Shadow AI - the unsanctioned use of artificial intelligence tools by employees without organisational policy, oversight, or formal approval - has become one of the defining governance failures in enterprise technology today.
As Vercel’s recent breach makes clear, the consequences reach well beyond an IT department's inbox. Customer data, intellectual property, and hard-won regulatory standing are all in play. And with EU AI Act enforcement arriving in August 2026, the window to get ahead of this risk is closing faster than most boards realise.
What Is Shadow AI, and How Did It Become an Enterprise Problem?
The term will be familiar to anyone who spent the 2010s arguing with employees about personal Dropbox accounts and WhatsApp groups. Shadow IT - the use of unsanctioned software to fill gaps left by corporate tooling - costs organisations millions in data exposure and regulatory fines before boards eventually catch up. The pattern is repeating. The difference this time is scale, speed, and sensitivity.
AI tools are more capable, more personally compelling, and more deeply embedded in daily workflows than a shared spreadsheet ever was. The data employees feed into them - customer transcripts, product roadmaps, deal intelligence, HR records - is often far more valuable and legally protected than anything that passed through a rogue Dropbox folder.
We sat down with Gary Hibberd, Head of Consultants Like Us, to get his perspective:
"We are trying to implement AI on top of data chaos. A lot of organisations don't really understand their current platforms."
Before shadow AI can be governed, many organisations first need a clearer picture of what data they hold - and where it already lives.
Does the Board Understand the Risk Shadow AI Poses?
In a word: no. And Hibberd does not soften the assessment.
"For most people, AI has only been around since 2022," he says. The mental model most boards are working from is that of a conversational search tool. The reality - AI embedded in CRM platforms, customer service workflows, contact center infrastructure, and employee productivity suites - is categorically different, and the risk exposure that comes with it is orders of magnitude larger.
"One of the biggest risks the board is facing is shadow AI," Hibberd says. "People are using it in the workspace without any real guardrails - policies, procedures, training, explaining to people about not putting confidential data into AI. That could be personal data, but it could also be the intellectual property of the company."
A recent EY survey found that 99% of organisations surveyed had experienced financial losses from AI-related risks, with compliance failures, flawed outputs, and data exposure among the most common causes. Estimated combined losses across surveyed firms reached $4.4 billion.
Is Shadow AI a Security Failure - or a Leadership One?
This is the reframe most organisations are still missing. Shadow AI is not, at its root, a discipline problem. It is a clarity problem - and that makes it a leadership responsibility.
"AI offers lots of opportunities to get quicker and better at what we do," Hibberd says. "So people are using it indiscriminately in their organisations without any real forethought about what they're using it for." Employees are not acting recklessly; they are responding rationally to capable tools, competitive pressure, and an organisational vacuum where policy should be.
Hibberd describes this as “adoption without clarity.” Organisations have not defined what AI is actually for - so individuals do it themselves. Without those answers at the leadership level, individuals fill the vacuum themselves - and the results increasingly land in boardroom risk registers and regulatory investigations.
"None of it's technical," Hibberd says of the governance conversation. "It's business. Security is not an IT risk; it's a business risk."
How Should Organisations Respond to Shadow AI?
The instinct is to reach for tools - an AI governance platform, a usage monitoring solution, a vendor agreement. Hibberd's prescription is to start with the fundamentals:




