Your Team Is Already Using Agents You Did Not Approve
78% of executives say they have a clear picture of how AI is being used inside their organisation. When you ask the employees, the real number is closer to 23%.
That gap is the whole story. Not a security gap, not a compliance gap, a perception gap. Most leaders are managing a version of their company that stopped existing about eighteen months ago.
The actual numbers are worse than the anecdotes
The average enterprise employee now uses 4.7 AI tools a week. Roughly 1.2 of them are approved by IT.
More than 80% of workers globally use AI that nobody sanctioned. PagerDuty found two thirds of office professionals have used unauthorised AI tools at work. About 98% of organisations have somebody running unsanctioned AI or apps. Around 45% of US workers use AI at work without telling their employer at all.
And the versions they are using are the worst possible ones from your point of view: 58% of those workers are on free tiers, which by definition come without enterprise data governance, retention controls or audit logging.
The data leaking is not trivial either. Cyberhaven found that 11% of everything employees paste into AI tools is sensitive: source code, customer PII, financial records, legal documents. Cisco found 27% of employees have pasted company data into public AI tools.
So the picture is not "a few enthusiasts experimenting." It is most of your staff, most weeks, on consumer accounts, with real company data.
Why the ban does not work
The instinct is a policy. Block the domains, send the email, add a line to the handbook.
Here is the number that kills that approach: 60% of workers said they would use an unapproved product anyway if it meant hitting their deadline.
Read that carefully, because it is not defiance. It is prioritisation, and it is the prioritisation you asked for. You hired people to deliver, you set the deadline, and then you told them the tool that would help them meet it is off limits. They are choosing the goal you gave them over the rule you gave them. Most managers, honestly, would make the same call.
A ban does not remove shadow AI. It moves it onto personal laptops and phones, where you have less visibility than you did before, and it teaches people not to mention it. You have not reduced your risk. You have reduced your information.
Shadow AI is a review of your internal tooling
Try reframing it. Every unsanctioned tool in your company is a feature request with evidence attached.
Somebody had a task, evaluated their options, and concluded that the thing they were given was worse than something they had to sign up for personally, in their own name, at their own risk, without telling anyone. That is a strong preference. People do not take on personal exposure for a marginal improvement.
So the inventory of shadow AI in your organisation is also a remarkably honest report on where your approved stack falls down. If half your sales team is quietly using an outside tool to draft follow-ups, that is not a discipline issue. That is your CRM losing a fair fight.
The useful question is not "how do we stop this." It is "what did they get that we did not give them."
What a sanctioned agent has to do to win
If shadow AI is a competitive loss, the fix is a better product, not a stronger rule. In practice, four things decide it.
It has to be there before the ticket. The unsanctioned tool won partly because it was available in ninety seconds with an email address. If your approved option requires a request, an approval, and a two-week wait, it has lost before it is evaluated. Whatever you sanction has to be reachable the moment someone needs it.
It has to be genuinely better at the specific job. Not broader. Better at the thing they were actually doing. A general assistant that is worse at drafting follow-ups than the tool they found will keep losing, no matter how many capabilities it lists.
It has to remember. This is the one most companies underrate. A tool that starts from zero every session forces the person to re-explain their clients, their tone, their process, every single time. The tools people go out and adopt on their own are frequently the ones that accumulate context. If your sanctioned option forgets, people will keep a second one that does not.
It has to keep the work inside your boundary. This is the entire point of sanctioning something, and it only counts if the first three are true. Governance that nobody uses is not governance, it is paperwork.
Notice that only the fourth item is about control. The first three are about quality. That ratio is roughly right, and it is the opposite of how most AI policies are written.
The uncomfortable version
If your approved tool would lose a fair fight against what your staff picked on their own, then banning the alternative is not risk management. It is protecting a worse product from competition, using your authority to do it.
That is worth sitting with before the next policy memo. The people using shadow AI are usually your most motivated employees. They are the ones who cared enough about the outcome to go find something. Punishing that instinct costs you more than the data exposure does, and it costs you the exact people you least want to demotivate.
What to actually do this quarter
Start with an amnesty, not an audit. Ask people what they are using and promise nothing bad happens for answering honestly. You will get a far better inventory in a week than any scanning tool will produce in a quarter, and you will find out which categories of work are underserved.
Then pick the two or three highest-volume uses and give people something sanctioned that is genuinely better at those specific jobs. Not a policy. A tool that wins.
Then keep the boundary real. Run it on infrastructure you control, keep the memory and the audit trail inside your own environment, and make sure you can answer what it touched and when. That is what turns a sanctioned tool into an actual reduction in risk rather than a differently-branded version of the same exposure.
Shadow AI is not a sign your staff are careless. It is a sign they are ahead of your procurement process. The companies that treat it as intelligence rather than misconduct will end up with both better tooling and better visibility. The ones that treat it as a discipline problem will get neither, and will keep believing they have a clear picture.
Want to test the most advanced AI employees, running on infrastructure you own? Try it here: https://geta.team