Skip to main content
Back to insights

Shadow AI: Build an Inventory Before You Write a Ban

An AI inventory gives organisations visibility into tools, data and decisions. It is a stronger starting point than a policy teams quietly work around.

  • AI and automation
  • Data engineering
  • Engineering leadership

Arinao Tshamano10 September 20261 min read

Employees adopt useful tools faster than governance processes can classify them. The result is shadow AI: real work moving through systems the organisation does not fully see.

A ban may reduce visible use while pushing valuable experimentation into personal accounts and unreviewed workflows. The deeper problem is not curiosity. It is the absence of safe, practical paths for common tasks.

What good engineering looks like

Create a lightweight inventory that records the tool, owner, purpose, data classes, vendor terms, integrations and decision impact. Use it to distinguish low-risk assistance from use cases that need security, privacy, legal or architecture review.

  • Make disclosure simple and non-punitive.

  • Classify data before classifying the tool.

  • Provide approved options for common low-risk work.

  • Escalate use cases that affect people, money, access or legal rights.

  • Review the inventory as vendors and features change.

A practical starting point

  1. Survey teams about actual AI-assisted tasks.

  2. Group uses by data sensitivity and consequence.

  3. Close the most obvious approved-tool gap.

  4. Publish a short route for requesting a review.

The decision to make

Visibility creates the basis for proportionate control. Without it, both permission and prohibition rely on assumptions.

Apply the thinking

Working through a related technology decision?

Share the operational context, current systems, constraints, and decision you need to make.

Discuss a requirement