No. 003 · AI Governance

Paper Trails and Shadow AI

Organizations invest significant resources building compliance programs — policies, training, audits, documentation.

How much of that investment actually changes behavior versus simply documenting that the organization tried?

According to Gartner, only 37% of compliance leaders are confident in their ability to measure program effectiveness. That's not a data collection problem. That's a design problem.

In my experience, the gap between a compliance program that documents effort and one that actually shifts behavior comes down to a single question: do the people who wrote the policy understand why the behavior they're trying to govern exists in the first place?

Most of the time, they don't. And a rule written without that understanding doesn't change behavior — it just creates a paper trail.

Curious what others are seeing on the ground.

ISACA's 2026 AI Pulse Poll surveyed 3,400 digital trust professionals and found that 90% believe employees at their organizations are using AI tools. Only 38% have a formal comprehensive AI policy. One in four have no policy at all.

KPMG's research puts the behavioral picture in even sharper focus. Half of the U.S. workforce reports using AI tools at work without knowing whether it's allowed. Another 44% admit to knowingly using AI in ways that contravene company policies and guidelines. Only 41% of employees report that their organization has any policy guiding AI use at all.

Read those numbers together. Then read them again.

This isn't a compliance gap. It's a governance design problem.

AI policy travels top-down as a document — authored by leadership, signed once, filed somewhere. AI behavior travels peer-to-peer as a habit — spread through shared prompts, chat threads, and a colleague saying "you have to try this." Those two channels don't touch each other. A rule that travels one path and a behavior that travels the other will diverge no matter how well the rule is written.

The productivity calculus makes it worse. When the reward for using an unapproved tool is concrete, recurring, and personal — and the risk is abstract, deferred, and someone else's problem — the behavior wins. Every time.

We've seen this pattern before. Shadow IT didn't disappear because organizations wrote better policies. It persisted because the tools people weren't supposed to use worked better than the ones they were supposed to use. AI is following the same road at a much faster speed.

The question worth asking isn't how do we enforce the policy we already have. It's why did we think a document was going to govern a behavior in the first place.


No. 003 in the Threshold Effects series. First published on LinkedIn, July 27, 2026.

0255075100ISACA 2026 AI PULSE POLLBelieve employees are using AI tools90%Have a formal comprehensive AI policy38%KPMG GLOBAL STUDY 2025Use AI at work without knowing if allowed50%Work at an organization with any AI policy41%
Ninety percent use it. Thirty-eight percent govern it.AI use and AI policy coverage, two independent 2025-2026 surveys.Source: ISACA 2026 AI Pulse Poll; KPMG Trust, Attitudes and Use of AI — Global Study 2025.
View data table
sourcemeasurepercent
ISACA 2026 AI Pulse PollBelieve employees are using AI tools90
ISACA 2026 AI Pulse PollHave a formal comprehensive AI policy38
KPMG Global Study 2025Use AI at work without knowing if allowed50
KPMG Global Study 2025Work at an organization with any AI policy41

Download the data (CSV)