No. 004 · AI Governance

Shadow IT Was the Rehearsal

In 2025 I published a piece in the ISACA Journal on shadow IT governance — specifically how and why employees adopt unauthorized technology outside of sanctioned IT channels, and what that means for organizational security culture.

The core finding wasn't surprising in hindsight: employees don't adopt shadow IT because they're trying to create risk. They adopt it because the unsanctioned tools solve a real problem faster than the approved ones do. The productivity gain is immediate and personal. The governance risk is diffuse and deferred. When those two things compete, behavior wins over policy almost every time.

What made shadow IT hard to govern wasn't the technology. It was the gap between how the policy traveled — top-down, documented, signed — and how the behavior traveled — peer-to-peer, through habit, through a colleague saying "just use this."

Organizations that never closed that gap didn't close it by writing better shadow IT policies. Most just learned to live with it.

Reading the AI governance data coming out in 2026, I keep seeing the same dynamic — same incentive structure, same behavioral pattern, same governance gap. The difference is speed and scale. Shadow IT crept in over years. AI is doing the same thing in months, across every function, at every level of the organization.

A policy document didn't solve shadow IT. It's not going to solve this either.


No. 004 in the Threshold Effects series. First published on LinkedIn, July 29, 2026.