What is Shadow AI?
The way AI gets into a business almost never started with a strategy.
Everyone got access to Copilot at work, because Copilot is what the business pays for, and many of NZ and Australia businesses are a Microsoft shop.
At home individuals try ChatGPT or Claude on a personal account, and the difference is instantly obvious: the frontier tools from Claude and ChatGPT are far more capable, easier to use, and built so that the average bear gets good results off the shelf with very little technical effort.
The experience at work with Copilot is often subpar, and reliant on IT setting up integrations to company data sources, Sharepoint sites being legible for AI to work with, and various features of the Microsoft suite being enabled for the user. In 95% of businesses, this foundation is not well set up.
The personal account is used on personal jobs (a CV, a speech, a holiday plan etc), and soon they're logging into it on a personal phone, then on the work laptop.
The next time a hard proposal or an awkward client email arrives at work, the choice is between the tool that struggles but has been okayed by the business, and the tool that delivers a better user experience with more capability, not sanctioned by the business.
We've all been told no by our parents at some point in our lives, and we all know that reaching for the forbidden toy is a much more pleasant experience than life without it.
So the employee opens their personal AI tool to complete the work task.
That is Shadow AI. Company work running through AI the business never approved and cannot monitor.
This pattern of behaviour has a predecessor: Shadow IT. When employees sign up for Dropbox or Trello because the approved systems didn't cut the mustard for what the person thinks they need.
Shadow AI is the same behaviour at far greater depth, because what flows through a personal AI tools is the actual thinking and judgement of the people working in a business: how work gets judged, priced, worded and decided.
What's wrong with Shadow AI?
Shadow AI is not edge case behaviour of the few.
UpGuard's State of Shadow AI research found more than 80% of workers use unapproved AI tools at work, with executives often the heaviest users of them all.
A PagerDuty survey found 66% of office professionals at large companies used AI while believing it broke company policy.
In nearly half of the conversations I have with people, most say they would rather use unsanctioned AI tools without telling anyone than risk being told to stop by asking for permission.
IT leaders tend to read all of this as data leakage risk, a legitimate concern. The issue is when employees put company or client information into AI tools that haven’t been approved by the organisation, with no enterprise agreement, security controls, retention policy or contractual protection around how that data is handled.
That is very different from using enterprise AI platforms where the organisation has agreed terms, admin controls and clear commitments around how company data is stored, processed and used.
Now, in fairness to these IT leaders, the response, almost everywhere, indexes on the stick rather than the carrot:
Ban unsanctioned tools
Block the domains
Hand down a policy that restricts everything except the approved toolset
We're three years into the AI revolution, impacting way people work, and that approach has produced 80% non-compliance, because people do not accept being told they cannot use something that makes them better at their job.
Prohibition doesn't remove the behaviour, just look at alcohol prohibition back in the day. It just moved underground.
Prohibition just puts a leader's mind to artificial rest at thinking they've protected the business when in-fact they're focused on the wrong thing.
The real risk needs reframing
Nearly every conversation about Shadow AI is a conversation about protecting company data.
That is an important framing, but it should not be the priority.
Genuinely damaging categories of information (customer records, source code, pricing, legal terms) all deserve clear controls and rules, and get no argument from me against that approach.
But they are likely a small slice of daily AI use for power users. For most businesses, most of the time, a lot of what gets leaked through Shadow AI is barely valuable enough to hand a competitor an advantage.
The loss that does hand competitors an advantage runs in the opposite direction and is not well understood by leaders.
Every AI conversation throws off what I think of as data exhaust: the decisions being made, the judgement being applied, the corrections given, the way the business's best people work through a problem, all written down for the first time anywhere.
That exhaust is gold within a business, and capturing and saving it is everything to building a business that runs on AI as its operating system.
When work runs through personal accounts, none of it gets captured; it lands in a chat history the business never sees. The knowledge, or context in AI speak, is not being captured.
So the question for businesses doesn't rest in a policy document, it's: how does the business get everyone working inside enterprise AI tools, and capture the decisions, judgement and work happening in them, so it builds a learning advantage no competitor can buy off the shelf?
The goal is not zero AI risk, because zero risk means zero learning. The goal is intelligent risk management to build a learning advantage.
The learning advantage
Two things become possible the moment work runs through enterprise AI tools with the right information capture mechanisms built in.
The business starts accumulating a written record of how its people actually think and work: the decisions, the judgement calls, the reasoning behind every piece of finished work.
It can then put the best AI models to work on that information: quoting from it, drafting from it, training new staff with it, and automating around it. That information and those captured records are the new asset, one the business can reuse in every future AI conversation, and it only exists if the conversations happen where the business can capture them.
The reason capture is worth so much comes down to the single fact that AI intelligence is democratised, and is accessible to everyone.
Every competitor can rent the same ChatGPT, Claude or Copilot for the same monthly fee, so the tools themselves give nobody an advantage. The edge comes from what each business can give to the tools, what context a user can provide.
Claude or ChatGPT usage only becomes a superpower for a business when it can read what that business knows (its pricing rules, its client history, its way of scoping a job etc.), and it cannot read what was never captured or written down. Most of that context lives in people's heads as tribal knowledge or sits in unstructured documents, and mostly none of it is available to AI systems today.
Something to call out is that this cuts both ways.
An AI with no company knowledge writes the same generic output for every business that asks it the same question.
An AI fed wrong or out-of-date knowledge is worse still, because it hands out confident, wrong answers to everyone in the business who trusts it.
This is where the least understood point of my point of view sits: having chats inside enterprise toolsets is not the same as capturing context. A Copilot or enterprise ChatGPT rollout gives the business logs and data controls, which ticks a compliance box for IT.
But a thousand transcripts sitting in an admin system is storage, not usable knowledge, because nobody can find any strategic decisions, pricing information or other intel buried in messages from months ago, especially when they aren't signposted for AI to find. Essentially, visibility of information is not the same as capturing context.
Capturing context means the useful thing a conversation produced gets pulled out, saved in a shared place, communicated to the team, and made findable by the next person and the next AI system.
Even the businesses that get the rollout right stop too early.
They move everyone onto the approved tools, tick the security boxes, and treat deployment as the finish line.
They don't know how to build a process for converting conversations into context files.
They have no governance process to decide where captured knowledge lives and who maintains it.
One of the most baffling things since returning to NZ 18 months ago is how inconsistently meeting transcription tools are used. Only now am I seeing meeting transcript tools being used slightly more regularly, but that number is still under 50% of the calls I join.
Meeting transcripts are the cheapest, richest source of context a business generates, produced automatically in every meeting and thrown away by the majority of NZ businesses.
Data exhaust and the company brain
Back to the data exhaust, because this is the foundation for solving the problem.
Every AI conversation produces explanations of how things really work, corrections ("no, we never discount past 15%", or "we never say that word in our material"), worked examples, and a finished artefact or document. Right now, in most businesses, all of it evaporates the moment the chat window closes.
The fix is about building small habits.
Every meaningful chat should end with an artefact (the corrected answer, the reusable prompt, or the documented rule) as a summary file (at a minimum),
Saved into the company brain (shared file storage),
One shared and governed house for what the business knows,
With personal information stripped out.
Run that habit for a year and every new AI interaction starts from the accumulated knowledge of the whole business.
The gap is already measurable: 96% of organisations say AI agents need company-specific context to be useful, yet only 36% have connected their AI to trusted internal content (Harris Poll of 1,600+ IT leaders for Box, 2026). The businesses closing that gap pull further ahead every month, because the value of collecting company knowledge over time is a compounding asset that others can't replicate.
None of this appears in any Shadow AI policy, because it's not a security issue.
But the prize for the business is combining the best human thinking in the business with AI, and that only works when the thinking is captured and stored somewhere the AI can read it.
Context capture is the habit of saving what conversations produce;
Context architecture is the system that organises what gets saved so people and AI can find it.
Stopping leaks protects what the business has today, and capturing context grows what it will know and can use moving forward.
What not capturing costs
The cost shows up in three recognisable scenes:
Continuity: the firm's best proposal writer runs every bid through a private AI setup built on years of client history and pricing logic. They resign, and all of it leaves the business.
Accuracy: ten service reps each teach a private chatbot the refund policy, in ten slightly different versions. One reps version of the truth is out of date and they're now delivering the wrong answer to a customer with total confidence, because no shared record exists to rectify the error, let alone fix it.
Expansion: leadership wants an agent to draft quotes automatically, but the project stalls in week two because the knowledge the agent needs was never captured anywhere an agent can find.
Drop the stick, show them the carrot
The missing piece in every Shadow AI approach to date is the carrot: nobody has told team members what they gain by bringing this work into the open. The strategy below is that carrot:
The business needs to declare amnesty and ask for show-and-tell. The people using AI in the shadows are the most motivated adopters in the building, so invite them to demonstrate their best workflow and treat it as a contribution to improving the business rather than an illicit confession.
Sell the personal benefit of contributing via approved tools. The pitch to staff is that captured context ends them having to re-explain everything to AI each time.
Install the one-artefact habit. Every meaningful AI session should end with something saved to the shared brain: a corrected answer, a reusable prompt, a documented rule, always with personal information stripped first.
Give the brain a home and an owner. One shared file storage system, one named person accountable, and a standing review rhythm. Context decays the moment the business changes, and an unmaintained brain becomes a problem in delivering the wrong-context at the right time.
The best time to start capturing context across a business was years ago. The next best time is now.
Not sure how to set this up in your business? Give me a shout, I can show you examples of how our system works and what we've built for other clients.

Passionate about all things AI, emerging tech and start-ups, Mike is the Founder of The AI Corner.
Subscribe to The AI Corner
