AI Controls and Governance

What is shadow AI and how do I manage it?

Somewhere in your organisation today, someone pasted part of a client document into an AI tool nobody approved, got a useful answer, and shipped the result as their own work. No record exists of the question, the context they provided, or the output they relied on. The work was probably better for it. That's what makes this hard.

Shadow AI is usually framed as a security problem, and the standard response has been a security response: block the unapproved tools, approve a sanctioned one, declare the matter managed. That response solves something real. It also misses most of the problem — because the shadow was never really about which tool was used. It was about what flowed through it, and where the output went.

What Shadow AI is

Shadow AI is the use of AI tools and capabilities inside an organisation without that organisation's knowledge, approval, or governance. It is the successor to shadow IT, and it spreads faster for a simple reason: an AI tool requires no procurement, no installation, and no integration to be useful. A browser tab and a paste are enough. Any employee with a deadline and a chatbot is a potential adoption event.

It is worth being honest about why it happens, because the cause shapes the fix. People do not use unsanctioned AI tools out of recklessness. They use them because the tools work — because the unsanctioned path answers their question in thirty seconds and the sanctioned path either doesn't exist or doesn't know anything about their actual job. Shadow AI is, among other things, demand evidence: a live map of where the organisation's approved tooling is failing the people doing the work. Demand evidence is not permission — the fact that people route around governance doesn't make the behaviour acceptable. It tells you where the governed path is failing, which is a different and more useful thing to know.

The Two Problems Wearing One name

"Managing shadow AI" conflates two problems that need different owners and different fixes.

The first is the tool problem: which AI services may be used at all, with what data, under what terms. This is genuinely a security and procurement matter — data processing agreements, retention terms, access control, blocking the services that fail the bar. It is the better-understood half, the tooling for it exists, and most organisations that have responded to shadow AI at all have responded here.

The second is the use problem, and it survives the first being solved completely. Approve a sanctioned AI tool for every employee tomorrow and you have governed which AI they use. You have not governed what organisational knowledge flows into it, what comes out, what decisions get made on the strength of that output, or where any of it is recorded. A sanctioned tool is not the same as governed use. The approval changed the logo on the chat window; the shadow — the ungoverned flow of context in and decisions out — carried on inside it.

This is the half most organisations have not named, and it is the half that compounds. Every AI-assisted judgement that ships as finished work, with no record of what informed it, adds to a growing layer of organisational decisions that nobody can later account for. The tool was approved. The use was invisible.

What Actually Accumulates in the Shadow

Two flows, in opposite directions, both unrecorded.

Inward: organisational context leaking into tools that retain nothing for the organisation. The background a salesperson types to get a better email, the constraint an engineer explains to get working code, the reasoning a manager describes to get a sharper plan. Each is a fragment of exactly the institutional knowledge organisations struggle to capture — surfaced, articulated clearly because the AI needed it clearly, and then lost, because it was typed into a chat window that belongs to a provider and persists nowhere the organisation can reach.

Outward: AI-shaped judgement entering the organisation's work without attribution. Recommendations adopted, drafts shipped, analyses trusted — none of them marked as AI-assisted, none traceable to what the AI was told. When one of those judgements later needs explaining, there is nothing to retrieve. Not because the record was lost: because it never existed anywhere the organisation could see.

The irony is sharp. The moment someone explains their problem to an AI tool is one of the few moments tacit knowledge becomes explicit voluntarily. Shadow AI captures that moment perfectly — for the provider, and for nobody else.

How to Manage it

Honestly: you don't manage shadow AI by elimination, because in practice elimination rarely succeeds. The tools are too accessible and too useful, and a policy that pretends otherwise produces compliance theatre and quieter shadows. The realistic strategy has five moves, and the order matters.

First, govern the tools. An approved set, clear data processing terms, the genuinely dangerous services blocked. This is the security and procurement work, it is necessary, and this page does not replace it. It is the floor, not the strategy.

Second, govern the data flows. Decide what categories of organisational information may flow into AI tools at all — client data, financials, anything under regulatory hold — and make the boundary explicit enough that a person with a deadline can apply it in the moment. A rule that requires a policy lookup to interpret will be skipped; a rule someone can hold in their head might not be.

Third, build the sanctioned path before policing the unsanctioned ones. People route around governance when the governed route doesn't serve them. If the approved tool knows nothing about their job, their project, or their constraints, it will lose to the browser tab every time. The sanctioned path has to actually answer the question they have.

Fourth, make the sanctioned path the easier one. This is the move most programmes skip and the one that does the work. Give the governed route better context than a blank chat window has — the organisational knowledge, the current goals, the live constraints — and the unsanctioned alternative becomes the slower, worse option. Incentive does what enforcement can't.

Fifth, capture the work. AI-assisted output needs somewhere to land as organisational record: what was asked, what context informed it, what judgement came back and was relied on. This is what converts the use problem from invisible to governed — not by surveilling the people, but by giving the work a home.

The first two moves are where most shadow AI programmes start and stop. The last three are where the use problem actually gets addressed.

Engramic's approach

How Engramic Approaches it

There are multiple ways to give AI-assisted work somewhere governed to land. This is one approach.

Engramic doesn't block tools or monitor employees — that is the security layer's job, and it stays there. Engramic addresses the use problem: it is where the organisational context that people currently type into chat windows gets authored deliberately, once, and made available to any connected agent or tool. The knowledge that today leaks into provider sessions accumulates instead in a graph the organisation owns. And the work that comes back — the decisions, the judgements — has somewhere to be recorded, traceable to the context that informed it.

The honest limit: Engramic governs the AI use that connects to it. An employee with a personal account in a browser tab is still outside the perimeter. The mechanism is not enforcement — it is making the governed path more useful than the ungoverned one, which is the only mechanism that has ever worked for shadow anything.

In short

Shadow AI is ungoverned AI use, and it is two problems wearing one name. The tool problem — which services are permitted — is a security matter with known fixes, and it's the half most organisations have addressed. The use problem survives the tool problem being solved: a sanctioned tool is not governed use, and the real shadow is the unrecorded flow of organisational context into AI tools and unattributed AI judgement back out. In practice elimination rarely succeeds; the realistic strategy is five moves — govern the tools, govern the data flows, build the sanctioned path, make it the easier path, and give AI-assisted work somewhere to land.