Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

Just as with 'Shadow IT,' employees will inevitably use the most effective AI tools, whether sanctioned or not. Instead of creating futile barriers, organizations should design systems that reward employees for curating and using these tools in a compliant and transparent manner.

Related Insights

Esper established a clear policy for employees to pilot new AI tools. They can experiment without ingesting proprietary data, then submit promising tools to an IT and security-led committee that promises a quick decision. This approach balances fostering innovation with maintaining security.

Many employees secretly use AI for huge efficiency gains. To harness this, leaders must create programs that reward sharing these methods, rather than making workers fear punishment or layoffs. This allows innovative, bottom-up AI usage to be scaled across the organization.

The practice of banning generative AI tools within large companies has ended. The focus has shifted to controlled adoption, as the rapid pace of model improvement means restricting employees to a single platform is now a significant competitive disadvantage.

Instead of reacting to unsanctioned tool usage, forward-thinking organizations create formal AI councils. These cross-functional groups (risk, privacy, IT, business lines) establish a proactive process for dialogue and evaluation, addressing governance issues before tools become deeply embedded.

When employees use unapproved AI tools, it shouldn't be seen merely as a compliance violation. It is often a strong signal that the officially sanctioned tools and training are inadequate for their workflow needs. This behavior highlights a critical gap in the company's enablement strategy that needs to be addressed proactively.

Employees often use personal AI accounts ("secret AI") because they're unsure of company policy. The most effective way to combat this is a central document detailing approved tools, data policies, and access instructions. This "golden path" removes ambiguity and empowers safe, rapid experimentation.

Instead of punishing employees for using unapproved AI tools, leaders should view it as a critical signal. It's often the highest performers who do this, not out of malice, but because the company's sanctioned tools are inadequate. They are identifying gaps and potential solutions for the organization.

When marketing teams adopt unsanctioned AI tools, it's typically not intentional subversion but an attempt to achieve business outcomes under pressure. IT leaders should interpret this "shadow IT" as a signal of urgent business needs, opening a dialogue about enabling innovation with proper guardrails.

Instead of blocking generative AI tools, Datadog's CISO proactively provided ChatGPT licenses to every employee. This approach avoids the 'all oops moment' of employees using unapproved tools with personal accounts, which creates shadow IT. By providing an official, governed solution with data retention controls, the company enables innovation while managing risk.

PagerDuty found 66% of office workers use AI tools they believe violate company policy. This isn't malicious, but a result of consumer AI tools often being far more capable than sanctioned enterprise software, creating a significant "shadow AI" governance problem for corporations.