Shadow AI is a measurement problem before it is a policy problem
Most organisations respond to unsanctioned AI use by writing a policy. The policy is not the binding constraint, because nobody knows what is being used, for what, or on which data — and a rule written against an unknown population changes nothing.
The policy exists. It was circulated, it was acknowledged, and it says that employees may not put company information into external AI tools without approval. It was written by people acting in good faith and it has almost certainly not changed what anybody does, because the sentence it needed to contain — here is the approved way to do the thing you are currently doing unapproved — was not in it.
That is the whole of the shadow AI problem, and it is not a discipline problem. People are not pasting a contract into a public assistant because they are careless. They are doing it because it works, because the approved alternative either does not exist or requires a form, and because the risk to them personally of missing a deadline is concrete while the risk of the paste is abstract.
The claim: an organisation cannot govern what it has not measured, and the measurement is available. Most of the effort currently going into AI policy would produce more risk reduction if it went into finding out what is actually happening first.
The scale of the thing being governed
The published research is consistent enough to act on even where individual numbers differ. IBM’s 2025 Cost of a Data Breach study found that shadow AI was a factor in around 20% of the breaches it examined and that its presence added substantially to the cost of an incident, with the great majority of affected organisations having no AI access controls in place at all — the report and its methodology are worth reading rather than quoting second-hand, because the sample and the definition of “involved” both matter.
What the figures describe, whichever survey you prefer, is not a fringe. It is ordinary work being done on tools nobody chose, through accounts nobody provisioned, on data nobody classified.
What measurement actually looks like
It is less invasive and less difficult than most organisations assume, and it does not require a new product in the first instance.
- Step 01 Egress and DNS records Which AI services are being reached from the corporate network, and at what volume. Already collected in most estates.
- Step 02 Identity and expense records Personal accounts on corporate email, and subscriptions appearing on expense claims. The cheapest signal of unmet demand.
- Step 03 Browser and endpoint telemetry Which tools are used, and by which function. Needs a stated purpose and a consultation, not a silent rollout.
- Step 04 A structured amnesty Ask people what they use and why, with an explicit undertaking that answering is not a disciplinary matter.
- Step 05 Data-class sampling For the highest-volume services, what categories of information are leaving. This is where the real exposure is quantified.
The fourth step is the one that gets skipped and the one that produces the most useful data. Telemetry tells you which tool. It does not tell you what job the person was trying to do, and the job is the thing you have to provide for if the behaviour is going to change. An amnesty conducted honestly returns a list of unmet needs that reads like a product backlog, because that is what it is.
From measurement to a control that holds
Once the population is known, the response is ordinary supply-side work rather than a policy.
The second line does most of the work. Where an approved path is slower than the unapproved one, people will keep choosing the unapproved one, and every additional control on the approved path widens the gap. This is the same dynamic that produced shadow IT, and the same remedy applies: make the sanctioned option the path of least resistance, then enforce.
The third line matters more than a long acceptable-use document. A rule that covers everything is remembered by nobody. Three named categories — customer personal data, unreleased financial information, credentials — are remembered by most people, and they cover the overwhelming majority of what an organisation would actually be harmed by losing.
What this does not tell you
None of this is a claim that measurement makes an organisation safe, and none of it is a substitute for a lawful basis, a records-of-processing entry, or a data protection assessment where personal data is involved. It is the step that has to happen before those are meaningful, because a data protection assessment of a system nobody uses is paperwork, and the systems people actually use are not in the inventory.
Nor should the telemetry steps be run without saying so. Monitoring employee tool use engages employment and data protection obligations in most jurisdictions, and an amnesty that turns out to have been conducted alongside covert monitoring will be the last honest answer that organisation ever receives. Consultation is not a constraint on this work. It is what makes the fourth step produce anything.
The reader who acts differently is the one who was about to commission an AI acceptable-use policy. Commission the measurement first. The policy will be shorter, it will be aimed at behaviour that exists, and it will be arguing with something real.