Shadow AI is your adoption roadmap. Most companies are trying to delete it.
Employees at nine companies in ten use personal AI tools for work. Four in ten companies have bought one. The gap between those numbers is usually described as a security problem. It is also the most accurate map you will ever get of where AI already helps your business — drawn for free, by the people doing the work. This playbook is how you find it, put a name next to it, and turn it into the program, without banning anything.
The account, not the tool.
Shadow AI is any AI tool used for work without the company's knowledge, approval or oversight. In practice that is five things: personal ChatGPT, Claude or Gemini accounts; AI coding tools on individual licences; meeting note-takers that record every call; browser extensions that add AI to the CRM and the inbox; and AI features that arrived inside software you already pay for, switched on by a vendor update nobody read.
The thing to notice is that almost none of it is a bad tool. It is a good tool on the wrong account. ChatGPT on a personal login is shadow AI; the same ChatGPT on a company-managed Team plan is not. The difference is whether the company can see users, revoke access, rely on the tier's data terms and close the account when someone leaves. That is why the most common action in this playbook is move, not ban.
Normal state, unmanaged by choice.
Companies whose employees regularly use personal AI tools for work, versus companies that have bought an official subscription.
Extra cost of a breach where shadow AI was a factor. It was a factor in one breach in five.
Of organisations have no AI governance policy at all. Of those that do, only a third audit for unsanctioned AI.
Of mid-market IT leaders confirmed an AI security incident in the past year.
Of desk workers are uncomfortable admitting AI use to their manager.
Employee usage rates for AI tools that were formalised from what people already used, versus tools built centrally.
Your employees have already run the pilot.
MIT's 2025 study of enterprise AI found that 95% of official pilots produce no measurable return — while, in the same companies, employees quietly automate large parts of their jobs with a $20-a-month personal account. Their words: this shadow economy “often delivers better ROI than formal initiatives and reveals what actually works.”
That is the reframe. The list of unsanctioned tools is not a list of violations. It is a ranked, evidence-based inventory of use cases that already have a user, a workflow and a demonstrated benefit — the three things every failed pilot lacked. The companies MIT found on the right side of the divide sourced AI initiatives from front-line managers and power users, not a central lab, and saw employee usage rates nearly double for the tools that came out of it.
So the job is not to make shadow AI stop. The job is to give it a name, an owner and a managed account, and to make the sanctioned path faster than going around it.
Five moves, in this order.
The order is the point. Each move produces the thing the next one needs, and doing them out of sequence is how companies end up with a policy nobody follows and training nobody applies.
Find it
Three finders cover most of it without buying anything. Search expense reports and card statements for AI vendors — the personal ChatGPT Plus on a corporate card is the single most common hit. Pull the SSO log and the browser-extension inventory from device management. And send an anonymous two-question survey: what do you use, and what for. Anonymous is not optional; nearly half of workers hide AI use from their manager, and a survey with names on it measures fear, not usage.
A list. Expect two to three times more than you thought, and expect the useful things to be in the surprising half.
Name it
Every item on the list gets a registry row: what it is, where it lives (which account, which tier), what it can reach, who depends on it, and — the load-bearing field — a named owner. A person, not a team. A tool nobody will own is a tool nobody will review, renew, retire or answer for when it goes wrong, and 'nobody will own it' is itself the decision about whether it stays. Give every row a review date ninety days out.
The AI Registry. It is the first artifact of governance because everything downstream — the policy, the training, the budget — has to refer to it.
Sort it
Each row resolves to one of four statuses. Keep: already on a managed account; formalise the owner and the terms. Move: the right tool on the wrong account — provision the company-managed tier of the same product and migrate people onto it before you close anything. Retire: remove by default and keep only named exceptions; browser extensions that read every page live here. Register: staff-built prompts, GPTs, skills and automations that others depend on — they need a row and an owner more than they need a rule. Anything you still cannot identify gets a fifth status, investigate, and goes back to move one.
A registry where every row has a next action, and a short list of provisioning tasks for IT.
Open a front door
When there is no way to ask for a tool, people do not stop wanting tools; they stop asking. Every future shadow tool starts there. The front door is one form or channel, one owner, and one promise: a decision within five working days, with the default answer being 'yes, and here is the path' — the managed tier, the data rules, the owner. Intake should be about the problem someone is trying to solve, not the app they found; half the time the registry already has a sanctioned answer.
A standing route for new tools that is faster than going around it.
Pave the path
Now write the usage policy — from the registry, not before it — so it names real tools and real data rules rather than hypotheticals. Put guardrails where the risk actually is: a sandbox for agents and automations, credentials that can be revoked independently of a person's own, circuit breakers on spend. Then, and only then, training: people learn fastest on the tools they already chose, in the workflows they already have, with a manager who visibly backs it.
A policy people can follow, guardrails instead of prohibitions, and training that lands because the structure underneath it exists.
What a registry row looks like.
Seven fields. If a row cannot be filled in, that is a finding, not a formatting problem — usually the missing field is the owner.
- Tool
- Meeting note-taker (Otter) on personal accounts
- Where it lives
- Personal accounts, 6 people in Sales
- Status
- Move — provision one managed note-taker, turn the rest off
- Owner
- Head of Sales (name)
- Can reach
- Every client call it joins; recordings stored by the vendor
- Depends on it
- Pipeline reviews; two customers have asked for transcripts
- Review date
- 90 days from today
Five responses that make it worse.
Banning personal tools
A ban moves usage from tools you can partly see to tools you cannot see at all. The people using AI most effectively are exactly the ones who will route around it, and they were your early adopters.
Mandating usage
Shopify, Meta, Microsoft and Salesforce all learned this in 2026: score usage and you get token-burning, leaderboards and unexamined output thrown over the wall. Usage is not adoption. Reward outcomes and owned workflows, not tokens.
Buying a detection platform first
Detection gives you visibility without ownership: a list of what is running with no name next to any of it. Useful at scale, after the registry exists. Not a substitute for it.
Writing the policy before the inventory
A policy written before the registry describes tools nobody uses and misses the ones everybody does. It becomes decorative within a quarter, and it teaches people that policies are decorative.
Training before the front door
Training people on tools they cannot get, or on workflows nobody owns, teaches them to want things the organisation will not give them. Structure first, enablement fifth.
Every one of these substitutes control for ownership. Control without ownership produces the same result every time: less visibility, the same usage, and a document nobody reads.
Build your registry in five minutes.
The audit asks fourteen questions and gives you a coverage score, the flags that need a decision this week, and a registry with a status and next action on every row. Free, and the score is not gated.
- Generate the usage policy from what the registry says is actually in use.
- Score your readiness across the six pillars the registry does not cover.
- Then the training — on the tools people already chose, with their managers in the room.