Shadow AI is actually the symptom: here's how to treat the cause

Wait 5 sec.

New reports on real-world AI deployments seem to be being published almost daily, but there's one clear message which seems to span them all – shadow AI is a major problem.The use of unapproved or unauthorized tools by workers is a common theme regardless of business size, sector or geography, and it often stems back to one or two reasons – employers are either being too prescriptive about permitted AI tools and are giving workers a narrow window of unsuitable tools to experiment with, or they lack any clear strategy altogether.These reports have already detailed the risks in great depth, but to summarize, using consumer-grade versions of AI apps puts sensitive and confidential workplace data at risk, be it leaks or secondary exfiltration via model training. Hence why companies invest in enterprise-grade versions with additional safeguards.Shadow AI is a symptom of a bigger problemToo commonly, employers consider shadow AI a disease that plagues their workers. Something that should be stamped out with more effective training or harsher consequences to breaking the rules.But the reality is that shadow AI is more often a symptom of the boarder workplace culture, and it's the cause of this that I set out to explore when speaking with industry experts and policymakers.Canva preaches the importance of freedom of choice – the Australian software giant gives its workers full autonomy over the models they want to use, affording them the time to identify the right tools rather than being prescribed unsuitable alternatives.Policies only work when they're accessibleBeginning with insufficient and unsuitable policies, Zendesk Chief Legal Officer Shana Simmons explained to me in an exclusive interview that many of today's agreements and policies are far too formal and field-specific."AI policies often fail because they’re written for lawyers, not for the people expected to follow them," she outlined, "if people can't understand the guidance, their behavior won't change."Simmons also explained the policies are being stored behind closed doors in hard-to-reach places, like HR folders that workers never, ever check. "If a policy is buried in a handbook or on a website, it’s not going to reach employees when they need its," she said, noting that policies should actually form part of the UI – or in other words, where the workers already are.Canva warns us that, "the most common mistake is treating AI training as a curriculum," whereas it should really be seen as an ongoing back-burner activity that's always developed. The company's spokesperson insisted that workers learn through fixing their own problems, not by "sitting through a course on prompting."Unsuitable tools and taking matters into their own handsIn a bid to work out whether it's employees or employers who are at fault (or whether it's shared), I asked whether shadow AI is a reflection of worker misconduct or insufficient tooling. In response, Simmons stressed that "most people want to do the right thing," agreeing that the most common cause of shadow AI is indeed poor tooling."If employees are given the tools they need and are informed of the rules and requirements in a way that’s understandable to them, and technical controls are in place to restrict the riskiest behavior, I’d expect shadow AI to be no greater a problem than any other form of employee misconduct."The answer then isn't necessarily to approve every new AI application, but understanding why users prefer certain tools over others is key to building suitable policies and safeguards around those.In certain, low-risk conditions, shadow AI could actually be an important and useful part of feedback, showing organizations where they're falling short and exactly where to invest, but a clear oversight over this is just as important to ensure that no leaks or other threats occur.AI literacy can't be taught – it's learnedClearly, then, workers need more guidance and support. But does that come in the form of training, policies, access to tools, or something else?Simmons explained that "training alone is not very effective for developing AI fluency," though giving workers a clear direction and some initial pointers certainly serves as a helpful baseline. Zendesk, for example, has found the greatest success in giving workers time and space to experiment and become accustomed with AI on their own terms.This particular company's stance was to pause non-urgent work and organize a dedicated internal hackathon to encourage proactive exploration. The result was a marked increase in employees' practical AI skills and better cross-team collaboration, but halting non-urgent operations altogether isn't a necessity and just reflects one initiative.It's a similar initiative that's being piloted by Canva, which tells its 5,300+ workers to drop tools for a full week and experiment with AI. "We give our team the room to step back, get out of business as usual, and try something genuinely new," a spokesperson said."Practical AI training should go beyond introductory courses and prompting techniques and create space for employees to actually use the tools in a safe, secure environment," Simmons concluded. Piloting AI tools with synthetic data (and therefore, no harmful consequences) ultimately leads to the highest levels of confidence.'Employers own the conditions... employees own the curiosity'Another key area where studies and reports have been split is in whose responsibility it is to upskill and re-skill, whether that's through updated policies, passive training or active experimentation.As a C-suite exec, Simmons believes the organization should bear the brunt of the responsibility by giving workers access to tools and learning opportunities. Clearly, they must think outside the box and offer a much broader array of support: "not just training, but also ideation and experimentation through initiatives like hackathons, sandboxes, and collaboration opportunities."But beyond that, it's totally on the workers' shoulders to "take those opportunities and run with them." After all, it's not just for the benefit of their organization, but it's also to ensure they stay relevant as work evolves in an AI-first era.A secondary opinion by Canva also backs this up: "Employers own the conditions: the time, budget, permission to experiment... Employees own the curiosity."