AI Governance and Shadow AI: Two Problems That Share a Solution

Governing sanctioned AI use is the visible half of the problem. Finding the unsanctioned tools employees have already adopted is the half that most organisations miss.

Two halves of the same problem

Most organisations treat AI governance as a policy exercise: write a set of rules about which AI tools may be used, get executive sign-off, publish it, and consider the work done. The result is usually a document that describes an imagined environment while the real one operates differently.

The reason is Shadow AI. Employees adopt AI tools independently — browser extensions, free tiers of consumer services, API-based integrations with productivity tools — because they are useful, free, and one click away. Each instance looks small. Cumulatively, they form an exfiltration surface no one owns.

What sanctioned AI governance covers

  • Which AI tools are approved, and for what kinds of work
  • What categories of data may be sent to those tools
  • How prompts and outputs are logged and reviewed
  • How AI-generated content is verified before use
  • Who is accountable when an AI-produced output causes harm

These are ordinary information governance questions applied to a new class of tool. The mistake is assuming that publishing the answers is sufficient.

Finding Shadow AI

Discovery of unsanctioned AI use is a mixture of technical and cultural work:

  • Network telemetry that identifies traffic to consumer AI endpoints
  • Browser extension audits, since many risks arrive through third-party extensions
  • Reviewing what employees actually use, through anonymous survey rather than only interview
  • Making the sanctioned option genuinely better than the unsanctioned one, so people prefer it

The last point matters most. Shadow AI thrives where sanctioned tools are worse than the free consumer alternatives. Policy alone will not close the gap.

POPIA implications

Personal information sent to an unsanctioned AI service is still a processing operation, still requires a lawful basis, and still creates a POPIA obligation if it leaks. The regulator does not distinguish between authorised and unauthorised tools. From an accountability perspective, the organisation is on the hook either way.

Related in the Knowledge Base

Free Download

Know what an attacker sees before they do.

A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.

Free PDF · No spam · Unsubscribe anytime

Send me the checklist