Governance

Shadow AI Is a Provisioning Gap

Two thirds of office workers at large companies have used AI tools they believed were not allowed.

Briefing 6 min read
DefinitionShadow AI is an employee’s use of personal AI tools and products for work, on accounts their employer has never vetted or approved.

It borrows its name from shadow IT in the cloud era, and it arrives the same way: individuals adopt something useful for their productivity.

A June 2026 PagerDuty survey of 1,250 office professionals at large companies found two thirds had used AI tools at work they believed company policy did not allow. At that level it stopped being an exception some time ago.

The reason somebody reaches for their own account

In the cloud computing days it could be an email, calendar, or note taking app somebody started using at work. With the explosion of SaaS software, and AI now integrated into almost every program and platform, an employee can be using a product that does not align with the company’s policies around privacy or confidentiality without ever realizing it.

What agents changed

For two years you could audit this by asking, because it was one person, one chatbot, one conversation, and somebody could tell you what they typed and the work product they collaborated on.

An agent reads a transcript nobody handed it, writes to a project record, pulls a past proposal from a different system, and schedules a follow-up, while you are at lunch. Your question moves from "was that a good answer" to "did that sequence do the right thing across four systems, with the correct information?"

Microsoft shipped Agent 365 into general availability in May 2026. The category now has vendors in it, which is worth knowing mostly so you can ignore most of them at your size.

The three things that close it

McKinsey's 2026 AI trust survey added agentic AI governance and controls to its maturity model this year. The table below sorts what that takes into three jobs, with the way a large organization typically handles each. The small firm column is our translation of it, from building these inside firms of five to fifty.

PillarEnterprise versionYours
Continuous monitoringA platform watching agent behavior liveA log. Which agent ran, what it read, what it produced, what it changed. It lives in your source of truth. Review it weekly until you trust it, then monthly
Transparent governanceAn AI council, a policy board, a procurement gateA one page list. Which agents run, what each is allowed to do, who owns each one. Updated quarterly, pinned where the team can read it
Adaptive risk controlsDynamic permission systemsA kill switch and a tested rollback. You can turn something off and undo what it did without calling a vendor

The failure these prevent is undramatic, which is why it goes unnoticed. An agent works well for three months and performance can slip, iterative improvements can cause drift, and larger datasets can accidentally share the wrong information much like an employee could. Client concerns on a call could be missed, call summaries could be too concise, a proposal that references the wrong service, or a follow-up goes out that contradicts what you said live. Caught early these are inexpensive mistakes. Left to accumulate across information handed between personal and corporate systems, they start to reflect on the organization, and a small business cannot afford to look sloppy in front of its clients.

Legal exposure is where this gets expensive fastest. Putting privileged email, meeting notes, or client documents through a tool your firm has not vetted can waive attorney client privilege, because privilege generally turns on who else can read the material and on what terms. Whether a given tool waives it depends on that tool’s contract and your jurisdiction, which is exactly why the decision belongs in a policy rather than in a moment. Understanding the chain of custody for sensitive, nonpublic, client or proprietary information is what lets you decide which silos may be shared with the technology you license, and unapproved agents and automations undermine the tightest governance structure you can write.

What is shadow AI?

Employees using AI tools their organization has not approved or vetted. A June 2026 PagerDuty survey found two thirds of office professionals at large companies had used AI tools they believed company policy did not allow.

Why do employees use unapproved AI tools?

The work needs doing and no approved option exists. Somebody with a deadline reaches for whatever they can get to, and in most firms nobody has provided an alternative.

Does banning AI tools solve shadow AI?

No. Prohibition without provision moves the same behavior further out of view, since the work still has to get done. Providing an administered account removes the reason to use a personal one.

What is the small firm version of AI governance?

A reviewed log of what each agent did, a one page list of which agents run and who owns them, and a kill switch with a tested rollback. The discipline matches the enterprise version; the cost doesn't.

What does agentic AI failure usually look like?

Slow drift. An agent performs well for weeks, then makes small errors nobody catches because nobody reviews its output the way they would review a junior colleague's.

How we read this

The two thirds gets reported as a risk statistic and we read it as a demand signal. Two thirds of a workforce went and found tools that helped them do their jobs, without being asked. Most change programs would take that enthusiasm gratefully.

So we would make the first move to define what intellectual property and information can be accessed by new technology and what should not. Then understand the tools could be advantageous to your business, how they handle sensitive information, and supply them rather than enforce a zero shadow AI rule. Give people something administered that works as well as what they found, and most of the exposure resolves itself without a confrontation.

What doesn't resolve itself is visibility, and that's what the log is for. A log feels like overhead right up until the first time an agent does something surprising and you can answer what happened in a minute.

One caution. It only works if somebody reads it. A log nobody opens tells you what went wrong after the client already has.

What you can do this week

Write the one page list before anything else. Every agent or automation currently running, what it is allowed to touch, and one name against each. Think about the information they need to be successful and how some of the more sensitive data can be stripped from its reach.

Then be thoughtful about an experimentation strategy with shadow AI. A competitive advantage small businesses have is to be nimble about change and adoption of emerging technologies, but not at the cost of your proprietary information. Think about what areas of your business would benefit from experimentation at the least risk compared to those areas with high risk and draft a plan for your team to follow, including the hours they can have to experiment.

Working together

Flow State Found works with a limited number of businesses to make their best work their baseline. The firms we hear from have a rule against personal accounts and nothing sanctioned to offer instead. We provision first and write the rules around what people are already doing, which is what makes a policy hold.

We take on limited engagements, so it starts with a conversation.

Start a conversation

For Deeper Context

  1. Cloud Security Alliance, The Shadow AI Agent Problem in Enterprise Environments, April 28, 2026
  2. PagerDuty, shadow AI workplace survey of 1,250 office professionals, June 11, 2026
  3. McKinsey, State of AI Trust in 2026: Shifting to the Agentic Era, March 25, 2026
  4. Microsoft, Microsoft Agent 365, now generally available, May 1, 2026
  5. Futurum Group, on Microsoft Agent 365 and the agent governance category, May 8, 2026

All Governance Briefings