Council Post: How Shadow AI Is Rapidly Outpacing Enterprise Risk Management
Luiz Domingos is Chief Technology Officer at Mitel.gettyEvery major enterprise today is investing in AI governance, yet employees are adopting AI faster than governance programs can keep up. This growing discon...
Luiz Domingos is Chief Technology Officer at Mitel.

getty
Every major enterprise today is investing in AI governance, yet employees are adopting AI faster than governance programs can keep up. This growing disconnect has given rise to a new form of shadow IT: shadow AI. Unlike traditional shadow IT, it can influence decisions, generate content, automate workflows and increasingly act on behalf of employees, often outside approved enterprise controls.
For many organizations, this behavior is driven by friction. When approved systems feel fragmented, slow or disconnected from how work happens, workers adapt by using unapproved tools to help them communicate and complete tasks more efficiently, though this creates a disconnect between enterprise governance and day-to-day operations.
According to Mitel’s recent State of Workforce Communication research, 76% of workers report using non-approved channels for work-related communication. Couple that number with accelerating AI adoption across the enterprise, and the potential risks posed by so-called shadow AI only grow larger.
Shadow AI is not primarily a technology problem; it is a workflow design problem. Employees rarely seek unauthorized tools because they want to bypass IT. They seek them because approved systems fail to remove friction from the work they need to accomplish.
The challenge for technology leaders no longer lies in restricting unauthorized tools or devising new communication policies but in understanding why employees are bypassing approved systems in the first place.
Shadow AI Is A Natural By-product Of Workflow Friction
Most organizations approach AI from the top down: focusing on models, infrastructure, governance, deployment speed and investment. Employees experience AI from the bottom up, through the tasks they perform every day.
The gap between workers’ needs and business leaders’ goals creates ideal conditions for shadow AI. For example, Gartner identified shadow AI as one of the GenAI blind spots CIOs need to address, citing research that found 69% of organizations suspect or have evidence that employees are using prohibited public GenAI. That disconnect can emerge when pressure to deliver productivity gains outpaces the approved tools, training and governance employees need to use AI effectively. As a result, they often experiment independently with publicly available AI tools, which can exacerbate governance issues.
In many cases, those tools are filling legitimate operational needs, including faster access to information, simplified communication workflows, task automation and reduced administrative burden.
Most employees are acting rationally within the constraints of their work environment. When approved systems slow work down, they naturally seek alternatives that help them accomplish their tasks more efficiently.
Tool Overload Is Fueling Unauthorized Technology Use
Today, employees operate across a sprawling mix of communication platforms, collaboration apps, messaging tools and AI assistants. Workforce data also indicates that workers use an average of seven communication tools daily. Rising complexity and constant switching between tools increase both workflow friction and operational risk.
Every additional AI assistant introduces another decision point: Which assistant should I use? Which one has the right data? Which one is approved? Ironically, AI intended to simplify work can increase complexity when introduced without an integrated workflow strategy.
This fragmentation is especially pronounced among front-line workers, who often need fast, reliable communication under pressure. When approved tools cannot deliver speed or usability, employees naturally gravitate toward tools that can, often outside of approved tech stacks.
The Real Risk Is Loss Of Visibility
Most conversations in technology circles about shadow AI naturally focus on security concerns, zeroing in on data leakage, compliance exposure and intellectual property risk. But one of the more immediate risks is around operational visibility. Organizations are gradually losing visibility into where AI is being used, what information it can access, how decisions are being influenced and, increasingly, what autonomous actions AI is taking.
When employees move work into non-approved systems, organizations lose sight of how decisions are made, where information flows and how AI-generated outputs influence their operations. That gap becomes harder to close as AI tools and agents operate with legitimate user access, in unmanaged environments or through connected systems that may not appear in traditional IT inventories.
Recent CISO-focused reporting found that 92% of organizations lack full visibility into AI identities, while 95% doubt they could detect misuse if it happened. Poor visibility quickly evolves from a technology problem into a business continuity and service-delivery problem, especially as AI becomes embedded into daily workflows and even begins to act autonomously.
To address this, IT decision-makers must get to the root of the operational friction driving unapproved tool usage.
What Technology Leaders Should Focus On Now
Shadow AI often signals a mismatch between enterprise systems and real operational workflows.
Technology leaders should focus on:
• Designing for adoption, not just governance; approved tools must be easier to use than unapproved alternatives.
• Reducing workflow fragmentation before adding more AI; AI cannot compensate for broken processes.
• Embedding AI where work already happens; don’t require employees to switch contexts.
• Treating governance as an enabler; the objective is trusted adoption, not restrictive control.
• Measuring operational behavior instead of just AI usage; understand where employees experience friction before deploying new AI capabilities.
The workforce is under pressure to move faster in environments where communication and collaboration have become increasingly complex. As enterprise AI adoption accelerates, organizations cannot govern their way out of workflow problems. They must design communication and AI environments that workers actually want to use and ensure that approved systems are easier, faster and more useful than alternatives.
As AI agents begin acting on behalf of users, not just assisting them, the governance challenge shifts from managing software to managing autonomous digital workers.
Shadow AI is rarely the root problem. It is usually a symptom. Organizations that focus only on restricting AI will continue chasing new tools as they emerge. Organizations that reduce workflow friction, embed AI into trusted systems and make approved tools the easiest way to work will be far better positioned to scale AI safely and successfully.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?