Operating guide · 2026

Shadow AI Is Already Inside the Company

A ban can close access to a service. It cannot show where AI already participates in work, what data it receives or which decisions now depend on it.

Reading time
3 minutes
Published through
Astana Hub
Topic
AI Governance and IP
Series
The system around the product

About this edition. Originally published in Russian on Astana Hub. This English site edition focuses on discovery, proportionate triage and a usable permitted route.

Employees usually begin using AI before the company has selected tools and written rules. A personal account compares two documents. A meeting service receives a new transcription feature. A developer connects an assistant to the coding environment. Support finds a faster way to prepare replies.

For one person, the experiment may be entirely rational. The gap appears at company level: the work has changed, but the organisation cannot see the change.

Shadow AI is the use of AI tools or functions outside the organisation's established visibility and control. It can exist inside a familiar and approved service when the account, data, connection or role of the output changes.

See what the company loses from view

The first loss is the data route. A customer request, contract, candidate CV, code fragment or internal discussion may enter a service under settings the company never reviewed.

The second is the role of the output. A draft gradually becomes a customer communication, a code change or a recommendation in a significant decision.

The third is access. An assistant may read folders, email and calendars, create tasks or change code. The service name stays the same while the use case expands.

The fourth is reconstructability. If the important reasoning lives in a personal chat, the team may later have no source, version or explanation for the decision.

Use a ban where it is necessary, but do not stop there

Some data and connections need an immediate stop. Secrets, credentials, restricted personal data and broad unassessed system access cannot be treated as harmless experimentation.

A universal ban without a workable alternative does not remove the employee's task or the benefit they already found. It makes the use less visible.

The first objective is narrower: recover visibility and separate low-risk work from uses that need configuration, a deeper review or a pause.

Run a short discovery window

Ask teams which recurring tasks they already solve with AI. Do not begin with "who broke the rule?"

For each use, record the task, benefit, service, account, input data, role of the output, integrations, possible actions and process owner. Focus on recurring uses whose outputs enter shared work.

Explain the purpose and the route that will follow. If disclosure is presented as a dialogue and then punished automatically, the next layer of shadow use will be harder to find.

Triage by four factors

  1. Data. Public, internal, confidential, personal or access secrets.
  2. Consequence. Idea, draft, recommendation, decision basis or automatic action.
  3. Access and autonomy. One prompt, a connected folder or the ability to act without confirmation.
  4. Scale. A reversible experiment or a repeating process on which a team, customer or product depends.

This supports three practical outcomes: permit under a short rule, permit after configuration and review, or stop pending a separate assessment. A stop is not necessarily permanent. It means the current route cannot continue while the material questions remain unknown.

Make the permitted route easier to use

Give employees a corporate account with reviewed settings, clear examples of permitted use, explicit input boundaries, a fast way to register a new use case and a person who can answer without turning every question into a project.

Return to the record after new data, memory, integrations, a different account or provider, a more consequential output, an automatic action, an incident or an unexpected result.

A one-week discovery exercise will not create a complete AI governance system. It will create the honest picture without which that system cannot begin.

Selected sources

Working in public

Analysis is only useful when the next operational question is visible.

I publish field notes to show how I move from a requirement or risk into product behaviour, control, evidence and ownership.

See the advisory approach

Continue reading

AI Is Already in the Workflow. What Changes Now?

AI rarely enters a company as one large programme. It arrives as a browser tab, a plugin or a familiar service with a new capability.

Read site edition

A Human Clicked Approve. Was the Decision Actually Reviewed?

The button records human presence. Control begins where disagreement can change the outcome.

Read site edition

A Designed System Is Not Yet a Working System

A document can be completed in a week. A mechanism becomes real only where someone makes a decision and either passes through it or works around it.

Read site edition