The tool nobody approved and everybody uses
August 22, 2026
Nearly four in five people who use AI at work bring their own. Read as a discipline problem, that produces a policy nobody follows. Read as evidence, it is the most precise account you will ever get, free, of which work your organization has made intolerable.
Six in the evening, and a contract to summarise
An analyst has a forty-page client contract and a note asking for the key obligations by morning. The approved route is to read it. The route she takes is to paste it into the assistant she pays for herself, get a summary in ninety seconds, check it against the clauses that matter, and go home.
She is not reckless and she is not lazy. She verified the output, which is more than some do. She used a tool that genuinely works. She also just sent a client's contract to a third party under terms nobody in the organization has read, created a summary that will enter a decision with no record of how it was produced, and left no trace that any of this happened.
This is half of the elephant we call Shadow: duct tape on legacy technology, plus ungoverned AI use and the debt it accrues. The duct-tape half is the older story. This half is the one moving fastest.
The evidence
Not a fringe behaviour. The default one.
78%
of the people using AI at work bring their own tools, outside any governance
Microsoft and LinkedIn, Work Trend Index 2024 (n=31,000 across 31 markets).
Is 78% a governance failure?
It is usually read that way, and reading it that way is what makes it unfixable. Note first what the figure actually says: among people already using AI at work, roughly four in five are supplying it themselves. That is not a minority circumventing a control. It is the mainstream route, and the sanctioned one is the exception.
A number that size stops being a story about individual conduct. When almost everyone independently reaches the same conclusion, the conclusion is about the environment, not about them. What they have concluded is that some part of their work is worse than it needs to be and that nobody was going to fix it on their timescale.
Which makes this the cheapest research an organization will ever be handed. Every unsanctioned tool in use is a person telling you, at their own expense and with their own time, precisely which task they find intolerable. Most companies pay consultants for a worse version of that list.
What is actually at risk?
Worth being precise here, because vague alarm is what produces the policy nobody follows. The risk is not that people use AI, and pretending otherwise costs you the credibility to be listened to on the parts that matter.
Three things are genuinely exposed. Data leaves under terms nobody assessed, not necessarily bad terms, but unknown ones, which for a client contract or personal information is its own problem. Outputs enter decisions without provenance: six months later nobody can say which parts of an analysis were machine-drafted, so nobody can tell what to re-check when a model turns out to have been wrong. And a dependency forms on a tool the organization does not hold: the subscription is personal, and it leaves with the person, along with the prompts and the working method.
The through-line is invisibility rather than danger. You cannot review what you do not know happened. Every one of those risks would be manageable if the work were visible. None of them is manageable while it is not.
Isn't this just the spreadsheet again?
Yes. And noticing that is the most useful thing in this article. The spreadsheet that quietly became production infrastructure in 2015 exists for exactly the reason the chatbot does now: work needed doing, the sanctioned path did not reach, and somebody competent built a bridge out of whatever was to hand.
That is why Shadow is one elephant and not two. Duct tape on legacy technology and ungoverned AI are the same behaviour in different materials, produced by the same gap between what work requires and what was provided. The organization that has a spreadsheet holding two systems together already knows how this ends, because it has watched the bridge become load-bearing before.
The difference is speed and reach. A spreadsheet spreads at the pace of email attachments. An assistant is adopted by a whole department in a fortnight without anybody announcing it, and the material it carries out of the building is not a copy of a report but the contract itself.
How do you know the Shadow is in your room?
It is invisible by construction. Nobody files a ticket. Look for the shape of the absence.
- Output quality or volume improves in a way nobody can quite account for.
- People describe what they produced but not how, and the vagueness is polite rather than evasive.
- A personal software subscription appears on an expense claim, once.
- Your own AI policy has a completion rate but no usage data behind it.
- The sanctioned tool exists, and the honest answer to why people avoid it is that it is slower.
Why doesn't banning it work?
Because a ban does not remove the behaviour, it relocates it. The work still has to be done tonight, the assistant still works, and the phone in someone's pocket is outside every control you own. What changes is not whether the contract gets pasted somewhere. It is whether it happens on a device you can see.
So enforcement tends to leave the residual risk almost exactly where it was while destroying the only useful thing about the situation: the visibility, and with it the demand signal. Afterwards you have a policy with a high acknowledgement rate, no usage data, and a workforce that has learned not to mention how anything was made.
The intervention that works runs the other way: make the sanctioned path better than the shadow one for the specific tasks people are already using it for. That is a much narrower and more achievable brief than governing AI in general, and you already know what the tasks are, because they told you.
How do you get the Shadow out of the room?
The same three moves we bring to any elephant, pointed at this one.
Map
Ask, with an amnesty and mean it. What are you using, for which task, and what did it save you? You will get an honest answer exactly once, and only if nothing happens to the first people who answer. The output is a ranked list of the work your organization has made intolerable. That is the same list a strategy exercise would have cost you a quarter to produce.
Prove
Take the top task and sanction it properly: an approved tool, terms someone has actually read, and a record of what was machine-assisted. Then check the only measure that matters: whether the shadow version stops being used. If it does not, the sanctioned path is still worse, and that is the finding.
Scale
Extend by task, not by policy. Every workflow you bring into the light removes a category of risk permanently, and leaves the governance document describing something that is actually happening. A rule people route around is not governance. It is a record of what you wished were true.
Find out what your organization is already using
The Elephant Safari names your herd in ten questions and ranks them by what they cost you. Or start from the business problem instead: the duct tape holding legacy technology together. Get the Shadow out of the room. Make the sanctioned path the better one.
Every figure in this article traces to a primary source. See it in Knowledge