It borrows its name from shadow IT in the cloud era, and it arrives the same way: individuals adopt something useful for their productivity.
A June 2026 PagerDuty survey of 1,250 office professionals at large companies found two thirds had used AI tools at work they believed company policy did not allow. At that level it stopped being an exception some time ago.
The reason somebody reaches for their own account
In the cloud computing days it could be an email, calendar, or note taking app somebody started using at work. With the explosion of SaaS software, and AI now integrated into almost every program and platform, an employee can be using a product that does not align with the company’s policies around privacy or confidentiality without ever realizing it.
What agents changed
For two years you could audit this by asking, because it was one person, one chatbot, one conversation, and somebody could tell you what they typed and the work product they collaborated on.
An agent reads a transcript nobody handed it, writes to a project record, pulls a past proposal from a different system, and schedules a follow-up, while you are at lunch. Your question moves from "was that a good answer" to "did that sequence do the right thing across four systems, with the correct information?"
Microsoft shipped Agent 365 into general availability in May 2026. The category now has vendors in it, which is worth knowing mostly so you can ignore most of them at your size.
The three things that close it
McKinsey's 2026 AI trust survey added agentic AI governance and controls to its maturity model this year. The table below sorts what that takes into three jobs, with the way a large organization typically handles each. The small firm column is our translation of it, from building these inside firms of five to fifty.
| Pillar | Enterprise version | Yours |
|---|---|---|
| Continuous monitoring | A platform watching agent behavior live | A log. Which agent ran, what it read, what it produced, what it changed. It lives in your source of truth. Review it weekly until you trust it, then monthly |
| Transparent governance | An AI council, a policy board, a procurement gate | A one page list. Which agents run, what each is allowed to do, who owns each one. Updated quarterly, pinned where the team can read it |
| Adaptive risk controls | Dynamic permission systems | A kill switch and a tested rollback. You can turn something off and undo what it did without calling a vendor |
The failure these prevent is undramatic, which is why it goes unnoticed. An agent works well for three months and performance can slip, iterative improvements can cause drift, and larger datasets can accidentally share the wrong information much like an employee could. Client concerns on a call could be missed, call summaries could be too concise, a proposal that references the wrong service, or a follow-up goes out that contradicts what you said live. Caught early these are inexpensive mistakes. Left to accumulate across information handed between personal and corporate systems, they start to reflect on the organization, and a small business cannot afford to look sloppy in front of its clients.
Legal exposure is where this gets expensive fastest. Putting privileged email, meeting notes, or client documents through a tool your firm has not vetted can waive attorney client privilege, because privilege generally turns on who else can read the material and on what terms. Whether a given tool waives it depends on that tool’s contract and your jurisdiction, which is exactly why the decision belongs in a policy rather than in a moment. Understanding the chain of custody for sensitive, nonpublic, client or proprietary information is what lets you decide which silos may be shared with the technology you license, and unapproved agents and automations undermine the tightest governance structure you can write.
Related questions
What is shadow AI?
Employees using AI tools their organization has not approved or vetted. A June 2026 PagerDuty survey found two thirds of office professionals at large companies had used AI tools they believed company policy did not allow.
Why do employees use unapproved AI tools?
The work needs doing and no approved option exists. Somebody with a deadline reaches for whatever they can get to, and in most firms nobody has provided an alternative.
Does banning AI tools solve shadow AI?
No. Prohibition without provision moves the same behavior further out of view, since the work still has to get done. Providing an administered account removes the reason to use a personal one.
What is the small firm version of AI governance?
A reviewed log of what each agent did, a one page list of which agents run and who owns them, and a kill switch with a tested rollback. The discipline matches the enterprise version; the cost doesn't.
What does agentic AI failure usually look like?
Slow drift. An agent performs well for weeks, then makes small errors nobody catches because nobody reviews its output the way they would review a junior colleague's.
How we read this
The two thirds gets reported as a risk statistic and we read it as a demand signal. Two thirds of a workforce went and found tools that helped them do their jobs, without being asked. Most change programs would take that enthusiasm gratefully.
So we would make the first move to define what intellectual property and information can be accessed by new technology and what should not. Then understand the tools could be advantageous to your business, how they handle sensitive information, and supply them rather than enforce a zero shadow AI rule. Give people something administered that works as well as what they found, and most of the exposure resolves itself without a confrontation.
What doesn't resolve itself is visibility, and that's what the log is for. A log feels like overhead right up until the first time an agent does something surprising and you can answer what happened in a minute.
One caution. It only works if somebody reads it. A log nobody opens tells you what went wrong after the client already has.
What you can do this week
Write the one page list before anything else. Every agent or automation currently running, what it is allowed to touch, and one name against each. Think about the information they need to be successful and how some of the more sensitive data can be stripped from its reach.
Then be thoughtful about an experimentation strategy with shadow AI. A competitive advantage small businesses have is to be nimble about change and adoption of emerging technologies, but not at the cost of your proprietary information. Think about what areas of your business would benefit from experimentation at the least risk compared to those areas with high risk and draft a plan for your team to follow, including the hours they can have to experiment.
Working together
Flow State Found works with a limited number of businesses to make their best work their baseline. The firms we hear from have a rule against personal accounts and nothing sanctioned to offer instead. We provision first and write the rules around what people are already doing, which is what makes a policy hold.
We take on limited engagements, so it starts with a conversation.
Start a conversationFor Deeper Context
- Cloud Security Alliance, The Shadow AI Agent Problem in Enterprise Environments, April 28, 2026
- PagerDuty, shadow AI workplace survey of 1,250 office professionals, June 11, 2026
- McKinsey, State of AI Trust in 2026: Shifting to the Agentic Era, March 25, 2026
- Microsoft, Microsoft Agent 365, now generally available, May 1, 2026
- Futurum Group, on Microsoft Agent 365 and the agent governance category, May 8, 2026