
Shadow IT has often followed the same arc — and consumer technology is typically the throughline. The smart phone became an essential communications tool. Home computers and fast home Internet enabled flextime, and personal productivity software was familiar and easy to use. The consumerization of IT brought BYOD (bring your own device) into the enterprise. And let’s not forget employees setting up non-IT routers or buying SaaS services with their company credit card. IT leaders had to establish a template for how to respond: not with outright bans, but with governance frameworks.
Shadow AI is following a similar arc, but with more risk. The stakes are higher due to potential data leaks, error amplification, and hallucinations. The pace is faster than many procurement cycles can handle – or new tools are emerging too quickly for IT teams to evaluate. What’s more, enterprise AI tools often lag far behind what’s freely available.
Foundry reached out to the CIO Experts Network, a community of IT professionals and technology industry influencers, to identify effective approaches and best practices for successfully managing shadow AI.
Shadow AI is a signal for CIOs
Shadow AI isn’t a problem to eliminate — it’s a signal to listen, experts say. When teams adopt AI tools outside of IT’s purview, it often means the official list of approved tools isn’t meeting employee needs fast enough.
“Employees are turning to AI not out of defiance, but because approved tools aren’t keeping pace. The infrastructure we position as our innovation gateway is often 6-12 months behind even baseline AI capabilities,” says Peter Nichol, Data & Analytics Leader, North America, Nestlé Health Science. “In this environment, blocking shadow IT simply doesn’t work, it only drives it further out of sight. The real opportunity is to recognize it as unmet business demand and respond by delivering capabilities that provide the speed, intelligence, and outcomes the business is actively seeking.”
Oreoluwa Adesanya, .NET ENGINEER and Backend Developer, agrees. “Shadow AI isn’t a rebellion — it’s a signal that your approved tools aren’t keeping up,” he says. “The fix isn’t to block and restrict, it’s to offer better, faster, safer alternatives that people actually want to use.”
Adesanya recommends organizations lock down data risk by building a private model gateway and governance layer that gives teams the AI power they need without exposing sensitive data to tools that are not vetted. By embedding approved AI directly into the platforms people already work in daily, he says, the appeal of going rogue disappears naturally. Ultimately, every shadow AI tool in an organization is a gap in strategy. Find the gap, close it, and the problem is solved at the root, he adds.
Governance starts with visibility, engagement, and education
One way to channel AI usage is by establishing governance frameworks that set clear boundaries around data privacy, security, and compliance, while still giving teams room to experiment. “Create an approved fast lane, or a curated set of vetted AI tools and APIs that people can adopt without months of procurement cycles. The goal isn’t to control every AI interaction, but to ensure that innovation happens within guardrails that protect the organization without stifling the people driving it,” says Javier Campos, AI Safety Researcher and Group Chief Technology Officer at Cape.io (formerly Peach).
Dr. Martin De Saulles, Principal Analyst at Information Matters, suggests a three-pronged approach — understand, educate, and provide. “Leaders first need to understand why employees are using AI and what tasks they are using it for. They then need to provide training on the risks to the business of unauthorized AI use as well as best practices for getting the most from those tools,” he says. “At the same time, employees must be given access to the best-in-class AI products for specific types of tasks while putting ‘walls’ around sensitive company data to prevent leakage.”
Employees often turn to unauthorized AI tools because sanctioned options are too slow, too locked down, or simply don’t yet exist. “CIOs who respond with blanket bans are just pushing adoption further underground, where data exposure and compliance risk compound invisibly,” cautions Will Kelly, a writer focused on AI and the cloud. “The better move is to stand up lightweight governance guardrails, give teams approved AI tools that solve their problems, and treat shadow AI as a demand signal rather than a policy violation. If your people are going around you to get work done, the dysfunction is yours, not theirs.”
Managing shadow AI starts with visibility, not punishment, says Tom Allen, founder of The AI Journal. “Assume people are using unapproved tools because they are trying to move faster, then map where AI is actually in use through surveys, logs, and network monitoring.”
“Rather than banning everything,” he continues, “provide a set of sanctioned AI tools with clear, AI‑specific acceptable‑use policies, training on what data can and cannot be shared, and simple ways for teams to request new tools. Finally, embed AI governance, including data protection controls, model and vendor risk assessment, and monitoring for sensitive data exfiltration, so that ‘shadow AI’ is steadily pulled into the light and managed as part of the normal technology portfolio.”
Establish what constitutes “safe use”
Vivek Singh, Senior Vice President of IT and Strategic Planning at PALNAR, suggests that CIOs don’t overreact. The first step CIOs must take is determine how to enable safe AI use across the enterprise. Singh’s recommendations include:
- Develop policies around the tools that are allowed, data usage, and risk levels.
- Develop a safe sandbox of vetted AI solutions.
- Monitor data classification and limit restrictions around it.
- Engage, educate and train all internal teams.
- Most importantly, security should be seen as an enabler of innovation and not a barrier.
In closing, Scott Schober, President and CEO at Berkeley Varitronics Systems, Inc., says: “A few years ago, I worked with an organization that discovered employees quietly feeding sensitive data into public AI tools to speed up their work—well-intentioned, but risky. The lesson was clear: you can’t manage shadow AI by banning it; you have to get ahead of it.”
“CIOs should establish clear, practical guidelines for AI use, paired with approved tools that are just as accessible and useful as what employees might seek on their own,” he says. “Visibility is key—monitoring and data loss prevention controls help identify unsanctioned use without creating a culture of surveillance. Most importantly, make security part of the enablement process so teams feel supported, not restricted, when adopting AI.”
Explore how organizations can enable trusted, enterprise-ready AI with the right context and guardrails here.
