Listen to this articleLoading audio…
The audio could not be loaded.Open the MP3 file.
Shadow AI

Organizations are failing at AI adoption in two ways at once. The first is the one you cannot see. It began without anyone deciding that it should. Before the strategy was written, before a vendor was chosen, before a policy was drafted, people across the business were already using AI to do real work on real data. This is shadow AI: employees using tools their employer has never approved, evaluated, or even inventoried.
It happens in ordinary ways. An engineer pastes proprietary code into a public chatbot to find a bug; a finance lead uploads draft quarterly numbers to get a summary before the board call; an HR manager pastes a spreadsheet of employee salaries to draft a compensation review. Code, financials, and personal data are leaving the business one prompt at a time, invisible and ungoverned.
Whether the tool keeps any of it is beside the point. Customer contracts name who is allowed to hold that data, employees were told whose hands their records would pass through, and a tool nobody disclosed is on none of those lists.
What would you do? You have the file, you have the deadline, and you have a tool in the other tab that will do in a minute what would otherwise cost you an afternoon. Nobody has told you not to. Nobody has offered you anything better. The honest answer, for most people, is that you would paste it in too.
None of these people set out to create risk. They set out to finish something. Approval is not what makes a tool useful.
The data leak is the only cost anyone can easily quantify, because it is the only one shaped like a cost: records exposed, regulator notified, an investigation someone has to answer for, a bill at the end of it. It has an owner and a number. What comes back has neither.
And nothing governs it. The suggested fix goes into the product, the summary goes into the board deck, and the organization does not know which tool produced them, what it was given, or whether it hallucinated the part that mattered. None of this costs anything until someone asks where it came from. Then there may be no record the business can reach, because the work happened somewhere it cannot see.
There is a cost nobody is likely to count: everything the organization learns this way, it learns privately. Your best analyst works out how to turn a messy vendor report into a clean risk summary. The discovery is not the wording of the prompt. It is realizing that the job can be done this way at all. The work sits in one person’s chat history and may never make it any further. If that analyst leaves, the work goes with them. Nobody else gets to build on it, and the analyst two floors up may carry on solving the same problem from scratch, without ever knowing someone else already found a way to do it.
The obvious answer is a policy. It can tell people what they should do. It does not, by itself, give them a better way to do the work. A rule that asks someone to be slower competes against the pressure they are already under, and it often loses. What prohibition removes is not the tool. It is your view of it.
As a result, the organization carries the full risk of AI adoption and captures almost none of the compounding benefit: maximum exposure, minimum leverage.
Shallow AI
The second failure happens in full view. These are the AI tools the organization did approve.
Each purchase made sense on its own. They were bought over the years for different teams: one for support, another for engineering, and a third for the account team. That is what procurement is good at buying: a tool with a defined budget aimed at solving a specific problem. Each solves the problem it was purchased to solve, and nothing beyond it. This is shallow AI: tools that improve a single function without ever becoming part of a process.
The problem appears at the boundaries between those functions. The work may move from one team to another, but the intelligence does not move with it. Each tool sees its own piece of the process, while the organization has to carry the rest by hand.
For example, a customer writes in with a problem. Support investigates the issue with one tool and opens a ticket for engineering. Whatever support learned that does not make it into the ticket is effectively lost to the rest of the organization.
Engineering picks up the ticket in a second tool, working from the summary support left behind. It has enough to continue, but not the full context of what support already discovered. The work moves forward, but the knowledge does not. Engineering may have to retrace steps, and useful context is lost between the teams.
The fix ships and the ticket closes. But the account team has a third tool. It sees the ticket open, then eventually sees it closed. It does not see what happened in between: what support discovered, what engineering investigated, what was tried, or whether the work was making progress or getting stuck. From the account team’s perspective, the system shows only two events: opened and closed. To understand the actual state of the work, they have to ask the teams directly.
Each tool optimizes its own step, but none owns the handoff. The organization has three intelligent systems, but no shared understanding of the process connecting them, losing the ability to reason about the process as a whole or answer the bigger question: what is actually happening across the customer journey?
The result is more than lost context. Work gets repeated. Engineering may redo an investigation that support has already performed. Account teams may chase information that already exists somewhere else. Humans become the integration layer, carrying context from one system to another, summarizing decisions, chasing status, and reconciling what each tool knows.
That is the real cost of shallow AI. Individual functions get smarter while the organization does not. And it is not something you can simply buy your way out of. Every enterprise runs these processes differently: its own escalation paths, thresholds, exceptions, and unwritten rules. A cross-functional process is specific to the business it runs in. Vendors can sell tools that solve common problems across many companies; they cannot sell the exact intelligence that connects your particular process end to end.
As a result, the organization pays for AI in every function and builds it in none: maximum coverage, minimum depth.
Shadow AI and Shallow AI are the same failure at two scales. In the first, what the organization learns is stuck in a person using a tool it never approved and cannot see. In the second, it is stuck in a function it can see perfectly well and still cannot reach. Either way it never accumulates.
And the two obvious answers are already gone. A rule does not work, because prohibition costs you the visibility you need. A purchase does not work, because nobody sells your process. What is left is the subject of Part II.
