No. 003 · AI Governance
Paper Trails and Shadow AI
Organizations invest significant resources building compliance programs — policies, training, audits, documentation.
How much of that investment actually changes behavior versus simply documenting that the organization tried?
According to Gartner, only 37% of compliance leaders are confident in their ability to measure program effectiveness. That's not a data collection problem. That's a design problem.
In my experience, the gap between a compliance program that documents effort and one that actually shifts behavior comes down to a single question: do the people who wrote the policy understand why the behavior they're trying to govern exists in the first place?
Most of the time, they don't. And a rule written without that understanding doesn't change behavior — it just creates a paper trail.
Curious what others are seeing on the ground.
ISACA's 2026 AI Pulse Poll surveyed 3,400 digital trust professionals and found that 90% believe employees at their organizations are using AI tools. Only 38% have a formal comprehensive AI policy. One in four have no policy at all.
KPMG's research puts the behavioral picture in even sharper focus. Half of the U.S. workforce reports using AI tools at work without knowing whether it's allowed. Another 44% admit to knowingly using AI in ways that contravene company policies and guidelines. Only 41% of employees report that their organization has any policy guiding AI use at all.
Read those numbers together. Then read them again.
This isn't a compliance gap. It's a governance design problem.
AI policy travels top-down as a document — authored by leadership, signed once, filed somewhere. AI behavior travels peer-to-peer as a habit — spread through shared prompts, chat threads, and a colleague saying "you have to try this." Those two channels don't touch each other. A rule that travels one path and a behavior that travels the other will diverge no matter how well the rule is written.
The productivity calculus makes it worse. When the reward for using an unapproved tool is concrete, recurring, and personal — and the risk is abstract, deferred, and someone else's problem — the behavior wins. Every time.
We've seen this pattern before. Shadow IT didn't disappear because organizations wrote better policies. It persisted because the tools people weren't supposed to use worked better than the ones they were supposed to use. AI is following the same road at a much faster speed.
The question worth asking isn't how do we enforce the policy we already have. It's why did we think a document was going to govern a behavior in the first place.
No. 003 in the Threshold Effects series. First published on LinkedIn, July 27, 2026.
View data table
| source | measure | percent |
|---|---|---|
| ISACA 2026 AI Pulse Poll | Believe employees are using AI tools | 90 |
| ISACA 2026 AI Pulse Poll | Have a formal comprehensive AI policy | 38 |
| KPMG Global Study 2025 | Use AI at work without knowing if allowed | 50 |
| KPMG Global Study 2025 | Work at an organization with any AI policy | 41 |