What are the primary behavioural and structural drivers of unsanctioned AI…
What are the primary behavioural and structural drivers of unsanctioned AI adoption after official tool rollout, and how effective are current governance mechanisms at containing unsanctioned AI systems that can call tools or take multi-step actions compared to earlier shadow IT waves?
- Post-rollout shadow AI is driven primarily by the same unmet-demand and workflow-friction conditions that drove earlier shadow IT, namely slow official delivery paths, weak business-IT fit, and sanctioned tools that do not match real work needs, while weak enforcement and risk unawareness remain secondary contributorsKlotz et al. (2019)Kopper et al. (2019)IBM (2025)LinkedIn (2024)
- Sanctioned rollout does not reliably displace unofficial AI use, because Microsoft, IBM, and Cyberhaven all show high enterprise adoption coexisting with persistent Bring Your Own AI, personal-account use, and unofficial tool selectionLinkedIn (2024)IBM (2025)Labs (2024)
- The best-supported causal interpretation is that official rollout often legitimises AI as normal work infrastructure while leaving employees free to choose faster or better-fitting shadow tools when the sanctioned lane remains narrow, poorly integrated, or weakly trainedLinkedIn (2024)IBM (2025)DORA (2025)
- Managed enterprise-agent platforms expose materially stronger control surfaces than unmanaged tools, because official control surfaces support real-time policy enforcement over authentication, tools, knowledge sources, channels, and triggers, plus audit logging and security-status feedbackLearn (2025)Learn (2025)
- Those same mechanisms are only partially effective against shadow AI systems that can call tools or take multi-step actions, because discovery can reveal unsanctioned app usage and traffic volume, but it cannot by itself reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerousLearn (2025)Center (2025)Mitchell (2026)Mitchell (2026)
- Shadow agentic AI is harder to contain than earlier shadow IT because the risk surface now includes hidden prompt injection, model-mediated exfiltration, and unintended tool execution, which means classic DLP and application inventory are necessary but insufficient controlsOwasp (n.d.)Center (2025)IBM (n.d.)
- The most credible governance design is therefore enablement plus containment: make the sanctioned lane lower-friction and better-trained for routine work, while forcing high-risk agentic use onto managed rails with discovery, attributed telemetry, least privilege, and pre-action approval or hold controlsNational (2023)DORA (2025)Learn (2025)Learn (2025)Mitchell (2026)
Research Question
What are the primary behavioural and structural drivers of shadow Artificial Intelligence (AI) adoption, meaning unsanctioned use of AI tools without formal approval or oversight, in enterprises after official tools have been rolled out, and what is the causal relationship between sanctioned tool provision and shadow usage, specifically, do provided tools reduce shadow AI or normalise bypass behaviours? How effective are current governance mechanisms, policies, Data Loss Prevention (DLP), and monitoring, at containing shadow AI systems that can call tools or take multi-step actions, referred to below as agentic AI, compared to earlier shadow Information Technology (IT) adoption waves?
Findings
Executive Summary
Sanctioned AI rollout does not, by itself, materially suppress unsanctioned AI use, referred to below as shadow AI; it more often normalises AI use while employees continue choosing faster or better-fitting unofficial tools.
The strongest drivers remain the same structural frictions that powered earlier shadow IT, slow sanctioned delivery, poor business-IT fit, weak workflow integration, and unmet demand, while weak enforcement and risk unawareness act mainly as contributing rather than primary drivers.
Current governance mechanisms provide materially stronger constraints inside sanctioned platforms, where authentication, tool restrictions, channel restrictions, and real-time DLP are available, but they remain only partially effective at containing shadow AI systems that can call tools or take multi-step actions because off-rail prompt semantics, tool plans, and delegated actions remain only partly visible.
Compared with earlier shadow IT waves, the behavioural problem is continuous but the containment problem is harder, because agentic AI adds cognition, autonomy, and machine-speed action risk that require discovery, attributed telemetry, and pre-action controls rather than policy and app inventory alone.
Key Findings
- Post-rollout shadow AI is driven primarily by the same unmet-demand and workflow-friction conditions that drove earlier shadow IT, namely slow official delivery paths, weak business-IT fit, and sanctioned tools that do not match real work needs, while weak enforcement and risk unawareness remain secondary contributors.
- Sanctioned rollout does not reliably displace unofficial AI use, because Microsoft, IBM, and Cyberhaven all show high enterprise adoption coexisting with persistent Bring Your Own AI, personal-account use, and unofficial tool selection.
- The best-supported causal interpretation is that official rollout often legitimises AI as normal work infrastructure while leaving employees free to choose faster or better-fitting shadow tools when the sanctioned lane remains narrow, poorly integrated, or weakly trained.
- Managed enterprise-agent platforms expose materially stronger control surfaces than unmanaged tools, because official control surfaces support real-time policy enforcement over authentication, tools, knowledge sources, channels, and triggers, plus audit logging and security-status feedback.
- Those same mechanisms are only partially effective against shadow AI systems that can call tools or take multi-step actions, because discovery can reveal unsanctioned app usage and traffic volume, but it cannot by itself reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous.
- Shadow agentic AI is harder to contain than earlier shadow IT because the risk surface now includes hidden prompt injection, model-mediated exfiltration, and unintended tool execution, which means classic DLP and application inventory are necessary but insufficient controls.
- The most credible governance design is therefore enablement plus containment: make the sanctioned lane lower-friction and better-trained for routine work, while forcing high-risk agentic use onto managed rails with discovery, attributed telemetry, least privilege, and pre-action approval or hold controls.
Assumptions
- Microsoft survey data, IBM survey data, and Cyberhaven telemetry were treated as collectively representative enough to support direction-of-travel claims across enterprise knowledge work. Justification: the three sources independently report the same persistence pattern after rollout.
- Microsoft Copilot Studio was treated as a representative example of current sanctioned enterprise-agent governance surfaces rather than as a unique outlier. Justification: the control categories align with NIST's governance, inventory, monitoring, and role-control expectations.
- Off-rail personal-account use was treated as only partially observable at enterprise level. Justification: the reviewed discovery sources expose app traffic, users, and bytes transferred, but not a full prompt-to-action trace for unmanaged tools.
Analysis
- The most persuasive evidence on sanctioned-tool effects came from post-rollout sources that directly measured behaviour rather than only describing risk, because those sources show official availability and shadow persistence at the same time.
- Earlier shadow-IT literature was weighted heavily for mechanism, because it explains why users route around governance, while current AI sources were weighted heavily for changed speed and scale.
- A pure-enforcement explanation is weaker than the mixed fit-and-friction explanation, because earlier shadow-IT studies already treat lack of restrictions and lack of awareness as contributing factors, while IBM and Cyberhaven still show heavy unofficial use even after official tools and policy attention are present.
- The governance synthesis separates control efficacy by surface, managed-lane controls provide stronger constraints, discovery can be useful, but unmanaged agentic actions remain harder to interpret and stop than unmanaged app use in older shadow-IT settings.
- The recommended design favours system improvement over prohibition, because the evidence suggests organisations need better internal platforms and stronger managed-rail containment together, not either one alone.
Risks, Gaps, and Uncertainties
- The evidence for sanctioned rollout causing more shadow use is observational rather than experimental, so the strongest conclusion is persistence and normalisation, not a quantified universal causal uplift.
- Official Microsoft documentation proves control availability but does not, on its own, prove cross-enterprise effectiveness rates for each control in production.
- Discovery and network telemetry reduce visibility gaps, but they do not eliminate the residual risk from unmanaged personal accounts, encrypted traffic, or prompt-level semantics that remain outside full enterprise inspection.
- Inaccessible Gartner and McAfee seeded pages may contain additional quantitative detail, but the core conclusions here do not depend on them because accessible Microsoft, IBM, Cyberhaven, NIST, and shadow-IT literature already support the main findings.
Open Questions
- What specific platform-quality and workflow-integration changes most reliably convert high-demand Bring Your Own AI users into sustained sanctioned-platform users?
- Which telemetry fields are minimally sufficient to distinguish benign unsanctioned experimentation from high-risk off-rail agentic use without creating disproportionate privacy or data-minimisation concerns?
- What is the most usable enterprise pattern for pre-action approval or verification hold that contains agentic risk without pushing routine workers back into shadow channels?
sources
Starting points and follow-on sources:
- [ ] McAfee (n.d.) McAfee homepage - seeded shadow-IT source, returned 403 in this session, not used for downstream factual support
- [ ] Gartner (n.d.) Gartner homepage - seeded analyst source, returned 403 in this session, not used for downstream factual support
- [ ] Belanger and Crossler (2011) Privacy in the Digital Age: A Review of Information Privacy Research in Information Systems - corrected record for the seeded DOI, checked but not used for downstream factual support
- [x] Microsoft WorkLab (2023) Will AI Fix Work? - workload-pressure baseline for why workers want AI assistance
- [x] Microsoft and LinkedIn (2024) Work Trend Index on the state of AI at work - post-rollout Bring Your Own AI (BYOAI) evidence
- [x] IBM (2025) Is rising AI adoption creating shadow AI risks? - survey evidence on unofficial use, feature gaps, and training demand
- [x] IBM (n.d.) Shadow AI - definitional comparison between shadow AI and shadow IT, plus productivity and governance framing
- [x] IBM and Ponemon Institute (2025) Cost of a Data Breach Report, The AI oversight gap - governance-gap indicators for incidents, access controls, and shadow AI policy absence
- [x] Cyberhaven Labs (2024) Shadow AI: How employees are leading the charge in AI adoption and putting company data at risk - enterprise telemetry on personal accounts, sensitive data, and persistence after enterprise rollout
- [x] Klotz et al. (2019) Causing factors, outcomes, and governance of Shadow IT and business-managed IT - shadow-IT baseline on slowness, unmet needs, and governance response
- [x] Kopper et al. (2019) Shadow IT and Business-managed IT: Practitioner Perceptions and Their Comparison to Literature - practitioner baseline on business-IT misalignment, agility gaps, and policy weakness
- [x] National Institute of Standards and Technology (NIST) (2023) AI Risk Management Framework Core - cross-cutting governance, inventory, training, monitoring, and role-clarity baseline
- [x] Microsoft Learn (2025) Copilot Studio security and governance - sanctioned-platform control surfaces and auditability
- [x] Microsoft Learn (2025) Configure data policies for agents in Copilot Studio - real-time DLP enforcement and configurable restrictions over tools, knowledge, channels, authentication, and triggers
- [x] Microsoft Learn (2025) Shadow AI discovery in Microsoft Entra Global Secure Access - network-based discovery and usage analytics for unsanctioned AI apps and tools
- [x] Microsoft Security Response Center (2025) How Microsoft defends against indirect prompt injection attacks - action and exfiltration risks that exceed classic DLP-only framing
- [x] Open Worldwide Application Security Project (OWASP) (2025) LLM01 Prompt Injection - why prompt injection remains incompletely preventable and why least privilege and human approval remain necessary
- [x] Google Cloud DORA (2025) Announcing the 2025 DORA report - evidence that AI amplifies existing workflow and platform weaknesses
- [x] Mitchell (2026) How do organisational incentives, culture, and behaviour influence adherence to governance in AI and low-code environments? - prior repository synthesis on governance circumvention drivers
- [x] Mitchell (2026) What capability and control design is needed to mitigate incentive misalignment, shadow AI, rail bypass, and skill decay at enterprise scale? - prior repository synthesis on interacting failure modes and scaled controls
- [x] Mitchell (2026) What are the primary failure modes in enterprise AI and low-code deployments, and how can governance systems be designed to mitigate them? - prior repository synthesis on failure classes and control mapping
- [x] Mitchell (2026) What observability and telemetry model is required to govern AI and low-code systems at scale? - prior repository synthesis on telemetry and reconstruction requirements
- [x] Mitchell (2026) UELGF extension: agentic AI-specific risks and runtime monitoring for non-deterministic behaviour - prior repository synthesis on precursor monitoring for agentic risk
| version | date | commit | summary |
|---|---|---|---|
| 1.0 | 2026-05-09 | 47d7bc5 | Initial completion |