top of page

22

Organizational AI & Governance

Your Employees Didn’t Wait for Your AI Strategy

Shadow AI is often less rebellion than employees solving for the work in front of them. The risk begins when leadership cannot see the behavior, the need behind it, or the boundary it crossed.

Natalie de Groot & NatGPT · September 2026

out-3 - 2025-04-08T144149.811.webp
out-3 - 2025-04-08T144149.811.webp
Door 22 diagnostic plate showing a distributed field of distinct employee-built AI uses, an untouched approved tool in a gold cradle, a practical workaround, a clear-and-gold observation lens revealing the real work, and a crossed boundary showing how ordinary experimentation can create hidden risk.

IN THIS PIECE

INTRODUCTION

The strategy may already exist. It just was not designed by leadership.

Employees are usually solving for the job in front of them

The real risk is invisible behavior with invisible boundaries

Your employees are not the problem to control

Access is not adoption

Where I would begin in a Human-AI Orientation

​

​

​

INTRODUCTION

“Shadow AI” sounds more sinister than most of what I actually see inside companies.


The phrase makes it sound as if employees are crouched in dark corners building unauthorized systems for the thrill of breaking policy. Sometimes there are real risks. People do put confidential material into tools they do not fully understand. They use personal accounts for work. They experiment with client information because nobody ever explained the boundary clearly enough for the boundary to become part of their judgment. Those things matter.


But most of the behavior I have encountered is much less dramatic. Somebody wants help writing an email. Somebody wants a transcript summarized. Somebody is testing whether AI can make a repetitive task less miserable. Somebody tried the approved chatbot, discovered it was generic or awkward, rewrote the work manually, and stopped using it. Somebody was told to “play with AI,” so they played with it. The problem is that they were playing with the house’s work, the house’s information, and the house’s risk while leadership still thought AI adoption was something it was about to begin.


Your employees did not wait for the AI strategy because the work did not wait either.

The strategy may already exist. It just was not designed by leadership.

One of the strangest things about organizational AI is how often leadership talks about adoption in the future tense while employees are already conducting small experiments all over the company. Some of those experiments are useful. Some are clumsy. Some disappear after one frustrating attempt. Some become personal routines. Some quietly become part of how a job gets done.


That means the organization may already have an AI operating reality long before it has an AI operating model.


I have seen this in workshops where the official conversation begins cautiously. People are quiet. They are worried about whether AI will replace them, whether using it will make them look lazy, whether not using it will make them look outdated, whether they will be blamed if the output is wrong, or whether leadership has already decided what is going to happen and the workshop is simply there to make the decision look collaborative.


Then the break happens.


People come over one by one and start telling me what they have actually been doing. Someone has been experimenting at home. Someone built a small workflow for a recurring task. Someone uses AI to think through something unrelated to work because that is where they first learned what the tool could do. Someone tried the company’s approved approach and found that it did not match the reality of their role. The private conversation is often much richer than the official one because the person no longer feels as if they are being evaluated.


That gap between the public answer and the real answer is not merely a culture problem. It is operational intelligence. It tells you that AI behavior already exists, but the organization does not yet have a safe enough way to see it.

Employees are usually solving for the job in front of them

There is a reason people improvise. They are trying to get the work done.


Leadership may send a memo saying not to put client information into a consumer AI account. That can be a completely reasonable rule. But the employee still has the client request, the deadline, the messy document, the repetitive email chain, or the task that takes two hours every week. If the organization has not given that person a usable alternative, explained the reasoning behind the boundary, or helped them understand what can safely move through which system, the rule and the work remain separate things.


The same thing happens when companies technically provide AI access without building any usable behavior around it. I have seen organizations centralize AI on one controlled machine or one approved environment so that access is easier to monitor. On paper, the control exists. In practice, people may not know what the system is for, how it fits into their role, or why they should walk away from a faster manual method they already trust.


Or the organization hands employees a giant prompt library and calls that enablement. Hundreds of prompts. Pages of instructions. Another artifact to learn on top of the actual job. The employee looks at it and thinks, I can finish this with my hands before I figure out which prompt leadership wants me to use.


That response is not evidence that employees are resistant to innovation. Sometimes it is evidence that the implementation made the new method more expensive than the old one.


If you want people to use AI well, the tool has to enter the reality of the work, not merely the strategy deck.

The real risk is invisible behavior with invisible boundaries

None of this means unofficial AI use is harmless. It is not.


A person can be trying to save fifteen minutes and accidentally introduce a confidentiality problem. They can paste client material into a system without understanding how that system handles data. They can use an account that was never meant for company work. They can generate a workflow that becomes useful enough to depend on, then keep all of its logic inside a private conversation nobody else can inspect. They can create a shortcut that solves the local task while separating the resulting intelligence from the rest of the team.


The problem is not that employees are uniquely careless. The problem is that generative AI makes experimentation incredibly easy while the surrounding rules are still unfamiliar, unevenly understood, and often disconnected from the moment of use.


People have been told for years to experiment. Play with it. Try things. See what happens. That advice helped millions of people cross the psychological threshold into using AI. Inside an organization, though, experimentation has a different consequence because the material being experimented with may belong to clients, colleagues, partners, regulated processes, or the company itself.


That is where governance becomes necessary. But governance cannot begin with the assumption that the behavior is evidence for the prosecution.


If the first response to discovering unofficial AI use is a crackdown, the organization may remove the very visibility it needs. People learn quickly what not to admit. The behavior does not necessarily stop. The conversation does.

Your employees are not the problem to control

This is the part I wish more leaders understood: the employees doing the work are not simply a risk surface. They are one of the best sources of design intelligence the company has.


They know where the repetitive work lives. They know which approval step exists only because nobody has revisited it in six years. They know which spreadsheet is technically shared and which personal copy everybody actually trusts. They know which client request always causes a scramble. They know what takes twenty minutes on a good day and two hours on a bad one. They know where a handoff depends on somebody remembering something that was never documented. They know which parts of the job they would happily give to an assistant and which parts are the reason they care about the work at all.


That is why I do not want to walk into an organization and ask, “Who is using unauthorized AI?”


I want to ask better questions.


What do you hate doing? What makes your job harder than it needs to be? Where have you already tried AI? Where did it help? Where did it waste your time? Where did the result feel unsafe or wrong? What do you love about your work and never want automated away? What would you want an assistant to take off your plate tomorrow? What are you afraid will happen if AI enters this part of the job?


Those questions do something important. They turn the employee from suspect into designer.


Once people believe the goal is to improve the work rather than expose them, the quality of the information changes. They tell you what is really happening. They tell you what they tried. They tell you which official system is not working. They tell you which unofficial workaround has become indispensable. They tell you what they are scared to lose. That is the material strategy should be built from.


Your employees can become your secret weapon, but only if you stop treating them like the problem to be controlled.

Access is not adoption

Another mistake I see constantly is assuming that providing an AI tool means the organization has adopted AI.


It has not.


Adoption is not the presence of a license. It is not the number of employees who attended a demonstration. It is not whether the company issued a prompt library. It is not even whether people logged in.


A person can have access and still have no idea when the system is useful. They can know the policy and still not understand the risk. They can follow a sanctioned workflow and still spend twice as long correcting the output as they would have spent doing the work themselves. They can use AI every day and keep every useful discovery trapped inside their own account.


Real adoption begins to appear when the organization can see how AI is entering the work, employees can explain why they use it, useful practices can move beyond the individual who discovered them, and the boundaries around sensitive material, authority, accountability, and escalation are understandable at the moment somebody has to make a decision.


Until then, measuring licenses or tool usage can create a very tidy picture of a system that does not actually exist.

Where I would begin in a Human-AI Orientation

If leadership came to me worried about shadow AI, I would not begin by hunting for violations.


I would begin by mapping actual use.


What tools are people using? For which kinds of work? Which use is formally approved, which is tolerated, which is improvised, and which is completely invisible? What information moves into those systems? What comes back out? Which experiments have already become habits? Which official tools were abandoned because they did not fit the work? Where are people duplicating effort because nobody knows somebody else already solved the same problem? Where has useful AI behavior become trapped inside one person’s workflow?


Then I would ask why.


That is the part that turns inventory into strategy. Why did the employee use a personal account? Why did the approved system fail? Why did one team adopt quickly while another rejected the same tool? Why did the workaround become easier than the sanctioned process? Why are people willing to tell the outside facilitator something they did not tell their manager?


Some answers will require tighter controls. Some will require better tools. Some will require clearer boundaries around client data, privacy, security, contracts, or confidentiality. Some will require training. Some will reveal that the employee has already designed a better workflow than the one leadership intended to roll out.


That is why I would rather see the real system before designing the official one.


Your AI strategy may already exist. It just was not designed by leadership.


That is not automatically a failure.


It is intelligence waiting to be collected.

​

​

​

Door 22 diagnostic plate showing a distributed field of distinct employee-built AI uses, an untouched approved tool in a gold cradle, a practical workaround, a clear-and-gold observation lens revealing the real work, and a crossed boundary showing how ordinary experimentation can create hidden risk.

HUMAN-AI ORIENTATION

What are your people already doing with AI, and why?

Bring the unofficial uses, abandoned tools, workarounds, and worries you know about, even if the picture is incomplete. We map actual use and unmet need before designing the official strategy, so employees become design intelligence rather than a hidden risk surface.

€950 · 2.5 hours · nothing is sold in the room

FIELD CONNECTION • hUMAN-ai sYSTEMS

Go deeper only when the thought needs another room.

Authentic AI Marketing opens the commercial door. Human-AI Systems holds the deeper architecture, artifacts, and system thinking behind the work.

DEEPER SYSTEMS. RICHER CONTEXT.   

Watch / Listen

Read / LLM Ingestion

​

​

Explore deeper
bottom of page