Governing Shadow AI
By Curtis Hibbs and Joshua Barnes
Fund a response team that carries each case from disclosure to a workable decision.
An enterprise that asks people to disclose hidden AI use needs capacity to respond. We propose a funded AI governance response team with a clear reporting route and a named owner for each case. The team helps people describe the work, brings the right authorities together and follows the case through to an authorized way of working or an explicit change in what must be delivered.
Employees and managers should not have to navigate the organization’s approval procedures themselves. Employees can report directly to the team without a manager’s permission. This does not promise secrecy from the manager: need-based sharing may include a manager responsible for a work decision. Employees need to know where to report, what information to provide and how to respond to an immediate concern. The team supplies the procedural expertise and follow-through. Existing incident, authorization, business and funding authorities retain their decisions.
Shadow AI describes AI use outside an organization’s visibility or authorization. Work already within approved conditions may simply need recording. Unapproved data access or actions need an authorization decision, including inside an approved application. Missing information about AI’s role may need clarification for the recipient of its output.
Betsy Tong’s proposal to invite disclosure of tools, tasks and data directs attention to what people are trying to accomplish. This guide develops a proposed response to that information. Neither the team nor a disclosure campaign is presented as an empirically validated remedy.
Fund the capacity to carry cases through
Give the response team a named executive sponsor, an explicit operating budget and assigned staff capacity. A team may begin small or sit within an existing function, but its work cannot depend entirely on spare time. Its purpose is to coordinate governance responses, not to conduct adversarial testing of AI systems.
The sponsor must secure dependable access to security, privacy, legal, procurement, technology and business specialists as relevant. Agree their response commitments and update dates, identify substitutes when someone is unavailable and provide escalation to the sponsor for missed commitments or unresolved dependencies. Funding a coordinator without securing specialist participation can leave the same unresolved queue behind a new front door.
People report through the team’s published contact route; the team then assigns a case owner who remains responsible for coordination until the work has a usable resolution. That person identifies required decisions, arranges specialist involvement, maintains the shared case record, gives the requester updates and escalates unresolved dependencies. The owner does not acquire permission to waive controls, direct incident response or commit business funds merely by owning the case.
The operating budget makes the team’s direct cost and capacity visible. Specialist time, implementation effort and disruption to the work may sit elsewhere; capture those separately when assessing the broader cost. A funded team creates a place to manage the response, not proof that the response is economical.
The absence of a team budget does not mean the enterprise avoids governance costs. Coordination may be scattered across managers and specialists, with duplicated effort, inconsistent decisions and waiting that increases the cost of delivery. Unmet needs can also leave pressure for continued unauthorized AI use. A funded team may reduce those costs and risks, but that is a proposition to test against the existing arrangement, not a guarantee that the team will always be cheaper.
Establish the response before inviting disclosures
Possible incidents include sensitive information sent through an unauthorized tool, exposed credentials or an AI tool taking an unauthorized action that could cause harm. Employees and managers should promptly report such concerns through the established incident response route. They need not determine whether an incident has occurred: the incident response lead assesses the concern and decides the handling. The response team follows the same rule if a concern reaches its intake first.
Use this operating sequence:
- Prepare: fund response capacity, assign authorities, establish incident routes and agree reporting protections before inviting reports.
- Understand and route: assign a case owner, describe the work and identify existing permission or decisions needed. Suspected incidents go directly to incident response.
- Resolve the work: secure an authorized route, change what has been promised or stop affected work, including an immediate decision about temporary arrangements.
- Check and maintain: evaluate changed arrangements proportionately, confirm the resolution with the people affected and keep reporting open as uses change.
Start within the capacity available and expand the invitation accordingly. Already discovered concerns require action now. Neither team intake nor preparation for broader reporting may delay incident response or the immediate work decision.
Follow the work through one case
Consider a constructed example. A customer cannot export reports from a software product. Earlier troubleshooting has not fixed the problem, so the support team passes the case to a technical specialist. Before choosing the next step, the specialist needs to understand what went wrong and which fixes have already failed. A support employee prepares that summary.
The company has authorized an AI assistant, but it cannot access the support case records needed for the task. The employee instead supplies case information to a personal AI account. Company authorization does not cover that account’s use of case data.
The employee tells the manager. The manager stops further case-data use through that account and contacts the company’s incident response lead, who coordinates the response to possible exposure. The lead arranges assessment of information already sent, data the provider may retain, delivered summaries and decisions they affected. This begins without waiting for the governance response team.
The manager also brings the unresolved work to the response team. Its case owner connects the manager with the leader accountable for the support service, who establishes a safe temporary way to work or changes the service commitment. The owner records that decision and coordinates exploration of an authorized replacement. Exploration can begin once further unauthorized transfers have stopped, exposure assessment is under way and the temporary arrangement or revised commitment is in place; the assessment need not be complete.
The specialist is the summary’s recipient. The customer needs the software to export reports successfully. If the summary omits that reinstalling the software already failed, the specialist might recommend it again, costing the customer time without resolving the problem. Faster summary preparation alone cannot establish less total support work or quicker resolution.
The case owner therefore records the needed output, its recipient, the intended customer contribution and the shortfall in the authorized method. Those facts help the decision-makers judge whether the work is needed and what an adequate alternative must provide.
Make candid reporting possible
Ask what AI has made possible as well as what it has accelerated. Do not assume every unauthorized use results from organizational failure. People may misunderstand policy, prefer a tool, disagree with a restriction or knowingly evade it. PagerDuty’s survey report published in June 2026 documents self-reported use despite perceived prohibition among office professionals in four countries. The vendor-sponsored survey cannot establish an individual’s motive. Investigate circumstances while retaining conduct accountability. Finding a use through technical discovery does not by itself establish deliberate concealment; assess the conduct and its circumstances under the same rules.
Formal protection from discipline may be inadequate if disclosure makes someone look incompetent, replaceable or undeserving of opportunities. In experiments by Reif, Larrick and Soll, people anticipated negative judgments for AI use, and evaluators judged AI users less favorably on competence and motivation. This identifies a potential reporting deterrent, not its prevalence in an enterprise or actual long-term career effects.
Before inviting reports, agree on managers’ basic response: acknowledge the information, address immediate concerns, connect the person with the response route and explain who will follow up. Assess contribution through quality, judgment and responsible behavior, rather than treating AI assistance itself as evidence of low ability. Provide a route outside the immediate manager for retaliation concerns, with someone accountable for investigating adverse treatment.
A protection statement could say: “We will not treat the act of good-faith reporting as evidence of poor performance. We will assess the underlying conduct separately and explain the process. Information will go to people who need it for assessment and response; confidentiality and immunity are not guaranteed.” Authorized leaders and employee-relations and legal specialists must be able to honor the statement. Before collection, explain how conduct such as knowingly prohibited data handling, deliberate concealment or intentional harm will be assessed, and when information must be shared for investigation or applicable obligations. These are limits to explain under the organization’s rules, not a blanket withdrawal of protection for reporting. Reporting does not permit continued prohibited use.
The case owner checks that the work consequence receives a decision. Removing the support employee’s workaround while leaving an impossible workload unchanged makes disclosure costly. Fair treatment and operational follow-through are both part of the enterprise’s capacity to govern.
Give each use the response it needs
The case owner gathers the task, tool/account, data categories and sources, connected systems, actions, recipient, influence on decisions and current authorization. This includes embedded features and integrations: approval of a host application does not authorize every AI action. Limit access to the shared case record to people who need it for assessment, decisions or delivery.
Do not collect complete prompts or customer records by default. Incident evidence belongs in its restricted process. Combine employee context with proportionate authorized technical discovery of uses or connections people overlook. Define purpose, access, retention, privacy limits and applicable employee consultation requirements before monitoring.
Route findings according to their condition:
- Suspected incident: immediate specialist triage of the concerns described above, without waiting for intake or approval. The incident response lead owns that response; the case owner coordinates the associated work decisions without duplicating restricted evidence. Applicable obligations depend on the facts and cannot be waived by a reporting invitation.
- Already authorized: the authorization owner, or someone delegated that check through the organization’s existing authority, confirms that task, data and actions meet existing conditions. The case owner records that confirmation; no fresh approval is needed solely because the inventory was incomplete. A response-team member may perform the check only with that delegation.
- Authorization missing or unclear: the case owner obtains a decision owner, interim work decision and next update date. Priority reflects consequences and business urgency. Apparent low risk and silence do not grant permission.
Avoid turning every repeat question into a new investigation. With the authorization owners, document reusable permitted paths and their conditions. Apply them to matching cases and reopen review when data, actions or other material conditions differ. Keep the reporting route open as uses change.
If AI’s role changes how a recipient should verify, rely on or attribute an output, make that role and relevant checking clear. This does not require announcing every trivial use. The support specialist needs to know that the summary is AI-assisted and what verification occurred.
NIST’s AI Risk Management Framework supports executive responsibility, assigned roles, resourced inventories and ongoing review. It does not establish that this proposed team arrangement will succeed.
Coordinate decisions without transferring their authority
The authorization owner holds the relevant permission decision under existing security, privacy, vendor-risk, procurement or change-control responsibilities. The case owner brings those requirements together; the employee does not have to discover the sequence alone. If responsibility is unclear, escalate to the team’s executive sponsor to secure an explicit assignment before use proceeds.
The workflow owner is the person accountable for operating the resulting work arrangement and accepting it against the agreed conditions. In the support example, the leader accountable for the support service holds this role as well as responsibility for service commitments. These responsibilities may belong to different people elsewhere; name them in the case record.
| Decision | Authority retained by |
|---|---|
| Assess and respond to possible exposure | Incident response lead and relevant specialists |
| Permit a use and set its conditions | Authorization owner |
| Fund and deliver an adequate route | Holder of the relevant implementation budget and named delivery owner |
| Decide temporary work or change commitments | Business leader accountable for that work |
| Accept and operate the resulting arrangement | Workflow owner |
The case owner records reasons, conditions, dependencies and next updates. Escalate missed responses or unresolved disagreements to the executive sponsor, who secures the required decision or resolves the resource conflict through the appropriate authority. The team’s operating budget does not automatically fund every proposed implementation.
Silence does not grant permission. Record which work may continue under existing authority while a decision is pending. In the example, security explains the boundary protecting case information; the support leader owns the consequence for service delivery.
A replacement must provide an acceptable result within necessary boundaries at an acceptable cost. Another approved chat window without usable case information leaves the support problem unresolved. Restricted retrieval, a smaller authorized information set, different work allocation, conventional automation or manual work may be adequate.
The enterprise need not reproduce every preferred feature or newly demonstrated capability. If no safe, viable route meets the outcome, the accountable business leader must change scope, timing or commitments, or stop affected work. The case owner follows through until that decision reaches affected recipients and is implemented.
Where a restriction itself may need revision, Reviewing AI Rules explains how to examine its purpose, dependencies and evidence. Investigation does not suspend it.
Verify the resolution and its cost
Scale evaluation to consequences and obtain actual trial authorization first. A low-consequence drafting change may need a small recipient check; sensitive access or consequential decisions require stronger evidence. Agree acceptance and stopping conditions appropriate to the risks.
For the support example, include representative and difficult cases. The specialist checks whether summaries preserve facts and uncertainties needed for diagnosis. Examine preparation, checking, corrections, elapsed time and control failures. Compare with an authorized baseline; never reproduce unsafe handling for comparison. Note changes in workload, staffing, training or tools that may explain results. A before-and-after observation does not isolate causation, and a small trial cannot establish protection against rare severe failures.
Keep three kinds of evidence separate:
- Visibility and response: understood uses, unanswered cases, time to an interim work decision, time waiting on decisions or delivery, and time to a usable outcome. Track recurring workarounds and reopened cases. Interpret reports alongside authorized discovery and confidential feedback within stated limits. Fewer reports can mean less use or less willingness to speak.
- Control: compliance with access, action permissions and required boundaries. Alerts depend on monitoring coverage and definitions; they are not automatically confirmed breaches or comparable risk rates.
- Value: output quality, total work effort, recipient acceptance and customer consequences. Preserve local benefits while identifying uncertainty about wider improvement.
Track governance cost separately. The case record should distinguish response-team effort, specialist time, implementation cost and disruption such as temporary capacity loss or deferred work. Use proportionate estimates or ranges, state assumptions and avoid counting the same effort twice. Keep uncertain or noncomparable consequences visible rather than forcing them into a falsely precise total. A smaller team budget does not establish lower overall cost or better governance.
The case owner closes a case when the workflow owner confirms a usable authorized route against the agreed checks, or the accountable business leader has implemented the decision to change or stop the work. An approval awaiting delivery is still unresolved work. Record the decision, owners, relevant permissions, observed results, remaining uncertainty and review triggers. Link to restricted incident records; operational closure does not close an incident investigation or remove its obligations.
Hand ongoing responsibility to the workflow owner and reopen the case when conditions materially change or the arrangement fails. Use recurring cases to improve reusable paths and capacity, rather than repeatedly making employees rediscover the process.
Start with one recurring workflow, an accountable sponsor and funded capacity to handle its cases. Test whether this arrangement produces timely, usable decisions at a proportionate cost while respecting controls and improving the work people depend on.