remains necessary, but it should describe routes that people can actually follow.

Make approved access practical within the relevant risk boundary. Slow approval can encourage bypassing, but rapid access is not suitable for every tool or data class. Define a proportionate route, a response time and a named owner for requests that need assessment.

Give employees concrete examples of restricted material, such as credentials, unreleased financial information and particular classes of personal data. The list must reflect the organisation’s actual obligations and sensitivity. No three examples cover every harmful disclosure, so pair them with a route for uncertain cases.

What this does not tell you

Measurement does not establish safety or replace applicable data-protection duties. It helps define the tools and processing that require assessment, while existing lawful-basis, transparency and record-keeping obligations continue to apply. Where the work requires a Data Protection Impact Assessment, the inventory provides inputs rather than its conclusion.

Employee monitoring itself requires a proportionate purpose, appropriate transparency and assessment of employment and data-protection obligations. Agree those conditions before collecting new telemetry. Covert collection or a misleading promise about disciplinary use can damage trust and raise separate legal issues.

The governance owner should commission a scoped inventory alongside any urgent controls. Review the resulting tasks with the business and security owners, agree approved routes and repeat the relevant measurement. Judge the policy by the behaviour and exposure it addresses, rather than its length.

Filed under · Governance · Governance · Shadow AI · Operating model Inference Institute · 02 Oct 2026 (updated)

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.