The first time someone told me about shadow AI, I reported it. I wouldn't now.

Save as PDF: File → Print → Save as PDF  |  ← Back to the article

PRAXORALAB
Capacity Building

Insight Report · Praxora Lab

The first time someone told me about shadow AI, I reported it. I wouldn't now.

Why treating unsanctioned staff AI use as a discipline problem teaches people to stop disclosing it, and what changes when it's read instead as a training needs analysis delivered for free.

Dr. Joshua Lau

Dr. Joshua Lau

AI Transformation Leader and Accredited Adult Educator · Praxora Lab

"Shadow AI" has become the phrase of the moment in governance circles: staff running company work through ChatGPT and its cousins, off the books, no sanction, no audit trail, no real idea what they're pasting into a consumer tool. The standard framing treats this as a policy failure, something to detect, restrict and report. I used to hold that view myself, and I held it right up until the moment it made me handle a situation badly.

A staff member at a client organisation mentioned to me, quite casually, that her whole team was running client-adjacent material through a free AI tool. My instinct, shaped by years of compliance-adjacent work, was to treat it as a red flag. I framed it upward as a risk finding, felt rather professional about it, and only later understood what I'd actually done: taken the one honest disclosure anyone was ever going to give me and taught the whole team to stop disclosing. Nobody in that organisation was going to volunteer their AI habits again, least of all to the visiting trainer. If the goal was visibility, I'd achieved the exact opposite.

What I should have seen, what I'd see now, is a demand signal. Here was a team that had already self-identified as motivated to use AI, already experimenting on real work, and receiving zero guidance on doing it safely or well. That organisation didn't have a discipline problem. It had a capability vacuum, and the staff had filled it themselves, imperfectly, because nobody got there first with training.

These days, when I run in-house sessions, I ask the question directly, off the record, no names, nothing going upstairs, who's already using AI tools at work that IT doesn't know about? Most hands go up. Every industry, every seniority level, every time. And the answers to "using it for what?" are never reckless. Drafting emails. Summarising documents. Tidying meeting notes. These are not rogue employees circumventing controls for sport. They're people who found something that helps, in an organisation that hasn't yet shown them the sanctioned, competent version of the same thing.

The reason the framing matters is that the two framings produce opposite responses. Call shadow AI a governance problem and the response is a policy memo and a blocked domain list, which, in my observation, pushes the same behaviour onto personal phones and personal accounts, where the organisation has even less visibility and the data exposure is worse. Call it a training backlog and the response is to find out what staff already do, meet them there, and replace the improvised version with a competent one: sanctioned tools, clear rules on what data goes where, and actual skill in getting good output.

Exhibit · Two framings, opposite responses

Policy failure vs. demand signal

Governance framing

Treat it as a policy failure

  • Respond with a policy memo and blocked domains
  • Pushes the behaviour onto personal phones and accounts
  • Visibility gets worse, not better

Training-backlog framing

Treat it as a demand signal

  • Find out what staff already do
  • Meet them where they are
  • Replace the improvised version with sanctioned tools and real skill

The one piece of sequencing I'd press on any L&D or compliance lead is this: find out what your staff are actually doing with AI before you write the policy. Anonymously, the way I do it in a classroom, not as a gotcha. A policy written in ignorance of real usage will prohibit things people depend on, permit things nobody does, and be quietly ignored within a quarter. A policy written after an honest audit at least regulates reality, rather than a compliance team's imagination of it.

Your workforce is already telling you, at considerable volume, what training they want. I ignored that signal once and called it diligence. I'd rather you didn't repeat my mistake.

If you take one thing: before you write the AI policy, ask, genuinely, anonymously, what people are already doing. The answer is your training needs analysis, delivered free.

About The Author
Dr. Joshua Lau

Dr. Joshua Lau

AI Transformation Leader and Accredited Adult Educator

Managing Director leading AI transformation at a Malaysian manufacturer, and a WSQ and HRDC accredited trainer who has delivered generative AI and agentic AI training to more than 1,000 learners across Singapore and Malaysia.

Want this applied to your organisation?

Praxora Lab runs the AI Governance & ROI Executive Programme and the AI Masterclass, turning frameworks like this one into a deployment roadmap.

Explore workshops →

© 2026 Praxora Lab. Author: Dr. Joshua Lau. Read online at praxoralab.com/insights/shadow-ai-training-backlog