"Shadow AI" has become the phrase of the moment in governance circles: staff running company work through ChatGPT and its cousins, off the books, no sanction, no audit trail, no real idea what they're pasting into a consumer tool. The standard framing treats this as a policy failure, something to detect, restrict and report. I used to hold that view myself, and I held it right up until the moment it made me handle a situation badly.
A staff member at a client organisation mentioned to me, quite casually, that her whole team was running client-adjacent material through a free AI tool. My instinct, shaped by years of compliance-adjacent work, was to treat it as a red flag. I framed it upward as a risk finding, felt rather professional about it, and only later understood what I'd actually done: taken the one honest disclosure anyone was ever going to give me and taught the whole team to stop disclosing. Nobody in that organisation was going to volunteer their AI habits again, least of all to the visiting trainer. If the goal was visibility, I'd achieved the exact opposite.
What I should have seen, what I'd see now, is a demand signal. Here was a team that had already self-identified as motivated to use AI, already experimenting on real work, and receiving zero guidance on doing it safely or well. That organisation didn't have a discipline problem. It had a capability vacuum, and the staff had filled it themselves, imperfectly, because nobody got there first with training.
These days, when I run in-house sessions, I ask the question directly, off the record, no names, nothing going upstairs, who's already using AI tools at work that IT doesn't know about? Most hands go up. Every industry, every seniority level, every time. And the answers to "using it for what?" are never reckless. Drafting emails. Summarising documents. Tidying meeting notes. These are not rogue employees circumventing controls for sport. They're people who found something that helps, in an organisation that hasn't yet shown them the sanctioned, competent version of the same thing.
The reason the framing matters is that the two framings produce opposite responses. Call shadow AI a governance problem and the response is a policy memo and a blocked domain list, which, in my observation, pushes the same behaviour onto personal phones and personal accounts, where the organisation has even less visibility and the data exposure is worse. Call it a training backlog and the response is to find out what staff already do, meet them there, and replace the improvised version with a competent one: sanctioned tools, clear rules on what data goes where, and actual skill in getting good output.
Exhibit · Two framings, opposite responses
Policy failure vs. demand signal
Governance framing
Treat it as a policy failure
- Respond with a policy memo and blocked domains
- Pushes the behaviour onto personal phones and accounts
- Visibility gets worse, not better
Training-backlog framing
Treat it as a demand signal
- Find out what staff already do
- Meet them where they are
- Replace the improvised version with sanctioned tools and real skill
The one piece of sequencing I'd press on any L&D or compliance lead is this: find out what your staff are actually doing with AI before you write the policy. Anonymously, the way I do it in a classroom, not as a gotcha. A policy written in ignorance of real usage will prohibit things people depend on, permit things nobody does, and be quietly ignored within a quarter. A policy written after an honest audit at least regulates reality, rather than a compliance team's imagination of it.
Your workforce is already telling you, at considerable volume, what training they want. I ignored that signal once and called it diligence. I'd rather you didn't repeat my mistake.
If you take one thing: before you write the AI policy, ask, genuinely, anonymously, what people are already doing. The answer is your training needs analysis, delivered free.