
AI Is the New Shadow IT
Joe Crabtree
August 12, 2026 · 17 min read
Somewhere in your company there is a spreadsheet called something like FINAL_v4_USE_THIS_ONE.xlsx. It calculates a number that ends up in a board deck. It was built by a person who left in 2021. Nobody in IT has ever seen it, there is no backup, and everyone is quietly terrified of the day it breaks.
That spreadsheet is the ancestor of the problem I want to talk about. It is also the reason I am not going to tell you that shadow AI is unprecedented. It is extremely precedented. We have been here for decades.
What is new is the meter. That spreadsheet was built once and then used by everybody for years, which was a governance disaster and, purely by accident, unbeatable value. Its modern replacement gets rebuilt from scratch every single time somebody needs it, by somebody who has no idea it already exists, and your company pays full price for every rebuild.
I was shadow IT before I knew there was a name for it
I started my career in the early 2000s, which is right around when somebody finally coined the term "shadow IT." I had never heard it. If you had said it to me back then I would have assumed it was related to shady hacking.
What I was actually doing was solving customer problems with the latest technology, which was arriving faster than anybody's ability to think about it. Somebody needed a report the official system did not produce, and waiting for the official system to produce it was not a plan, it was a wish. So I built it. It started as an Excel workbook. Then the workbook grew a few macros, because doing the same thing by hand every Monday morning is how you learn to write macros. Then the macros grew into real Visual Basic, because by that point the thing had a user interface and, heaven help us all, error handling. Then the data outgrew the spreadsheet and I moved it into an Access database sitting on a shared drive. I was extremely proud of this back then.
Nobody in IT knew it existed. No backup, no access control beyond whoever could find the folder, no record of what it did to the numbers before they went upstairs, and no plan for the day I moved on. Which I did, eventually, leaving behind a file with my initials in the name and a small group of people who were now afraid of it.
I was not being sneaky, and neither were my managers, who thought the whole thing was fantastic. The capability was real, the need was real, and the governance model did not exist yet because the industry had not finished inventing it. I was a young coder with a deadline and the most powerful tool within reach.
But here is the part worth holding onto, because it is the part we have since thrown away. That ugly little database was used by everyone. One person built it, once, and forty people got the answer out of it for years. It was a governance nightmare and an efficiency miracle at the same time. The tool was in the shadow. The answer never was.
The playbook we already paid for
In 2003, "we did not know any better" was completely true. It is not available to us anymore, because companies then spent twenty years fighting shadow IT through three phases and learning exactly which one works.
Prohibition. Block the domain, lock the laptop, write a policy with the word "strictly" in it. This has the same success rate as banning snacks in an open plan office. People are not defying you. They are hungry and trying to finish something by Thursday.
Discovery. Around 2012 Gartner coined the term cloud access security broker, built around one embarrassing question: what are our people actually using? IT teams who confidently estimated forty applications would get a report back listing three hundred. Discovery did not stop shadow IT. It ended the pretense that anyone knew what was going on.
Absorption, which is the one that worked. Every shadow tool was evidence of a real unmet need and a sanctioned path that was too slow, so the organizations that got a grip stopped treating users as the problem and built a fast lane instead.
That is the whole lesson. Shadow IT is not a discipline problem. It is a latency problem. People route around the official path when the official path is slower than the deadline.
Then the shadow learned to think
Here is where the pattern breaks, and it breaks in the one place we had finally built a defense.
The concern with every previous wave was data governance. Company information living outside the company's retention rules, access model, and audit trail. What made it survivable is that shadow IT left tracks. An unapproved tool is a thing. It has a domain in the proxy logs, a charge on an expense report, a file that moved from here to there. That is the entire reason discovery worked at all.
Generative AI erases the tracks. The tool is a text box. The data leaves as typed prose in the middle of a conversation, not as a file transfer anyone can flag, frequently on a personal device at ten at night. No discovery report will ever contain the line "the three year strategy, pasted on Tuesday." Every organization is now back to phase one visibility while believing it is still in phase three.
Then there is the part with no precedent. Data does not just flow out, judgment flows back in. Someone pastes your strategy into a personal chat account and outsources a piece of executive reasoning to a system nobody chose, under terms nobody read, with no record that it happened. Six weeks later a decision worth several million dollars rests partly on a conversation that cannot be reconstructed. And because it cannot be reconstructed, the next person who needs that same reasoning has no way to reach it. They will buy it again.
Think of it as hiring a brilliant consultant who works from an unlisted address, keeps a perfect copy of every document you hand over, never signs an engagement letter, and is available at two in the morning. The last part is exactly why your team hired them. And they did hire them, at scale. Microsoft and LinkedIn found that 78 percent of AI users bring their own AI tools to work, and Cyberhaven's telemetry found that 32.3 percent of enterprise ChatGPT use runs through personal accounts.
The frameworks were supposed to handle this
Every major consulting firm has been selling Responsible AI Governance since around 2019. The principles, the ethics board, the risk taxonomy, the acceptable use policy, the maturity assessment with the spider chart. Real money changed hands.
Now look at whether any of it changed behavior. KPMG and the University of Melbourne surveyed more than 48,000 people across 47 countries and found that 57 percent of employees hide their AI use and present the output as their own, and that close to half admit using AI in ways that break their employer's policy. Sit with the fact that a Big Four firm published that. The people selling the frameworks are the ones documenting that the frameworks are not landing.
I don't think the frameworks are bad. I think they answer the wrong question. A framework establishes what is permitted. It does not make the permitted thing faster than the forbidden thing, and it does not make the permitted thing reusable. An employee standing between a governed workflow that needs a request and an approval, and a text box that answers in four seconds, is not weighing your policy. They are meeting a deadline.
Four bills arrive, and the quiet one is the biggest
Security. IBM's 2025 Cost of a Data Breach research found that 20 percent of breached organizations were compromised through shadow AI, that high shadow AI exposure added roughly $670,000 to the average breach, and, most damning, that 97 percent of organizations reporting an AI related breach had no proper AI access controls. Not weak controls. None.
Compliance. Your auditor will eventually ask who approved this analysis, what data went into it, and can you show me. If the answer involves a personal account and a browser tab, you do not have a finding, you have a paragraph in a report. "Our people use AI responsibly" is not a control. A control has a log.
Privacy. Not everyone in your company is supposed to see everything. Then somebody pastes the compensation model, the layoff scenario, or the acquisition thesis into a tool that has no idea your company has an org chart. Buying the enterprise version does not fix this on its own. A company wide chat deployment where anyone can ask anything about anything is the same exposure with better paperwork, unless somebody actually modeled who is allowed to see what.
Cost. This is the quiet one, and it is the one this article is really about. Scattered subscriptions on expense reports are only the visible half of the bill. The larger half never appears as a line item at all, because it is the same intelligence being purchased over and over by people who cannot see each other working.
You are buying the same answer over and over
To be fair to everyone, the access problem is largely getting solved. Most companies I talk to have signed the enterprise agreement, turned the seats on, and put a real sanctioned tool in front of their people. That happened faster than any adoption cycle I have watched in twenty years.
It did not empty the shadow. Most of the numbers above were measured inside organizations that already had AI policies, and often a sanctioned tool as well. Standing up the corporate version does not retire the personal account. It adds a second place where the work happens, on top of the first one, which is still running at ten at night on somebody's home wifi.
And here is what almost nobody did next. They stopped there.
What most enterprises actually bought is a personal chat account with the company logo on it. Everyone got their own. Every conversation is private. Nothing anybody produces is visible to anybody else. That is fine for one person. Look at what it means across a whole organization and the economics fall apart.
Picture one company in one week. Someone in finance asks the model to size the risk in a vendor consolidation. Someone in operations asks nearly the same question in different words on Wednesday. Someone in strategy asks it again on Thursday, because they are building a board slide and had no idea the first two conversations ever happened. Three answers come back. All three are reasonable. All three are slightly different, because that is how these models work. All three were paid for at full price. And in a real company this is not three people once. It is thirty people, every week, forever.
Nobody in that story did anything wrong, which is exactly what makes it so hard to see. Each of those three people made a perfectly sensible decision. The organization made a terrible one, repeatedly, and never found out, because there is nowhere you could stand to watch it happen.
This is what is actually underneath the runaway AI bills now making the news. Uber burned through its entire 2026 AI coding budget by April. Vitaly Gordon, the CEO of Faros AI, described one of his own engineers spending $40,000 on tokens in a single month, then added the sentence that should be pinned above every CFO's desk: "I genuinely don't know whether I should stop him or should I go and tell everyone else to be like him." He is not describing a discipline problem. He is describing a man who cannot tell value from waste, because nothing in his stack was built to show him. J.R. Storment, executive director of the FinOps Foundation, heard companies say they were 3x over their entire 2026 token budget in April, and watched the conversation shift from "go fast" to "we need guardrails."
Read those closely and notice what they are not. They are not stories about buying something nobody needed. They are stories about finding out late. Not one of those companies decided to spend that money. They discovered it afterward, on an invoice. And the meter runs faster every time the tools get better, because an agent does not ask one question, it asks hundreds of them in a loop while you are at lunch.
So the cost problem and the reuse problem are not two problems. They are one problem wearing two hats. Your company is paying, again and again, for answers it already owns and cannot find.
Now notice where this one is happening. Inside the sanctioned tool, in daylight, on the corporate account, by people doing exactly what you asked them to do. Which took me a while to make sense of, because it did not look like shadow IT to me at all.
Then I worked out why. Shadow IT has changed shape on us, and the definition we have used for twenty years now describes the wrong half of the problem.
For two decades the shadow was the tool. The thing you could not see was the Access database, the unapproved app, the workbook with a business process buried in it, and it mattered because company data was sitting somewhere nobody governed. But look again at what my database actually did once it existed. It was completely ungoverned and completely visible. Forty people used the same one. The output was the most shared object in the building.
Generative AI inverts both halves. The tool is now the governed part, procured and logged and wired into single sign on. The output is what fell into shadow. Forty people, forty private conversations, forty answers nobody else will ever see, all of it produced on a tool your CIO signed off on.
That is a harder problem than the one we solved, because this time there is nothing to discover. A scanner can find an unapproved app. Nothing you can buy will tell you that your head of finance and your head of operations paid to ask the same question nine days apart.
So granting access was only half of absorption. The half that made absorption work was making the sanctioned path genuinely better than the alternative, and a private text box with a company logo on it is not better. It is the same text box with central billing.
The front door does not just have to be faster. It has to remember.
What a governed AI path actually needs
Four properties, and none of them are exotic.
Answers that get reused instead of bought twice. This is the one everybody forgets, and the only one that reduces consumption rather than restricting it. If an expensive piece of analysis is produced once and then lives where the whole organization can see it, build on it, and argue with it, the second person who needs it pays nothing. If it disappears into a private chat window, your company will buy that same answer again, and again, at full price, forever.
One pooled budget, not a hundred private ones. Per seat allowances quietly guarantee the duplicate spending, because a balance that belongs to one person is a balance nobody else can see being spent, and what you cannot see you cannot stop buying twice. Pooling also matches the work, which is spiky. The person running a market analysis this month needs ten times what they needed last month, and the finance lead needs almost nothing until quarter close.
Permission to run AI, separate from permission to read. Being allowed to look at the strategy is not the same as being allowed to spend company money and company data generating new analysis on top of it. Those should be separately grantable, and the second one should be auditable.
Cost visibility before the spend, not after. Nobody makes a good decision about whether an analysis is worth running when the price arrives four weeks later on a summary invoice. Show the estimate at the moment of the click, and show the organization its running position while there is still something to be done about it.
How we built this into Analyzt AI
What we are actually building is a place for an enterprise to centralize its LLM intelligence. Every expensive thought the organization pays a model to have should end up somewhere it can be found again, questioned, extended, and reused, instead of evaporating in a browser tab belonging to one person.
Strategy execution is where we started, and it is just the first module. We started there deliberately, because it is the broadest and most delicate use case. Strategy work involves the most sensitive data in the company, the highest value decisions, and the analysis most likely to be quietly redone by somebody who never knew it had already been done.
Run it once, and everyone can see it. When someone generates an assessment narrative or a business case analysis, it is saved to the organization and it is there for the next person, who reads it instead of buying it again. Better than that, they can build on it, challenge the assumptions inside it, and take it further, because it is a shared artifact rather than one person's private transcript. In the world I described earlier, thirty people produce thirty slightly different numbers. That is not just wasteful spending. It is how a company ends up arguing about whose figure is right instead of deciding what to do.
Tokens belong to the organization, not the seat. One pooled balance, drawn on by whoever is doing the work that week. Unused balance carries forward rather than expiring, because we would rather people use the platform for the right reasons than the calendar ones. Consulting firms running multiple client organizations pool across the whole firm.
Running AI is its own permission. Reading the platform and executing AI against it are separate rights, granted separately, logged separately. That distinction sounds small until an auditor asks who is allowed to generate analysis on regulated data, and you can answer with a list instead of a shrug.
Nothing generates on its own, and you see the estimate first. Every AI action is an explicit click, and before the click you get an estimate of what it will consume. Nobody finds out in the following quarter what April cost.
And the boring but critical part: everything runs against the company's data, with an audit trail. Every run is attributable to a person, a purpose, and a cost.
The uncomfortable conclusion
Your people are using AI on company strategy right now. They are not being reckless. They are being productive in the only way currently available to them, which is precisely what every generation of shadow IT has been. You will not fix that with a policy. Nobody ever has. You fix it by building a sanctioned path that is genuinely better than the shadow one, and then getting out of the way.
But the version of this that keeps me up at night is not a data breach. It is quieter than that, and considerably more expensive. It is a company that has already paid for an answer three times and is about to pay for it a fourth, because the first three are sitting in three private chat windows belonging to three people who have never spoken to each other about it.
Sit with how strange that is. The thinking got done. The company paid for it. The company owns it. And the company still cannot find it, cannot check it, and cannot build on it, so next week it buys the same intelligence again, at full price. None of that appears on any invoice you could read. It just quietly becomes the largest AI line item you have, and the only one you were never shown.
An organization's accumulated intelligence is supposed to be the thing that compounds. Right now, in most companies, it is the thing being repurchased.
That ugly little Access database I built twenty years ago got one thing right that your enterprise AI rollout is getting wrong. It was built once, and everybody used it. We spent twenty years learning how to govern the tool. The work now is to stop losing the answer.
If that sounds familiar, come see what governed AI looks like. And if you run a consulting firm answering these questions for clients right now, let's talk.
About the author
Joe Crabtree is the founder and CEO of Analyzt AI. He spent more than 20 years in strategy and transformation consulting, including over seven years at Avanade, an Accenture company, before building Analyzt AI to give organizations consulting rigor and strategy execution in one AI scored platform.
Connect on LinkedInSee how Analyzt AI puts this into practice.
Join the Beta