The Long Shadow of Unauthorized Tech Use in the Modern Enterprise

Posted on September 24, 2026

0


Naming an owner establishes accountability on paper. It does not establish whether the owner is operating inside the system.


A governance argument has been circulating this week, and it is a reasonable one: every row in the accountability matrix needs a name next to it. No unassigned responsibilities. No ambiguity about who answers for what.

Necessary. And insufficient — for a reason that is already in the published record.

On 16 September, in When a Consumer Mindset Serves the Business World, I documented a finding from a March 2026 survey of 2,001 employees in the United Kingdom and the United States: 65% of senior decision-makers use unapproved AI tools, against 31% of the people they manage. Slightly more than twice the rate.

The governance risk is running out of the offices of the people writing the governance.

That is not a compliance observation. It is a structural one, and it reframes the ownership question entirely. If the person named in the row is also the person working outside the governed environment, the name establishes formal accountability and nothing else. Six questions survive the naming:

  • Does the named owner follow the same rules?
  • Can the organization detect when the owner does not?
  • Is the exception recorded and tested as evidence?
  • Can anyone challenge the executive’s use?
  • Does the approved AI environment support the actual work?
  • Who owns the collective consequence when leaders create the shadow system?

This is not new behavior

It is the newest version of a pattern that has run through every technology era on record. The official system arrives. It fails to accommodate how the work is actually performed. People route around it. Governance arrives afterward and treats the workaround as the problem.

EraOfficial enterprise technologyThe employee workaround
1996–2000Mainframes, client-server systems, early ERPUncontrolled Excel models, macros, Access databases, locally installed applications
2000–2006ERP expansion, intranets, enterprise emailPersonal email, instant messaging, USB drives, home computers, downloaded software
2007–2012Web-based enterprise systemsPersonal smartphones, tablets, consumer applications — the emergence of BYOD
2012–2017Enterprise cloud and sanctioned software-as-a-serviceDropbox, Google Drive and other unapproved cloud applications — “shadow IT” becomes the label
2017–2022Integrated platforms, collaboration suites, automationLow-code applications, personal workflows, bots, unsanctioned automation
2023–2026Enterprise generative and agentic AIPersonal AI accounts, undeclared models, uploaded corporate information, independently built AI workflows

I am not reading that pattern backward into the record. I was describing its operating mechanism while it was happening.

In December 2013, in 3 Supply Chain Concepts That Should Finally (and Mercifully) Be Abandoned, I argued that maverick spend was an artificially created problem — the unintended consequence of poorly designed ERP procurement platforms that limited supplier engagement, forcing buyers to go against what they knew from experience was a better route to savings. The industry response to that understandable resistance was to introduce change management in an effort to enforce compliance. Nobody asked first why the sanctioned system conflicted with operating reality.

Shadow AI is the latest expression of the same pattern.

Six eras. Six official stacks. One constant.

The technology in each column is unrecognizable from one era to the next. The conduct has changed too — materially, and never more than now, with senior management apparently leading it. What has not changed is the operating pattern behind the behavior: the gap between the sanctioned system and the way the work actually has to be done. That is Invariant Physics™ — the condition was already operating, and each new generation of technology is a change of coordinates rather than a change of situation.

What is different this time

The workaround itself has changed category.

A spreadsheet calculated — and sometimes embedded undocumented assumptions directly into forecasts, pricing and operating decisions. A personal device connected. A cloud application stored and shared.

AI combines all three exposures. It absorbs information, interprets context, generates recommendations and increasingly acts. So AI does not create the epistemic problem; it dramatically expands it. The output does not stay in the tool — it flows into decisions, supplier selections, customer communications and board material, and the organization inherits the judgment without knowing where it came from.

The historical governance gap has acquired agency, speed and scale.

Read the shadow as evidence

The instinct is to fence it. The more useful move is to read it.

When someone repeatedly uses an unsanctioned tool for a specific task, they have produced behavioral evidence that the sanctioned route may not adequately serve that task. That evidence does not establish the cause. Unauthorized use can equally reflect convenience, habit, privilege, experimentation or plain disregard for policy. What it identifies is where the organization has to start tracing backward.

It is not clean data in the compliance sense either. The confident and the vocal are overrepresented, and silence does not mean the approved route works. But it is unusually direct information about the distance between the work people have to do and the system they were given — and it costs nothing to collect.

And when the heaviest users are the people who wrote the policy, the explanation that the workforce lacks discipline stops being available.

Two structural explanations then demand investigation. Either the sanctioned environment does not support the work the organization actually performs, or the rules are understood not to apply equally at the top. Individual explanations may sit alongside them. Neither structural possibility is resolved by assigning a name to a row.

The largest governance gap in most organizations is not an unassigned row. It is the distance between what the named owners require and what the named owners do.


Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™

On Friday I am running a free 30-minute lab on selecting and working with AI models — a working session, not a presentation. Friday, 25 September, 9:30 AM Eastern, and again Wednesday, 30 September, 1:00 PM Eastern.

Register: https://www.linkedin.com/events/7504567838724997120/

-30-

Posted in: Commentary