What is actually happening
Someone in finance is pasting a vendor contract into a consumer chatbot to summarize it. Someone in support is drafting responses in a browser extension nobody evaluated. An engineer is using a coding assistant against a repository the license terms do not clearly cover. None of these people are being reckless by their own lights — each has found a tool that makes a real task faster, and the approval process either does not exist or takes six weeks.
The risk is genuine. Data leaves your control and may be retained or used for training. There is no record of what the system said when someone acted on it. Outputs enter customer-facing work with no review. And none of it appears in any inventory, which means the honest answer to an auditor's question about AI usage is that you do not know.
Why the ban fails
A prohibition changes where the behavior happens, not whether it happens. It moves to personal devices and personal accounts, where you have less visibility and no logging at all. The organization trades a manageable problem for an invisible one and records the trade as a policy win.
There is a second cost that is harder to see. A ban tells the people who found a genuine productivity improvement that the organization would rather they be slower. That is a real signal about how the company handles initiative, and it is remembered.
If the unsanctioned path is faster than the sanctioned one, the unsanctioned path wins. This is not a values question. It is a friction question.
What works
Find out what is actually in use
Before policy, inventory. Ask directly and without consequence attached — an amnesty framing gets far better data than a compliance survey. Supplement with what you can see: expense reports for personal AI subscriptions, egress to known AI domains, browser extension inventories. The goal is a list of tools and the tasks they are being used for, because the tasks are the actual finding.
Provide a fast sanctioned path
One approved tool that covers the top three tasks on that list, available to everyone who asked, with a request process measured in days rather than quarters. Coverage matters more than capability here: a slightly worse tool that is available today beats a better one that requires a procurement cycle.
Classify data, not tools
Most AI policies are written as tool allowlists, which go stale within a month. A more durable version defines what categories of data may go into a system of a given class — public, internal, customer, regulated — and lets the tool list follow. People can apply that rule to a tool nobody has evaluated yet, which is the situation they will actually be in.
Log the sanctioned path
The strongest practical argument for the approved tool is that it produces a record. When something goes wrong — and it will — being able to reconstruct what the system said and who acted on it is the difference between an incident and a crisis. That is also the capability an auditor or acquirer will ask about.
The governance framing
Shadow AI sits inside a broader question: does anyone own AI usage in the organization at all? In most companies where it has become a problem, the answer is that responsibility is split between security, legal, and IT, none of whom have a mandate to make anyone faster. The behavior is a symptom of that gap, and it recurs until the gap is closed.