How do organisational incentives, culture, and behaviour influence adherence to…

How do organisational incentives, culture, and behaviour influence adherence to governance in AI and low-code environments?

2026-04-26 · governance-policy security-risk workforce-skills · medium · source → · wiki →
key claims
  1. Shadow IT and low-code circumvention are driven primarily by unmet delivery demand, poor business-IT alignment, and slow sanctioned execution, while low-code platforms mainly act as accelerants that make workaround creation easier once the demand already existsKopper et al. (2019)Klotz et al. (2019)D-nb (n.d.)
  2. Shadow AI is already widespread in enterprise work, because survey and telemetry evidence show widespread personal-tool use, high rates of non-corporate accounts, rapid growth in corporate data flows into AI tools, and strong association between AI incidents and missing governance controlsInternational (n.d.)Cyberhaven, Shadow AI (n.d.)IBM (2025)
  3. Governance friction raises circumvention risk because employees rationalise policy violations and workarounds as necessary, harmless, or professionally responsible when the sanctioned path blocks timely execution of legitimate workVance (2010)Internationalbusinessconference (n.d.)Dourish et al. (2004)
  4. Incentives such as productivity expectations, leadership resistance, and pressure for rapid delivery change the perceived legitimacy of governance by making unsanctioned use feel more aligned with local performance goals than official compliance doesInternational (n.d.)DevOps (2024)National (n.d.)
  5. Durable compliance depends on culture as much as on policy, because clear role ownership, leadership-set tone, training, safety-first norms, and explicit policy socialisation all reduce the ambiguity that otherwise invites local reinterpretation and covert tool useNational (n.d.)DORA (2025)DORA (2025)International (n.d.)
  6. Sanctioned self-service inside visible guardrails is a durable governance design, because overt, low-friction lanes can be trained, logged, and constrained while covert shadow systems cannot be governed effectively after they emergeMicrosoft (n.d.)Microsoft (n.d.)Microsoft (n.d.)Klotz et al. (2019)
  7. Governance programmes that ignore maker and developer experience will tend to create both delivery drag and shadow behaviour, because AI and low-code tooling amplify the quality of the surrounding workflow and platform rather than compensating for a weak operating modelDevOps (2024)DORA (2025)Prior item (n.d.)
  8. Bypass behaviour remains multi-causal, because weak awareness, weak restrictions, convenience, and peer behaviour can all convert delivery pressure into covert shadow use even when structural capability gaps remain the strongest recurring background conditionKopper et al. (2019)Klotz et al. (2019)IBM (n.d.)Prior item (n.d.)

Research Question

How do organisational incentives, culture, and behaviour influence adherence to governance in Artificial Intelligence (AI) and low-code environments, specifically, what conditions drive teams to bypass governance controls, creating shadow Information Technology (IT) and ungoverned automations, and what governance design choices and cultural conditions produce durable compliance rather than formal compliance with behavioural circumvention?

Findings

Executive Summary

Key Findings

  1. High confidence: Shadow IT and low-code circumvention are driven primarily by unmet delivery demand, poor business-IT alignment, and slow sanctioned execution, while low-code platforms mainly act as accelerants that make workaround creation easier once the demand already exists.
  2. High confidence: Shadow AI is already widespread in enterprise work, because survey and telemetry evidence show widespread personal-tool use, high rates of non-corporate accounts, rapid growth in corporate data flows into AI tools, and strong association between AI incidents and missing governance controls.
  3. High confidence: Governance friction raises circumvention risk because employees rationalise policy violations and workarounds as necessary, harmless, or professionally responsible when the sanctioned path blocks timely execution of legitimate work.
  4. Medium confidence: Incentives such as productivity expectations, leadership resistance, and pressure for rapid delivery change the perceived legitimacy of governance by making unsanctioned use feel more aligned with local performance goals than official compliance does.
  5. High confidence: Durable compliance depends on culture as much as on policy, because clear role ownership, leadership-set tone, training, safety-first norms, and explicit policy socialisation all reduce the ambiguity that otherwise invites local reinterpretation and covert tool use.
  6. Medium confidence: Sanctioned self-service inside visible guardrails is a durable governance design, because overt, low-friction lanes can be trained, logged, and constrained while covert shadow systems cannot be governed effectively after they emerge.
  7. Medium confidence: Governance programmes that ignore maker and developer experience will tend to create both delivery drag and shadow behaviour, because AI and low-code tooling amplify the quality of the surrounding workflow and platform rather than compensating for a weak operating model.
  8. Medium confidence: Bypass behaviour remains multi-causal, because weak awareness, weak restrictions, convenience, and peer behaviour can all convert delivery pressure into covert shadow use even when structural capability gaps remain the strongest recurring background condition.

Assumptions

Analysis

Risks, Gaps, and Uncertainties

Open Questions


sources

Connected items

Loading…

View full knowledge graph →