
Do not punish it. Shadow AI exists because your employees are afraid of you. They are using AI to do their work better and faster, and they are hiding it because they believe they will get in trouble if anyone finds out. That is not a security problem first. It is a culture problem, and the fix is a clear policy, a paid subscription and a leadership group that stops being the enemy.
Why shadow AI exists
Employees do not hide tools that make them look good in a company that celebrates them. They hide tools in companies where the culture does not visibly support AI, where nobody has said out loud that using it is allowed, and where leadership might treat it as cheating. Your best people have already transformed how they work, in silence. The silence is the part you created.
The fix: pay for it, openly
Put three things in place. A clear, open policy that says employees are allowed to use AI. A budget that pays for their subscriptions, the 20, 100 or 200 dollar plan, on company-approved accounts. And a culture that visibly supports it from the top.
The subscription is the masterstroke, and the psychology is simple: employees love it when the company pays. It is the same pleasure as flying on the company’s ticket. A large share of your shadow users, currently paying out of their own pockets, will happily surface the moment you offer to cover the plan they are already on. And go one step further than permission: put a reward policy in place. Tell your people you are looking for great ideas, for uses of AI nobody in leadership has thought of, for everything the company could do better. Now the behaviour you were about to punish becomes the behaviour you are actively harvesting.
Why you will never fully eliminate it
Be honest with yourself about the ceiling. I have seen employees keep a personal subscription and use it on their corporate PC while connected through their own mobile phone’s data plan, precisely so that nothing ever touches the company network. Some companies respond with proxies and blocked URLs, and lose anyway, because every employee carries a private, unblockable connection in their pocket. You will reduce shadow AI significantly with policy, payment and culture. You will not get it to zero, and chasing zero through surveillance costs you the exact trust you are trying to build.
Governance is teaching, not blocking
Reduction alone is not the goal. Quality is. Clients have started complaining about work that is obviously AI-written, and that is where real governance begins: an internal team that trains people, provides examples and teaches the difference between using AI in client work and sounding like AI in client work. It is allowed, and there are ways it should be done. This is not optional culture-building either: the EU AI Act’s duty to prepare your employees for AI is already in force, so the company that governs by teaching is also the company that is compliant.
Start with the apology, not the anger
When you discover shadow AI, do not start by being angry at your people. Start by saying the true thing: we did not have the policies and governance in place, and that is on me as the leader. The limitation was never the employees. Then plan, put the structure in place, and grow from there. Your employees save money and work in the open. You gain visibility, control and a map of your most creative AI talent. And your clients get better work, which is the point of all of it.
Frequently asked questions
What is shadow AI?
Shadow AI is employees using AI tools for their work without the company’s knowledge or approval, typically on personal subscriptions and private accounts. It emerges when people believe they will get in trouble for using AI, so they hide the productivity gains instead of sharing them.
Should I ban employees from using ChatGPT or Claude?
No. Bans and URL blocking fail in practice, because employees route around them, including using personal subscriptions over their own mobile data so nothing touches the company network. The effective response is an open policy, company-paid subscriptions on approved accounts, and training in how to use AI well.
How do I get employees to admit they are using AI?
Remove the fear and add a reward. Announce that AI use is allowed, offer to pay for their subscription plans, and ask openly for their best AI ideas and discoveries. Most hidden users surface quickly when the company covers the plan they were paying for themselves.
Does shadow AI create legal risk under the EU AI Act?
Unmanaged AI use sits outside your governance, and the EU AI Act’s obligation to ensure employees are prepared for AI is already in force. Bringing shadow use into an open, trained, company-approved structure is both the cultural fix and the compliance fix.
Thomas Anglero is a Strategic AI Advisor, keynote speaker and author of Intro to Artificial Intelligence. He has delivered over 450 keynotes across 30 countries for organisations including IBM, the WHO, the World Government Summit and the European Commission. He founded the IBM Watson AI Lab for Cancer at the Oslo Cancer Cluster and closed over $500 million in enterprise transformation deals as CTO and Chief Innovation Officer at Cognizant.
If you are leading your organisation through this, I work with a limited number of senior leaders each quarter. Get in touch at Anglero.com.