Silicon Valleys Journal
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
Silicon Valleys Journal
No Result
View All Result
Home Technology & Industry AI

Shadow AI is a distraction from the real visibility problem

By Michael Covington, VP of Strategy at Jamf

SVJ Thought Leader by SVJ Thought Leader
September 14, 2026
in AI, C-Suite Perspective, Cybersecurity, Enterprise Tech, Innovation Spotlight, Leadership & Perspective, Policy & Regulation, Technology & Industry
0
Shadow AI is a distraction from the real visibility problem

Shadow AI is fast becoming a favourite scapegoat of enterprise security. It gets wheeled out to explain everything from a marketing assistant testing a new writing tool to a developer running an unauthorised coding agent.

However, using the same catchall phrase for everything means it’s easy to start treating these issues as though they carry the same weight, which is a dangerous trap when some unauthorised AI is far more impactful than others.

The real issue isn’t that employees are using AI tools IT didn’t approve, it’s that most IT teams have no reliable way to see what’s actually running across their fleet, sanctioned or not. Without that visibility, every tool looks equally suspicious or equally benign, whether merely speeding up mundane tasks or risking a critical data leak. And the inability to quantify the problem makes it impossible for leaders to understand the scale so they can action change.

This isn’t just an internal operations problem anymore. The EU AI Act’s transparency and disclosure obligations came into force on 2nd August 2026, and enforcement is already active, carrying fines of up to €15 million or 3% of global annual turnover. An organisation that doesn’t know what AI is running across its fleet can’t disclose it, let alone govern it.

Why the blind spots keep growing

Shadow AI has become so ubiquitous because the usage of AI started outstripping the ability to track and manage its impact almost immediately. Our own research found that nearly three-quarters (72.9%) of organisations have already deployed AI in some form, yet 81.7% consider themselves exposed to AI-related risk.

Network and cloud monitoring tools haven’t kept up with this change – they can tell you that traffic moved but not always what actually caused it. A spike in outbound calls might be a sanctioned productivity tool doing exactly what it’s supposed to, or it might be something nobody signed off. From the network alone, the two often look identical. And this scenario becomes even more challenging as more AI processing shifts to local compute.

Often, the tools with the biggest blind spots around AI activity aren’t the ones showing up on anyone’s radar. Command-line tools, IDE extensions, browser add-ons, and packages pulled straight from code repositories rarely register on conventional monitoring.

Keeping a handle on AI might seem like an issue relegated to enterprises still finding their footing, but we’ve found that incident rates actually rise as AI adoption matures. Around 19% of organisations suffered an incident while still exploring AI, up to 27.1% among those with it deeply embedded in daily workflows. Those critical visibility gaps only widen as adoption grows.

Blocking treats the symptom, not the cause

Faced with that kind of blind spot, hitting the block button seems like the most direct solution. Lock down the sanctioned stack, restrict everything else, and call the risk contained.

However, we discovered that IT teams find blocking the obvious AI websites is the easy part, but it can quickly turn into a game of whack-a-mole. Close one route and employees simply find another, whether that means a personal account on a personal device or a workaround that nobody in IT will ever see.

It’s not a case of defiance, but that the tool solved a problem faster than waiting for approval did. Most IT teams are left choosing between two bad options. Clamping down too hard means productivity suffers but ease off and the door opens to even more exposure.

There’s a third option that will actually strike the right balance: informed governance. Unfortunately, it’s not on the table without the right capabilities.

How to gain the full picture on AI use

It’s important to remember that governing AI is a different function to securing it. Governance sits above security, not in competition with it. Its job isn’t to detect threats, but to confirm that an organisation’s own policy exists, is being followed, and actually holds at scale as new tools arrive every week.

That starts with visibility that goes beyond the network edge. Knowing which cloud services are being accessed is useful, but it stops short of knowing which tools are installed, what they can reach, and how they behave once they’re running.

Closing that gap means building governance into deployment itself, setting access and data-handling policy for a tool before it reaches the fleet, rather than retrofitting rules once it’s already in daily use.

Gartner’s guidance for 2026 supports this, urging security leaders to account for AI agents whether or not they were ever formally approved, and to have a response plan ready for both categories.

Governance and enablement aren’t opposing goals either. Our research found that organisations are already pursuing automation, productivity deployment, and governance at similar levels, not sequentially.

Focus on removing blind spots, not tools

Shadow AI was never really the core problem. It’s become a label that let organisations avoid asking the harder question, which is whether they actually know what’s running across their own fleet. Most don’t, and no amount of blocking changes that.

The starting point is straightforward: audit what’s actually installed and in use, then build access policy around real behaviour rather than assumptions about what employees might be doing.

Gartner estimates that spending on AI governance is projected to reach $492 million in 2026 and surpass $1 billion by 2030. Getting this right is now standard practice, rather than a niche concern for a handful of the most cautious or heavily regulated industries.

With the EU AI Act’s transparency obligations now in force, organisations that can’t say what AI is running across their fleet may already be falling short of a regulatory requirement, not just a best practice. The more demanding obligations still to come, covering high-risk AI use in areas like employment and critical infrastructure, will only raise that bar further over the next two years.

Previous Post

Attribution Wasn’t Built for Businesses That Close Offline

Next Post

Why AI Is Breaking the SaaS Pricing Model

SVJ Thought Leader

SVJ Thought Leader

Next Post
Why AI Is Breaking the SaaS Pricing Model

Why AI Is Breaking the SaaS Pricing Model

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

December 27, 2025
The AI Cold War and How to Prepare for It

The AI Cold War and How to Prepare for It

May 1, 2026
AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

November 24, 2025
The UK’s Seed-to-Series A gap is growing. Should we fix it?

The UK’s Seed-to-Series A gap is growing. Should we fix it?

November 25, 2025
The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

1

50 Key Stats on Finance Startups in 2025: Funding, Valuation Multiples, Naming Trends & Domain Patterns

0
CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

0
Clarity Is the New Cyber Superpower

Clarity Is the New Cyber Superpower

0
When the Market Grows Slower and the Revenue Gets Better: Reading Mix Shift in Technology Forecasts

When the Market Grows Slower and the Revenue Gets Better: Reading Mix Shift in Technology Forecasts

September 14, 2026
Stablecoins, fraud and the next compliance challenge for financial institutions

Stablecoins, fraud and the next compliance challenge for financial institutions

September 14, 2026
Why AI Is Breaking the SaaS Pricing Model

Why AI Is Breaking the SaaS Pricing Model

September 14, 2026
Shadow AI is a distraction from the real visibility problem

Shadow AI is a distraction from the real visibility problem

September 14, 2026

Recent News

When the Market Grows Slower and the Revenue Gets Better: Reading Mix Shift in Technology Forecasts

When the Market Grows Slower and the Revenue Gets Better: Reading Mix Shift in Technology Forecasts

September 14, 2026
Stablecoins, fraud and the next compliance challenge for financial institutions

Stablecoins, fraud and the next compliance challenge for financial institutions

September 14, 2026
Why AI Is Breaking the SaaS Pricing Model

Why AI Is Breaking the SaaS Pricing Model

September 14, 2026
Shadow AI is a distraction from the real visibility problem

Shadow AI is a distraction from the real visibility problem

September 14, 2026

About & Contact

  • About Us
  • Branding Style Guide
  • Contact Us
  • Help Centre
  • Media Kit
  • Site Map

Explore Content

  • Events
  • Newsletter
  • Press Releases
  • Reports & Guides
  • Topics

Legal & Privacy

  • Advertiser & Partner Policy
  • Communications & Newsletter Policy
  • Contributor Agreement
  • Copyright Policy
  • Privacy Policy
  • Prohibited Content Policy
  • Terms of Service

Tiny Media Brands

  • Silicon Valleys Journal
  • The AI Journal
  • The City Banker
  • The Wall Street Banker
  • World Lifestyler
  • About
  • Privacy & Policy
  • Contact

© 2025 Silicon Valleys Journal.

No Result
View All Result

© 2025 Silicon Valleys Journal.