gonzalo@flores — ~/en/writing/your-team-already-adopted-ai-without-you ES
Gonzalo Flores Kemec

← Writing

·3 min read ·shadow AI

Your team already adopted AI without you

Shadow AI is not a security problem to ban: it is a diagnostic signal. Almost half of employees use AI in ways that contravene their organization's policies. That does not measure indiscipline; it measures the distance between what policy allows and what the work needs.

While leadership debates whether to “adopt AI”, the team already adopted it. Someone pastes a client email into ChatGPT to draft the reply, another uploads a sales spreadsheet to get a summary, a third uses a personal copilot to write code. No policy, no explicit permission, often with internal data. That is shadow AI, and the costliest mistake is reading it as a security problem you solve by banning.

The numbers are large. The global study by the University of Melbourne and KPMG (Gillespie, Lockey et al., 2025; more than 48,000 people across 47 countries) found that almost half of employees admit to using AI in ways that contravene their organization’s policies —including uploading sensitive information to public tools—. On the cost side, IBM’s Cost of a Data Breach 2025 reports that organizations with high levels of shadow AI pay on average around 670,000 dollars more per breach than those with little or none. (It is an industry report: treat it as cost color, not as population statistics.)

Not indiscipline: latent demand

The temptation is to treat the employee who uses AI in secret as someone breaking the rules. But look at what they actually did: they solved a work need the organization failed to channel. It is the same old workaround —the parallel spreadsheet, the undocumented shortcut— now with a language model instead of an Excel file. And like any workaround, it is latent demand made visible: it says, with a precision no internal survey achieves, what the person lacks in order to do their job.

That almost half do it against policy does not, then, measure a discipline problem. It measures the distance between what policy allows and what the work needs. Banning without reading that distance does not remove it: it pushes it further into the shadows, where it can neither be governed nor protected.

From risk to roadmap

In my framework, shadow AI is a diagnostic symptom, not a crime. The answer is not a memo threatening sanctions; it is reading the need and governing it:

  1. Inventory the real use cases. Which tools showed up, for what, with what data. The inventory is already half the policy.
  2. Classify the risk. Drafting an internal email is not the same as uploading client data to a public tool with no processing agreement.
  3. Channel toward governed alternatives. Give the tool the person already sought on their own, but with a data agreement, and a one- or two-page policy people actually understand —not a twenty-page PDF no one opens—.

That same KPMG study sharpens the diagnosis: 57% hide that they use AI, 66% trust what the model returns without verifying it, and only 47% received any training. Heavy use, little verification, hidden use, and almost no one trained. It is not distrust of AI; it is absent governance felt in the worker’s body.

Why this is sociotechnical, not a firewall matter

Shadow AI does not appear in the code: it appears in the gap between the formal process and the real one. It is sociotechnical debt —the liability that accumulates each time technology is installed (or banned) without resolving the human subsystem—. A firewall pushes it into the shadows; an honest policy turns it into information. Closing the distance between what is allowed and what is needed turns shadow AI from a risk into an adoption roadmap: the map, drawn by your own team, of where AI is already paying off and where it still needs governing.


The framework is developed in The sociotechnical bridge and in My approach. Related essays: SME maturity is not a straight line · In the public sector, what cannot be audited cannot be used.

./contact --talk

Does this sound like your organization?

Diagnosis, architecture, implementation or AI governance. Remote, UTC−3, trilingual.

Contact