How do organisational incentives, culture, and behaviour influence adherence to…
How do organisational incentives, culture, and behaviour influence adherence to governance in AI and low-code environments?
key claims
- Shadow IT and low-code circumvention are driven primarily by unmet delivery demand, poor business-IT alignment, and slow sanctioned execution, while low-code platforms mainly act as accelerants that make workaround creation easier once the demand already existsKopper et al. (2019)Klotz et al. (2019)D-nb (n.d.)
- Shadow AI is already widespread in enterprise work, because survey and telemetry evidence show widespread personal-tool use, high rates of non-corporate accounts, rapid growth in corporate data flows into AI tools, and strong association between AI incidents and missing governance controlsInternational (n.d.)Cyberhaven, Shadow AI (n.d.)IBM (2025)
- Governance friction raises circumvention risk because employees rationalise policy violations and workarounds as necessary, harmless, or professionally responsible when the sanctioned path blocks timely execution of legitimate workVance (2010)Internationalbusinessconference (n.d.)Dourish et al. (2004)
- Incentives such as productivity expectations, leadership resistance, and pressure for rapid delivery change the perceived legitimacy of governance by making unsanctioned use feel more aligned with local performance goals than official compliance doesInternational (n.d.)DevOps (2024)National (n.d.)
- Durable compliance depends on culture as much as on policy, because clear role ownership, leadership-set tone, training, safety-first norms, and explicit policy socialisation all reduce the ambiguity that otherwise invites local reinterpretation and covert tool useNational (n.d.)DORA (2025)DORA (2025)International (n.d.)
- Sanctioned self-service inside visible guardrails is a durable governance design, because overt, low-friction lanes can be trained, logged, and constrained while covert shadow systems cannot be governed effectively after they emergeMicrosoft (n.d.)Microsoft (n.d.)Microsoft (n.d.)Klotz et al. (2019)
- Governance programmes that ignore maker and developer experience will tend to create both delivery drag and shadow behaviour, because AI and low-code tooling amplify the quality of the surrounding workflow and platform rather than compensating for a weak operating modelDevOps (2024)DORA (2025)Prior item (n.d.)
- Bypass behaviour remains multi-causal, because weak awareness, weak restrictions, convenience, and peer behaviour can all convert delivery pressure into covert shadow use even when structural capability gaps remain the strongest recurring background conditionKopper et al. (2019)Klotz et al. (2019)IBM (n.d.)Prior item (n.d.)
Research Question
How do organisational incentives, culture, and behaviour influence adherence to governance in Artificial Intelligence (AI) and low-code environments, specifically, what conditions drive teams to bypass governance controls, creating shadow Information Technology (IT) and ungoverned automations, and what governance design choices and cultural conditions produce durable compliance rather than formal compliance with behavioural circumvention?
Findings
Executive Summary
- Teams usually bypass AI and low-code governance when the sanctioned path is too slow, too weak, or too hard to use relative to the productivity payoff of the workaround, although weak awareness, convenience motives, and peer norms also contribute to whether that pressure becomes covert shadow behaviour.
- Hollow compliance appears when staff can rationalise circumvention as necessary problem solving, especially under delivery pressure and when official controls interrupt work without offering a credible low-friction alternative.
- Durable compliance is most likely when governance combines clear policy, leadership support, open communication, training, and sanctioned self-service inside visible guardrails, because that package removes the behavioural reward for shadow behaviour while keeping risky work visible and governable.
Key Findings
- High confidence: Shadow IT and low-code circumvention are driven primarily by unmet delivery demand, poor business-IT alignment, and slow sanctioned execution, while low-code platforms mainly act as accelerants that make workaround creation easier once the demand already exists.
- High confidence: Shadow AI is already widespread in enterprise work, because survey and telemetry evidence show widespread personal-tool use, high rates of non-corporate accounts, rapid growth in corporate data flows into AI tools, and strong association between AI incidents and missing governance controls.
- High confidence: Governance friction raises circumvention risk because employees rationalise policy violations and workarounds as necessary, harmless, or professionally responsible when the sanctioned path blocks timely execution of legitimate work.
- Medium confidence: Incentives such as productivity expectations, leadership resistance, and pressure for rapid delivery change the perceived legitimacy of governance by making unsanctioned use feel more aligned with local performance goals than official compliance does.
- High confidence: Durable compliance depends on culture as much as on policy, because clear role ownership, leadership-set tone, training, safety-first norms, and explicit policy socialisation all reduce the ambiguity that otherwise invites local reinterpretation and covert tool use.
- Medium confidence: Sanctioned self-service inside visible guardrails is a durable governance design, because overt, low-friction lanes can be trained, logged, and constrained while covert shadow systems cannot be governed effectively after they emerge.
- Medium confidence: Governance programmes that ignore maker and developer experience will tend to create both delivery drag and shadow behaviour, because AI and low-code tooling amplify the quality of the surrounding workflow and platform rather than compensating for a weak operating model.
- Medium confidence: Bypass behaviour remains multi-causal, because weak awareness, weak restrictions, convenience, and peer behaviour can all convert delivery pressure into covert shadow use even when structural capability gaps remain the strongest recurring background condition.
Assumptions
- Assumption: Shadow-IT, low-code, and security-policy-circumvention research is directionally applicable to AI governance behaviour. Justification: direct AI-specific causal studies on governance friction remain sparse, while the recurring mechanism of unmet demand, workaround creation, and rationalised bypass appears across all three literatures.
- Assumption: Cyberhaven telemetry and IBM survey evidence are representative enough to infer enterprise shadow-AI behaviour patterns, even though exact prevalence values may vary by workforce mix and monitoring coverage. Justification: the two sources use different methods yet point in the same behavioural direction.
Analysis
- The shadow-IT and low-code literature received the highest evidentiary weight for root-cause analysis because it directly addresses why business users build or procure unsanctioned tools when formal delivery channels fail them.
- The AI-specific evidence was weighted mainly for prevalence, account choice, data exposure, and governance-gap severity, because the public source set offers stronger observational evidence than causal proof for shadow-AI behaviour.
- Security-policy-violation and workaround studies were used to explain how friction turns into circumvention, namely through rationalisation, practical reinterpretation of rules, and adaptation to everyday work conditions.
- Vendor documentation was used only for feasible control-surface and operating-model evidence, not as proof that any specific governance programme necessarily succeeds in practice.
- Companion repository items were used to qualify the delivery and operating-model implications of the external evidence, but not to upgrade confidence beyond what the independent external sources justify.
Risks, Gaps, and Uncertainties
- Public evidence on shadow AI is strong enough to establish prevalence and risk direction, but still thinner on long-run organisational outcomes, before-and-after governance interventions, and sector-specific causal measurement.
- The seeded analyst sources were inaccessible from this runtime, so the item relies more heavily on open surveys, telemetry, standards, and academic literature than on analyst benchmarking.
- Two seeded academic references were inaccurate at the citation level, one for the titled "Security in the Wild" attribution and one for the Tallon Digital Object Identifier (DOI), which reduced the value of the original source list until working publisher records were substituted.
- The shadow-IT literature is credible and relevant but not AI-specific, which is why some transfer claims remain medium confidence rather than high confidence.
Open Questions
- Which governance interventions measurably reduce shadow-AI usage without suppressing legitimate productivity gains over a twelve-month period?
- What is the optimal operational split between central governance, platform teams, and local business owners for turning covert shadow demand into overt governed delivery at scale?
- Which message, policy, or training interventions most effectively reduce employee neutralization and workaround rationalisation in AI governance settings specifically?
sources
- Gartner documents portal — - seeded analyst source; access-gated in this session and not used for downstream factual support
- McKinsey state of AI 2024 — - seeded official survey source; official page could not be retrieved directly in this session
- Dourish et al. (2004), Security in the Wild: User Strategies for Managing Security as an Everyday, Practical Problem — - accessible publisher record for the titled paper; seeded Ashenden and Lawrence attribution could not be verified
- Siponen and Vance (2010), Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations — - accessible abstract page for the seeded security-policy-violation paper
- Tallon, Ramirez, and Short (2013), The Information Artifact in IT Governance: Toward a Theory of Information Governance — - accessible official page replacing the inaccurate seeded Tallon Digital Object Identifier (DOI)
- Kopper et al. (2019), Shadow IT and Business-managed IT: Practitioner Perceptions and Their Comparison to Literature — - practitioner evidence on shadow IT drivers and governance responses
- Klotz et al. (2019), Causing factors, outcomes, and governance of Shadow IT and business-managed IT: a systematic literature review — - systematic review of shadow IT causes, outcomes, and governance
- Kass, Strahringer, and Westner, Drivers and Inhibitors of Low Code Development Platform Adoption — - literature review on low-code adoption pressures and risks
- International Business Machines (IBM), Is rising AI adoption creating shadow AI risks? — - survey evidence on unauthorised AI use, leadership resistance, and training demand
- IBM, Shadow AI topic page — - definition and driver summary for shadow AI
- Cyberhaven, Shadow AI: Employee AI Adoption Risks Your Company Data — - telemetry evidence on shadow AI, non-corporate accounts, and sensitive-data exposure
- IBM and Ponemon Institute, Cost of a Data Breach Report 2025 — - quantified governance-gap indicators around AI incidents and shadow AI
- DevOps Research and Assessment (DORA) 2024 report announcement — - delivery-friction and open-communication evidence
- DORA 2025 AI capabilities report page — - culture, capabilities, and internal-platform evidence
- DORA 2025 report announcement — - policy clarity, control-system, and platform-foundation evidence
- National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) Core — - cross-cutting governance, risk culture, role clarity, training, and safety-first expectations
- NIST AI RMF Playbook page — - tailoring and non-checklist governance guidance
- Microsoft Power Platform Center of Excellence (CoE) overview — - central-governance-plus-enablement pattern for low-code
- Microsoft Copilot Studio security and governance — - governable surfaces, audit logs, environment routing, and maker guidance
- Microsoft Copilot Studio data-loss-prevention controls — - sanctioned guardrails over authentication, knowledge, tools, channels, and triggers
- Prior item: Business-led low-code agent governance — - adjacent repo synthesis on bounded maker lanes
- Prior item: AI governance cost, performance, and delivery impact — - adjacent repo synthesis on governance friction and delivery effects
- Prior item: Systems capability debt, citizen development, empirical evidence — - adjacent repo synthesis on unmet demand and workaround adoption
- Prior item: AI low-code decision rights, accountability, and liability — - adjacent repo synthesis on escalation and ownership surfaces