Shadow AI surge: execs defy bans, risks escalate

The gist
Senior execs are fueling a shadow AI surge in healthcare, quietly doubling down on banned tools and exposing organizations to skyrocketing security and compliance risks.
What to know
- Nearly two-thirds of healthcare executives admit to using unapproved AI tools—almost twice the rate of lower-level employees—signaling a culture that prizes speed over security.
- Shadow AI now accounts for up to 70% of unsanctioned AI use, contributing to 1 in 5 data breaches and costing organizations an average of $670,000 per incident.
- Banning AI tools backfires by driving their use underground; experts urge integrated governance, visible policies, and accountable leadership to restore control and trust.
C-Suite’s Double Standard
Senior executives drive shadow AI adoption by bypassing weak internal tools and governance, leaving organizations exposed to untracked risks that IT leaders can neither audit nor control.
Senior executives use unapproved AI tools at nearly twice the rate of lower-level employees, with nearly two-thirds admitting to such usage compared to just 31% of their subordinates, according to a TrustedTech survey. This disproportionate reliance on shadow AI not only undermines governance efforts but also signals a culture where speed is prioritized over security and compliance, as Andy Nolan of TrustedTech warns, 'If senior leaders bypass approved AI tools or policies, it sends an implied message that speed matters more than security and compliance.'
The high usage of shadow AI by senior executives creates a governance conundrum because CIOs and CISOs often lack the authority to enforce policies on C-suite leaders, complicating risk management. Amit Maloo, CISO at Ivalua, highlights this blind spot: 'CISOs and CIOs are held accountable for the risk exposure but have no visibility into the problem... there is no audit trail, no permissions model, or no way to reconstruct what happened or why.' This lack of oversight leaves organizations vulnerable to untracked decisions made with sensitive information.
At the root of senior executives’ shadow AI usage is the absence of approved AI tools that meet their performance and usability expectations. TrustedTech notes that shadow AI flourishes because 'what their employer hands them is worse than mainstream AI tools, or because nothing has been approved in the first place.' Amit Maloo emphasizes that governance policies alone are insufficient, stating, 'Successful organizations will be those that make the secure path the easiest path,' underscoring the need for secure, user-friendly AI solutions aligned with business pace to effectively curb shadow AI.
Shadow AI’s Hidden Fallout
Unapproved AI use now fuels a surge in costly data breaches and legal liabilities as security teams grapple with invisible tools, unvetted vendors, and policies that push risky practices further underground.
Shadow AI has emerged as a pervasive security blind spot within organizations, with estimates showing that 40% to 70% of AI usage occurs outside sanctioned tools, leaving security teams largely in the dark. Experts like Matt Caffrey of Barracuda emphasize that the core issue is not AI itself but the lack of visibility into its use, which complicates governance and risk management efforts. This widespread unapproved adoption creates a governance vacuum far more challenging than traditional shadow IT, exposing enterprises to significant data leakage risks and compliance breaches.
Attempts to outright ban AI tools have proven counterproductive, often driving usage underground where it becomes even harder to detect and control, thereby increasing risks of sensitive data exposure and compliance violations. As Matt Caffrey warns, prohibitive policies may inadvertently escalate security threats, while Chase Cunningham highlights that forbidding generative AI outright is not a strategy but a catalyst for covert and indiscriminate use. Instead, organizations must focus on understanding how and why employees use AI to craft policies that encourage responsible adoption and visibility.
The security and legal ramifications of shadow AI are profound, with IBM research revealing that shadow AI contributed to one in five data breaches and added an average of $670,000 to the cost of each incident. Unvetted AI vendors—98% of whom bypass security reviews—pose heightened risks, especially large language model providers like OpenAI and Anthropic, which are flagged as 52% more likely to be high risk due to their deep access to sensitive data and critical systems. This lack of oversight not only jeopardizes proprietary information and client confidentiality but also exposes companies to GDPR violations and legal liabilities, as courts increasingly hold deploying organizations accountable rather than AI developers.
Security teams are shifting from traditional blocking tactics—which have failed against persistent employee reinstallation of unapproved AI tools—to faster, integrated risk review processes that prioritize speed and contextual governance. Technologies like protective DNS offer critical visibility by monitoring AI tool communications through organizational networks, yet technology alone is insufficient. As Lee Anstiss and others stress, continuous employee training and fostering an AI-positive culture are essential to embed accountability and judgment into AI use, transforming governance from reactive enforcement into proactive risk mitigation.
Embedding Accountability in AI
True AI governance demands built-in oversight, cross-functional accountability, and sanctioned tools that outcompete shadow AI—otherwise, organizations risk a persistent culture of secrecy and fragmented responsibility.
Effectively managing shadow AI demands an integrated approach that weaves governance frameworks directly into AI architectures from the outset, rather than retrofitting controls post-deployment. Frank Cirone of Snowflake underscores this necessity, emphasizing that governance requires a fusion of domain, AI, IT, and data expertise to embed accountability and trust within AI agents. This architectural embedding is complemented by cultural shifts that clarify ownership and responsibility, addressing the alarming statistic that nearly one in four organizations lack clear accountability for AI errors, which severely undermines trust and governance efforts.
Cultural transformation is pivotal in fostering a climate of responsible AI adoption, where accountability and human oversight are non-negotiable. Mike Goldsworthy highlights CFOs as stewards of this change, advocating for a 'glass box' approach that ensures AI outputs are explainable, auditable, and integrated within governed financial workflows. This cultural shift counters the fragmented ownership and governance challenges noted by Lauren Kornutick and Aslam Rawoof, who call for cross-functional committees reporting to top leadership to maintain trust and clarity in AI decision-making.
Technology remediation plays a critical role in mitigating shadow AI risks by providing sanctioned, secure AI tools that match or exceed the utility of unauthorized alternatives, alongside comprehensive AI feature inventories that restore visibility and control. Deluxe’s CTDO Yogaraj Jayaprakasam stresses that shadow AI is fundamentally a governance vacuum, not a technology failure, and proactive deployment of approved AI lanes can preempt unsanctioned usage. Allan Dabre further advocates for AI inventories capturing ownership, purpose, risk tiers, and lifecycle data to maintain ongoing oversight, though such inventories require clear accountability to avoid becoming obsolete.
Sustainable AI governance hinges on the continuous execution of integrated strategies that balance innovation with security and compliance. Grant Erickson describes mature frameworks that allow controlled experimentation through defined validation processes, ensuring users can trial new tools without compromising safety. Edward Chen echoes this by emphasizing disciplined AI design that traces every action back to human accountability, supported by robust data foundations, identity controls, and governance mechanisms. This holistic approach not only manages risks but also builds organizational momentum and trust in AI adoption.



