Governing AI before the regulation arrives

Governing the AI you didn't approve

Roughly 80% of workers use AI tools their employer hasn't sanctioned, and IT can see under a fifth of them. Shadow AI isn't an edge case to police — it's the default state of any organisation that hasn't looked.

Every organisation I have looked at has more AI in it than its leadership believes. Not slightly more. Categorically more.

The numbers are consistent across surveys from 2025 and 2026, and they are not close. Around 80% of workers use AI tools their employer has not approved. 98% of organisations have employees using unsanctioned AI somewhere. And IT teams have visibility into fewer than 20% of the AI applications their people actually use.

That last figure is the one that matters. The gap between what is happening and what is visible is not a rounding error. It is four fifths of the problem.

This is not a junior-staff problem

The comfortable version of this story is that a few enthusiastic analysts are pasting things into a chatbot. That version is wrong, and the data on who is doing it is the most uncomfortable part of the research.

Nearly 90% of security professionals report using unapproved AI tools themselves. The people writing the policy are among the people breaking it. In the public sector, 70% of staff use AI without their manager’s knowledge when no approved tool has been provided.

Read those two findings together and the shape of the problem changes. This is not defiance. It is what happens when a capability arrives faster than a sanctioned way to use it, and the people best placed to understand the risk conclude — often correctly — that the productivity gain is worth it.

You cannot police your way out of that. You can only out-provide it.

What is actually leaving the building

The leakage profile is specific enough to act on.

38% of employees report sharing sensitive company information with AI tools without permission. Analysis of what people paste into consumer chat interfaces suggests roughly 11% of it is confidential — customer records, contract terms, source code, unreleased financials, and in regulated sectors, personal data that carries statutory handling obligations.

The financial consequence is measurable. IBM’s 2025 breach reporting puts the additional cost of a breach at organisations with high shadow-AI exposure at around $670,000 above those with low exposure. That is not the cost of the breach. That is the premium for not knowing what tools your data was in.

And detection lags badly, because nothing alerts. A employee pasting a client list into a personal AI account generates no security event. There is no failed login, no anomalous transfer, no policy violation your DLP was configured to catch. The first signal is usually external.

The embedded problem nobody inventories

Here is the part that catches even organisations that have run a shadow AI exercise.

Most shadow AI is no longer a person visiting a website. It is a feature that arrived inside software you already bought. A note-taker in your meeting platform. A summarisation feature in your ticketing system. A drafting assistant that appeared in a product update and defaulted to on.

Nobody procured those. Nobody assessed them. They did not go through vendor review because the vendor was already approved — for something else, under terms written before generative AI existed. The register that lists your approved suppliers will tell you nothing about which of them started processing your data through a model last quarter.

When you run the inventory, the question is not “what AI tools have people signed up for”. It is “which of our existing systems have added AI features, what data do those features touch, and what do the terms say about training”.

Why the policy you have probably isn’t working

Only 43% of organisations have an AI governance policy at all. Of those that do, the implementation gap is severe — and only 17% of boards exercise any oversight of AI governance, which means most policies have no one senior enough to enforce them.

But the deeper failure is design, not enforcement. A prohibition without a sanctioned alternative does not reduce usage. It relocates it — from tools you could have configured and logged, to personal accounts you cannot see, on devices you do not manage.

The 70% figure from the public sector research is the clearest evidence of this. The variable was not policy strength. It was whether an approved tool had been provided.

What I would actually do

Four things, in this order.

Discover before you legislate. Do not start with a survey — people under-report, and the ones using AI most productively are the least likely to volunteer it. Start with signals they do not control: network and DNS logs, identity provider sign-in records for AI domains, and expense claims. Corporate cards find more shadow AI than questionnaires do. Then run the second inventory: which approved vendors have shipped AI features into products you already use.

Provide the sanctioned path first. Before you prohibit anything, have something to point at. A tenancy you control, with retention disabled, logging on, and terms that say the provider will not train on your inputs. Make it easier to use than the consumer version, or you have simply added friction to the compliant route.

Classify, then set rules per tier — not per tool. Tool-by-tool policies date instantly. Data-tier rules survive. Green data can go to a public tier. Amber requires a contracted tenancy. Red does not leave the boundary, whatever the tool. That framing survives the next product launch; a list of approved vendor names does not.

Give the register an owner and a cadence. A one-off discovery exercise produces a document that is wrong within a quarter. The register has to be live, and someone has to be accountable for it — which, per the governance baseline, means a named executive rather than a distributed hope.

The regulatory edge of this

For anyone operating in Sub-Saharan Africa, this stops being a productivity question and becomes a compliance one quickly.

Nigeria’s GAID 2025 requires data protection impact assessments for high-risk AI processing. You cannot assess what you have not inventoried. South Africa’s King V Code places AI governance on the governing body, with director-level consequences. Kenya’s Data Protection Act imposes controller accountability for all processing, including processing nobody authorised.

None of those obligations contain an exception for AI you did not know about. Shadow AI is not a gap in your policy. It is unassessed processing, sitting inside your existing legal obligations, generating exposure that will be attributed to you regardless of whether it was approved.

The organisations that handle this well are not the ones with the strictest policy. They are the ones that looked first, provided a real alternative second, and wrote the rules third.