Skip to main content

drssivanesan.com

What if your organisation’s biggest AI risk isn’t the AI you approved?

What if it is the AI you never knew existed?

For years, organisations worried about Shadow IT. Employees brought their own applications intoe, often without the knowledge or approval of central IT. Then came Shadow Cloud, as teams began adopting infrastructure and services outside established technology governance. Today, we are entering a potentially far more consequential phase: Shadow AI.

Employees are already using AI tools to write reports, analyse contracts, evaluate suppliers, screen candidates, summarise customer interactions, generate code, prepare presentations, interpret data and support business decisions. Many of these tools were never approved by IT, assessed by Risk, reviewed by Internal Audit or included in the organisation’s AI inventory. Yet they are already influencing business outcomes.

That is the beginning of what I call the Shadow AI Economy.


From Shadow IT to Shadow Intelligence

There is a fundamental difference between Shadow IT and Shadow AI. Shadow IT primarily introduces technology risk. Shadow AI can introduce decision risk. An employee using an unauthorised project-management application may create a data-security or compliance issue. An employee using an unapproved AI system to evaluate a customer, interpret a contract, recommend a supplier or assess a candidate can influence an actual business decision.

The distinction is critical because AI does not simply process information. Increasingly, it interprets information, identifies patterns, recommends actions, prioritises alternatives, generates content and, in some cases, executes decisions. This means the governance question can no longer be limited to, “Which AI systems has IT approved?” The more important question is becoming, “Which AI systems are influencing decisions across our organisation?”

Those are very different questions.


The Employee Who Quietly Built an AI Workforce

Consider a relatively ordinary enterprise employee working in procurement. Every week, she uses AI to summarise supplier proposals, compare contract clauses, analyse pricing, identify unusual terms, draft negotiation points and prepare management reports. None of this initially appears particularly dangerous. In fact, she may simply be significantly more productive than she was before.

But consider what has actually happened. She has created a personal AI workflow in which one AI tool summarises information, another analyses documents, a third helps evaluate suppliers and another prepares management recommendations. Individually, each application may appear relatively harmless. Collectively, however, they are influencing procurement decisions, while the organisation may have no visibility into the workflow.

There may be no AI register entry, no model classification, no data-flow assessment, no defined accountability, no monitoring and no independent assurance. Yet business decisions are being shaped by the combined output of these systems.

This is where Shadow AI becomes an enterprise risk.


The Invisible AI Stack

The modern employee may already be working with an invisible AI stack. At the first level, AI is used for personal productivity, helping with writing, research, meeting summaries, presentations and email generation. At the next level, it supports analysis by interpreting data, identifying trends, forecasting outcomes and developing scenarios. Beyond that, AI increasingly influences business decisions through activities such as candidate screening, supplier evaluation, risk assessment, customer prioritisation and financial recommendations.

Generative AI adds another layer, producing reports, contracts, policies, marketing material, code and executive communications. The most significant shift, however, comes with agentic AI, where systems move beyond recommending an action and begin taking the action themselves.

This progression changes the governance challenge fundamentally. We are moving from “AI helped an employee” to “AI influenced a decision”, and increasingly towards “AI executed the decision.” Governance must evolve accordingly.


The Productivity Paradox

Here is the uncomfortable part: Shadow AI is not necessarily bad. In many cases, it is actually good for the organisation. Employees are adopting AI because it makes them faster, reduces repetitive work, improves research, helps them solve problems and allows small teams to achieve more.

Trying to eliminate Shadow AI completely may therefore be both unrealistic and counterproductive. The real challenge is not to ask, “How do we stop employees using AI?” The better question is, “How do we make responsible AI adoption easier than irresponsible AI adoption?”

That requires a fundamentally different governance philosophy.


The Four Risks of Shadow AI

The first risk is data leakage. Employees may unknowingly place customer information, confidential documents, intellectual property, financial information, employee data or strategic plans into AI platforms operating outside the organisation’s approved environment. The behaviour may not be malicious. It may simply be convenient.

The second risk is decision contamination. An AI-generated recommendation may enter an official business process without being identified as AI-generated. A manager may believe that the analysis came from the team when, in reality, an AI system performed much of the analysis and the team simply accepted its output. This distinction becomes particularly important when the decision subsequently produces an adverse outcome.

The third risk is accountability dilution. When an AI recommendation contributes to a consequential business decision, responsibility can become unclear. Is the employee accountable? The manager? The technology team? The business process owner? The AI vendor? The model itself? If accountability is not established before AI becomes embedded in the process, resolving responsibility after an incident becomes considerably more difficult.

The fourth – and perhaps most dangerous – risk is control blindness. An organisation cannot govern what it cannot see. It may have an AI policy, an AI governance committee, an approved AI inventory and formal AI risk assessments, while significant AI activity continues outside all of them. This creates a dangerous illusion of control.


The AI Governance Gap

Traditional GRC generally operates around known assets. We identify the system, identify the owner, classify the risk, define controls and monitor compliance. Shadow AI creates a different problem because the asset itself may be invisible.

The documented process may show an employee analysing supplier proposals, preparing recommendations and submitting them for approval. The actual process may involve an employee uploading those proposals into several external AI systems, combining the outputs and then presenting the resulting recommendation to management.

The official process remains unchanged on paper.

The operational reality has changed completely.

This is why Shadow AI should not be treated simply as another cybersecurity issue. It is fundamentally an enterprise governance problem.


The Internal Audit Blind Spot

Internal Audit faces an equally interesting challenge. Traditional audits often begin with the question, “Show me the systems supporting this process.” But with Shadow AI, that answer may be incomplete.

The actual workflow could look like this: an employee interacts with an AI tool, receives an analysis, moves the output into another AI system, combines the resulting recommendations and ultimately enters the final information into an official business system. Only the final system may appear in the organisation’s process documentation.

The AI interactions in the middle remain invisible.

This creates what I would call the Invisible Control Layer: the difference between how the organisation believes work is being performed and how work is actually being performed with AI.

Internal Audit therefore needs to ask a different question: “Show me how the work is actually being performed – not simply how the process is documented.”

That distinction could become increasingly important as AI becomes embedded in everyday workflows.


A New Classification: AI by Decision Impact

I believe organisations should begin classifying AI not only by technology but also by business impact.

AI used for personal productivity may present relatively low governance risk when it has no material influence on organisational decisions. AI used for analytical support deserves greater scrutiny because it influences how employees interpret information. AI used for business decision support requires stronger governance because it materially influences outcomes. AI that makes or executes consequential decisions demands the highest level of oversight.

The principle is simple: the greater the decision impact, the greater the governance requirement.

An AI tool generating a meeting summary should not require the same controls as an AI system recommending who receives a loan, which supplier receives a major contract or which customer should receive enhanced scrutiny.


What Boards Should Be Asking

Board conversations about AI often focus on cybersecurity, privacy, regulation, model risk, investment and productivity. All of these remain important. But Shadow AI introduces a different set of governance questions.

Do we know how many AI tools are actually being used across the organisation, rather than simply how many have been approved by IT? Can employees clearly distinguish between acceptable and unacceptable AI use, or is our AI policy simply sitting on the intranet? Which business processes are already being influenced by AI? Are AI-generated outputs identifiable when they enter critical workflows? Who owns the risk when an employee uses AI to support a consequential decision? Can Internal Audit independently identify AI usage outside the official AI inventory?

And perhaps the most important question of all is this:

Are we governing AI adoption – or merely governing AI procurement?


From AI Policy to AI Visibility

Most organisations are rushing to create AI policies, and that is necessary. But policy alone will not solve Shadow AI. Organisations need AI visibility.

That begins with discovery: identifying where AI is actually being used across the organisation. It then requires classification, determining whether the AI is being used for productivity, analysis, decision support or autonomous action. The next step is assessment, including data sensitivity, decision impact, regulatory exposure, third-party risk and operational consequences.

Governance must then apply controls proportionate to the risk, followed by continuous assurance to determine whether actual AI usage remains consistent with organisational policy.

This moves the organisation from AI Governance towards AI Governance plus AI Observability.

The Future May Not Be “Human vs AI”

That is the wrong debate.

The real transformation is increasingly becoming Human + AI + AI + AI.

Employees will assemble their own AI ecosystems. Some will be formally approved. Some will remain unofficial. Some will disappear after a few months, while others will become deeply embedded in critical workflows. Eventually, some employees may effectively manage AI agents as digital colleagues.

The organisational chart may continue to show employee, manager, director and executive. But the operational reality could increasingly involve employees directing AI agents, AI agents interacting with other AI agents, those agents accessing business systems and the resulting activity influencing organisational decisions.

Our governance architecture needs to catch up with that reality.


The New Three Lines of Defence

The traditional Three Lines model remains valuable, but AI adoption requires a broader perspective.

The first line, the business, must understand acceptable AI use and own the risks created by its workflows. The second line, Risk and Compliance, needs visibility across AI usage, decision impact, data exposure and regulatory requirements. The third line, Internal Audit, must independently assess not only whether AI controls exist but whether employees are actually operating within them.

There is also an emerging capability that deserves greater attention: Continuous AI Assurance.

AI usage can change significantly faster than the traditional audit cycle. The question is therefore no longer simply, “Was this AI system compliant when we approved it?”


It is becoming:

“Is AI being used responsibly today?”

The Emerging Risk: Governance Debt

There is another risk we should begin discussing: AI Governance Debt.

Just as organisations accumulate technical debt when technology grows faster than architecture, they can accumulate governance debt when AI adoption grows faster than oversight.

Every unofficial AI tool adds a small amount of governance debt. Every undocumented AI workflow adds more. Every unclassified AI-supported decision adds further exposure. Eventually, an organisation can reach a point where it can no longer answer a basic question:

“Where is AI influencing our business?”

At that point, governance becomes considerably more expensive because the organisation is no longer governing deployment. It is attempting to reconstruct history.


One Idea Worth Sharing

The biggest AI risk may not come from an AI system that breaks the rules. It may come from thousands of employees using AI perfectly reasonably – but outside the organisation’s visibility.

That is what makes Shadow AI different.

It does not necessarily look like an attack. It does not necessarily look like misconduct. It does not necessarily look like a traditional control failure.

It often looks like productivity.

And that is precisely why it can be so difficult to govern.

Boardroom Cue

At your next Board, Risk Committee or Audit Committee meeting, ask one question:

“Can we identify every AI system currently influencing material business decisions across our organisation – including those that have never gone through our formal AI governance process?”

If the answer is “We don’t know,” you may not simply have an AI problem.

You may have something more fundamental.

You have an AI visibility problem.

And you cannot govern what you cannot see.


Final Thought

The first phase of enterprise AI was about adoption. The second phase is about integration. The next phase will be about accountability.

The organisations that succeed will not necessarily be those that restrict AI the most, nor will they necessarily be those that deploy it the fastest. They will be the organisations that create an environment where innovation is encouraged, experimentation is visible, risk is understood, accountability is clear and AI adoption remains aligned with organisational values and risk appetite.

Because the real question is no longer:

“Does our organisation use AI?”

Almost certainly, it does.


The question boards should now be asking is:

“How much of our organisation is already being influenced by AI that we don’t know about?”

That is the Shadow AI Economy. the workplace, often without the knowledge or approval of central IT. Then came Shadow Cloud, as teams began adopting infrastructure and services outside established technology governance. Today, we are entering a potentially far more consequential phase: Shadow AI.

Employees are already using AI tools to write reports, analyse contracts, evaluate suppliers, screen candidates, summarise customer interactions, generate code, prepare presentations, interpret data and support business decisions. Many of these tools were never approved by IT, assessed by Risk, reviewed by Internal Audit or included in the organisation’s AI inventory. Yet they are already influencing business outcomes.

That is the beginning of what I call the Shadow AI Economy.

From Shadow IT to Shadow Intelligence

There is a fundamental difference between Shadow IT and Shadow AI. Shadow IT primarily introduces technology risk. Shadow AI can introduce decision risk. An employee using an unauthorised project-management application may create a data-security or compliance issue. An employee using an unapproved AI system to evaluate a customer, interpret a contract, recommend a supplier or assess a candidate can influence an actual business decision.

The distinction is critical because AI does not simply process information. Increasingly, it interprets information, identifies patterns, recommends actions, prioritises alternatives, generates content and, in some cases, executes decisions. This means the governance question can no longer be limited to, “Which AI systems has IT approved?” The more important question is becoming, “Which AI systems are influencing decisions across our organisation?”

Those are very different questions.


The Employee Who Quietly Built an AI Workforce

Consider a relatively ordinary enterprise employee working in procurement. Every week, she uses AI to summarise supplier proposals, compare contract clauses, analyse pricing, identify unusual terms, draft negotiation points and prepare management reports. None of this initially appears particularly dangerous. In fact, she may simply be significantly more productive than she was before.

But consider what has actually happened. She has created a personal AI workflow in which one AI tool summarises information, another analyses documents, a third helps evaluate suppliers and another prepares management recommendations. Individually, each application may appear relatively harmless. Collectively, however, they are influencing procurement decisions, while the organisation may have no visibility into the workflow.

There may be no AI register entry, no model classification, no data-flow assessment, no defined accountability, no monitoring and no independent assurance. Yet business decisions are being shaped by the combined output of these systems.

This is where Shadow AI becomes an enterprise risk.


The Invisible AI Stack

The modern employee may already be working with an invisible AI stack. At the first level, AI is used for personal productivity, helping with writing, research, meeting summaries, presentations and email generation. At the next level, it supports analysis by interpreting data, identifying trends, forecasting outcomes and developing scenarios. Beyond that, AI increasingly influences business decisions through activities such as candidate screening, supplier evaluation, risk assessment, customer prioritisation and financial recommendations.

Generative AI adds another layer, producing reports, contracts, policies, marketing material, code and executive communications. The most significant shift, however, comes with agentic AI, where systems move beyond recommending an action and begin taking the action themselves.

This progression changes the governance challenge fundamentally. We are moving from “AI helped an employee” to “AI influenced a decision”, and increasingly towards “AI executed the decision.” Governance must evolve accordingly.


The Productivity Paradox

Here is the uncomfortable part: Shadow AI is not necessarily bad. In many cases, it is actually good for the organisation. Employees are adopting AI because it makes them faster, reduces repetitive work, improves research, helps them solve problems and allows small teams to achieve more.

Trying to eliminate Shadow AI completely may therefore be both unrealistic and counterproductive. The real challenge is not to ask, “How do we stop employees using AI?” The better question is, “How do we make responsible AI adoption easier than irresponsible AI adoption?”

That requires a fundamentally different governance philosophy.


The Four Risks of Shadow AI

The first risk is data leakage. Employees may unknowingly place customer information, confidential documents, intellectual property, financial information, employee data or strategic plans into AI platforms operating outside the organisation’s approved environment. The behaviour may not be malicious. It may simply be convenient.

The second risk is decision contamination. An AI-generated recommendation may enter an official business process without being identified as AI-generated. A manager may believe that the analysis came from the team when, in reality, an AI system performed much of the analysis and the team simply accepted its output. This distinction becomes particularly important when the decision subsequently produces an adverse outcome.

The third risk is accountability dilution. When an AI recommendation contributes to a consequential business decision, responsibility can become unclear. Is the employee accountable? The manager? The technology team? The business process owner? The AI vendor? The model itself? If accountability is not established before AI becomes embedded in the process, resolving responsibility after an incident becomes considerably more difficult.

The fourth – and perhaps most dangerous – risk is control blindness. An organisation cannot govern what it cannot see. It may have an AI policy, an AI governance committee, an approved AI inventory and formal AI risk assessments, while significant AI activity continues outside all of them. This creates a dangerous illusion of control.


The AI Governance Gap

Traditional GRC generally operates around known assets. We identify the system, identify the owner, classify the risk, define controls and monitor compliance. Shadow AI creates a different problem because the asset itself may be invisible.

The documented process may show an employee analysing supplier proposals, preparing recommendations and submitting them for approval. The actual process may involve an employee uploading those proposals into several external AI systems, combining the outputs and then presenting the resulting recommendation to management.

The official process remains unchanged on paper.

The operational reality has changed completely.

This is why Shadow AI should not be treated simply as another cybersecurity issue. It is fundamentally an enterprise governance problem.


The Internal Audit Blind Spot

Internal Audit faces an equally interesting challenge. Traditional audits often begin with the question, “Show me the systems supporting this process.” But with Shadow AI, that answer may be incomplete.

The actual workflow could look like this: an employee interacts with an AI tool, receives an analysis, moves the output into another AI system, combines the resulting recommendations and ultimately enters the final information into an official business system. Only the final system may appear in the organisation’s process documentation.

The AI interactions in the middle remain invisible.

This creates what I would call the Invisible Control Layer: the difference between how the organisation believes work is being performed and how work is actually being performed with AI.

Internal Audit therefore needs to ask a different question: “Show me how the work is actually being performed – not simply how the process is documented.”

That distinction could become increasingly important as AI becomes embedded in everyday workflows.


A New Classification: AI by Decision Impact

I believe organisations should begin classifying AI not only by technology but also by business impact.

AI used for personal productivity may present relatively low governance risk when it has no material influence on organisational decisions. AI used for analytical support deserves greater scrutiny because it influences how employees interpret information. AI used for business decision support requires stronger governance because it materially influences outcomes. AI that makes or executes consequential decisions demands the highest level of oversight.

The principle is simple: the greater the decision impact, the greater the governance requirement.

An AI tool generating a meeting summary should not require the same controls as an AI system recommending who receives a loan, which supplier receives a major contract or which customer should receive enhanced scrutiny.


What Boards Should Be Asking

Board conversations about AI often focus on cybersecurity, privacy, regulation, model risk, investment and productivity. All of these remain important. But Shadow AI introduces a different set of governance questions.

Do we know how many AI tools are actually being used across the organisation, rather than simply how many have been approved by IT? Can employees clearly distinguish between acceptable and unacceptable AI use, or is our AI policy simply sitting on the intranet? Which business processes are already being influenced by AI? Are AI-generated outputs identifiable when they enter critical workflows? Who owns the risk when an employee uses AI to support a consequential decision? Can Internal Audit independently identify AI usage outside the official AI inventory?

And perhaps the most important question of all is this:

Are we governing AI adoption – or merely governing AI procurement?


From AI Policy to AI Visibility

Most organisations are rushing to create AI policies, and that is necessary. But policy alone will not solve Shadow AI. Organisations need AI visibility.

That begins with discovery: identifying where AI is actually being used across the organisation. It then requires classification, determining whether the AI is being used for productivity, analysis, decision support or autonomous action. The next step is assessment, including data sensitivity, decision impact, regulatory exposure, third-party risk and operational consequences.

Governance must then apply controls proportionate to the risk, followed by continuous assurance to determine whether actual AI usage remains consistent with organisational policy.

This moves the organisation from AI Governance towards AI Governance plus AI Observability.

The Future May Not Be “Human vs AI”

That is the wrong debate.

The real transformation is increasingly becoming Human + AI + AI + AI.

Employees will assemble their own AI ecosystems. Some will be formally approved. Some will remain unofficial. Some will disappear after a few months, while others will become deeply embedded in critical workflows. Eventually, some employees may effectively manage AI agents as digital colleagues.

The organisational chart may continue to show employee, manager, director and executive. But the operational reality could increasingly involve employees directing AI agents, AI agents interacting with other AI agents, those agents accessing business systems and the resulting activity influencing organisational decisions.

Our governance architecture needs to catch up with that reality.


The New Three Lines of Defence

The traditional Three Lines model remains valuable, but AI adoption requires a broader perspective.

The first line, the business, must understand acceptable AI use and own the risks created by its workflows. The second line, Risk and Compliance, needs visibility across AI usage, decision impact, data exposure and regulatory requirements. The third line, Internal Audit, must independently assess not only whether AI controls exist but whether employees are actually operating within them.

There is also an emerging capability that deserves greater attention: Continuous AI Assurance.

AI usage can change significantly faster than the traditional audit cycle. The question is therefore no longer simply, “Was this AI system compliant when we approved it?”


It is becoming:

“Is AI being used responsibly today?”

The Emerging Risk: Governance Debt

There is another risk we should begin discussing: AI Governance Debt.

Just as organisations accumulate technical debt when technology grows faster than architecture, they can accumulate governance debt when AI adoption grows faster than oversight.

Every unofficial AI tool adds a small amount of governance debt. Every undocumented AI workflow adds more. Every unclassified AI-supported decision adds further exposure. Eventually, an organisation can reach a point where it can no longer answer a basic question:

“Where is AI influencing our business?”

At that point, governance becomes considerably more expensive because the organisation is no longer governing deployment. It is attempting to reconstruct history.

One Idea Worth Sharing

The biggest AI risk may not come from an AI system that breaks the rules. It may come from thousands of employees using AI perfectly reasonably – but outside the organisation’s visibility.

That is what makes Shadow AI different.

It does not necessarily look like an attack. It does not necessarily look like misconduct. It does not necessarily look like a traditional control failure.

It often looks like productivity.

And that is precisely why it can be so difficult to govern.

Boardroom Cue

At your next Board, Risk Committee or Audit Committee meeting, ask one question:

“Can we identify every AI system currently influencing material business decisions across our organisation – including those that have never gone through our formal AI governance process?”

If the answer is “We don’t know,” you may not simply have an AI problem.

You may have something more fundamental.

You have an AI visibility problem.

And you cannot govern what you cannot see.


Final Thought

The first phase of enterprise AI was about adoption. The second phase is about integration. The next phase will be about accountability.

The organisations that succeed will not necessarily be those that restrict AI the most, nor will they necessarily be those that deploy it the fastest. They will be the organisations that create an environment where innovation is encouraged, experimentation is visible, risk is understood, accountability is clear and AI adoption remains aligned with organisational values and risk appetite.

Because the real question is no longer:

“Does our organisation use AI?”

Almost certainly, it does.

The question boards should now be asking is:

“How much of our organisation is already being influenced by AI that we don’t know about?”

That is the Shadow AI Economy.

And it may already be operating inside your organisation.


I would be interested to hear from fellow Board Directors, CIOs, CROs, CISOs, Internal Auditors and AI Governance Leaders:

Does your organisation know where AI is actually being used – or only where AI has been officially approved?

#StraitsTribe #AI #ShadowAI #AIGovernance #GRC #RiskManagement #InternalAudit #BoardGovernance #AgenticAI #DigitalTransformationn

Nesan Sivakaruniam
×