“Shadow AI: Banning Is Not Governing”

Published in collaboration with Andrea Zurini’s“Digital Innovation Review”
In the summer of 2025, in one of the most closely monitored governments on the planet, a series of automated alerts began to go off. Sensors operated by the Department of Homeland Security (DHS)—the U.S. agency responsible for internal security—and systems that monitor what enters and exits federal networks had detected internal documents uploaded to the public version of ChatGPT.
When the technicians traced the chain back, they came across a name they hadn’t expected: the acting director of CISA, the federal agency that protects the United States’ critical infrastructure. At least four contractual documents marked “For Official Use Only” (sensitive, for internal use only, unclassified) were uploaded to the public version of the chatbot. This was revealed by Politico in late January 2026, citing four department officials.
The detail that turns this news story into a parable is something else entirely. At DHS, ChatGPT was blocked for most employees precisely because of the risk of data leakage. Shortly after taking office, the director had requested and obtained special permission. The rule was in place; he was the authorized exception. And when he exercised that exception, it was his own agency’s monitoring systems that detected it.
If this happens at the very top of America’s most heavily defended perimeter—where security checks are in place and the alarms actually work—what’s going on in an ordinary office, where there aren’t any sensors?
AI has already been adopted at your company. It’s just that no one decided to do it.
The Italian Paradox
The Italian figures tell the same story in statistical terms. TheArtificial Intelligence Observatory at the Politecnico di Milano has captured two sides of the same phenomenon. The official side: the Italian AI market is worth 1.8 billion euros, having grown by 50% in one year. The corporate side: 24% of large companies prohibit the use of generative AI tools not provided by the organization, and only four out of ten large companies have established guidelines for their use.
In the middle lies the statistic that debunks both sides: among workers who actually use AI, just 19% say they do so exclusively with company-provided tools. The other eight out of ten rely, at least in part, on tools that the company has never provided—or even seen.
Moreover, this trend shows no signs of slowing down. The survey by the HR Innovation Observatory—also at the Politecnico—based on a representative panel of 1,500 workers, shows that the percentage of employees using AI tools not provided by their company rose from 27% to 34% in one year; 51% use external tools alongside or in place of company solutions.
There is, however, a limitation to all these numbers: they are self-reported, and they measure what people admit to doing. Telemetry measures what people actually do, and it’s more rigorous: by observing corporate browsers from the inside, LayerX finds that 77% of employees paste data into generative AI tools, and that 82% of this activity occurs through personal accounts, outside of any oversight.
A ban does not eliminate use. It eliminates the visibility of use. Those who chose prohibition haven’t solved a single problem—they’ve created another one, because the phenomenon they’re supposed to regulate is now officially invisible.
The Question Nobody Heard
It’s tempting to interpret this phenomenon through the lens of the discipline itself: employees who break the rules, so we need stricter rules. That’s the most common interpretation—and it’s the wrong one.
No one pastes a contract into ChatGPT to defy the legal department. They do it because they’ve found something that works—something that gives them in thirty seconds what used to take an hour—and the organization hasn’t offered them anything equivalent. This “under-the-radar” AI isn’t insubordination: it’s an unanswered demand for productivity that has organized itself.
Anyone with enough experience in the workplace will recognize this scenario. Twenty years ago, it was called “shadow IT”: personal email accounts, USB drives, and cloud services set up under the radar. It took organizations years to realize that this chaos wasn’t sabotage. It was a poorly written list of the needs they hadn’t listened to.
There is, however, a difference in nature, even more so than in scale. Shadow IT moved files: documents that already existed, duplicated in the wrong place. Shadow AI moves lines of reasoning. It’s not just the attachment that ends up in the prompt. It also contains the company’s problem, fully articulated: the strategy explained to the AI to seek its help, the contract pasted in to have it summarized, and the customer data contextualized better than it is in any management system. It’s the difference between losing an archive and losing the thinking that interprets it.
Governing, then, does not mean liberalizing everything or buying the first tool with the word “enterprise” in its name. It means three steps, in the right order: assessing the situation before drafting any policy; providing an official channel that can compete with the unofficial one, because no ban can withstand the competition from a tool that works; and training people to recognize what comes out of a prompt.
And today, the official channel can take two forms: a business contract with written commitments regarding data use, or open-source models operated under the company’s own control. These are two legitimate approaches, each with different costs and skill requirements. The third option—choosing not to choose—leaves employees on their own with their personal accounts: and it is the worst of the three.
The ban addresses the risk. The government addresses the demand. And since the demand is real, only the second response is sustainable.
Andrea Zurini
Consultant and trainer in artificial intelligence and digital transformation.
Instructor for the AI Super Power Master’s program at H-FARM Business School.
He writes the newsletter Digital Innovation Review.
This text is an excerpt. The full article also explores where these hidden conversations end up (a commercial supply chain documented by an investigation that has received little coverage in Italy), the hunger for data among those who build these models—from the program Anthropic used to purchase and dissect millions of printed books to the different treatment of business contracts versus personal accounts—and the resulting governance decisions.
Published on August 4 in Digital Innovation Review – Shadow AI: The Underground Economy of Artificial Intelligence