Skip to main content

What We Do in the Shadows: The Elephant in the AI Strategy Room

Many organisations believe they don't have an AI strategy yet. That's the comfortable version. The uncomfortable version is that they already do. It just hasn't been designed intentionally.

27 March 2026

Many organisations believe they don't have an AI strategy yet.

That's the comfortable version. The uncomfortable version is that they already do. It just hasn't been designed intentionally.

Across industries right now, employees are using AI tools in their daily work, often without approval, often without anyone upstairs knowing, often with sensitive data flowing through systems nobody has vetted or even identified. This is shadow AI, and it's far more widespread than most leadership teams know, or want to acknowledge.

The data isn't ambiguous. Over 80% of employees use unapproved AI tools. More than 90% of companies show evidence of employee-driven AI usage. Over half of those employees have put sensitive data into AI systems their employer knows nothing about. One in five organisations has already had a breach linked to this behaviour.

These figures come from sources including UpGuard, Reco, Menlo Security, MIT, IBM, and Gartner, drawn from surveys of thousands of employees and IT leaders and from enterprise telemetry data. Prevalence varies by company size, industry, and region, but the trend holds everywhere: employee-driven AI use far outpaces official approval, and that gap creates security, compliance, and data leakage risk.

The reason isn't a mystery. Employees aren't waiting for a strategy because they don't need one. They're responding to pressure to move faster, to tools that are freely available, and to the entirely rational wish to do less mindless work. From where they sit, using AI makes sense. From where leadership sits, it's uncontrolled adoption, and it's becoming a serious problem.

Restricting access rarely works. Block the tools, lock down the systems, and employees switch to personal accounts, work outside the corporate network, and route around whatever controls you've put in place. That leaves you with the worst of both worlds: AI in use across your organisation, but invisible, ungoverned, and unconnected to anything you've actually decided.

AI adoption won't be stopped. The real issue was never the presence of AI. It's the absence of structure around it.

Without clear policies, defined use cases, knowledge governance, or decision frameworks, AI becomes another layer of complexity stacked on existing complexity. Unmanaged complexity creates risk immediately, not eventually.

Regulation is starting to catch up. Legislation emerging across regions will require organisations to demonstrate they understand how AI is being used, that data exposure is managed, that accountability exists, and that governance is actually in place. For many organisations, that's going to be a reckoning, not because they used AI, but because they won't be able to show where, how, or whether it was used responsibly.

So whether you designed it or not, your organisation already has an AI strategy. It looks like employees choosing tools individually, usage patterns forming on their own, decisions made without oversight. It's a strategy. Just not a defensible one.

If you're still asking whether to adopt AI, that decision has already been made by the people who work for you. The real question is how you take control of the usage that already exists, and the adoption still coming.

Structure before AI. Most organisations are doing it in the wrong order.

Shadow AI isn't a threat to eliminate. It's a signal that your organisation is already evolving, whether you're steering it or not.