AGENSPHERE/ JOURNAL
← JOURNAL
ENTERPRISE AI · PART 5 OF 9
J-029NOTE3 MIN READ

Shadow AI: when every team buys its own model

Shadow AI is what happens when marketing has one AI subscription, support another and engineering three. Each team solved its own problem, and the company now pays several times for the same capability with no shared context, no shared controls and no view of the total.

IN SHORT
  • Shadow AI is AI use outside any shared platform or policy: personal accounts, team-level subscriptions and one-off integrations, each chosen locally.
  • It causes duplicated spend, inconsistent quality, data leaving through unapproved tools, and no company-wide view of cost, usage or risk.
  • Banning tools rarely works; people route around bans when the tools help them. Making the approved path the easiest path works better.
  • A shared AI platform gives every team the same gateway, routing, context and controls, while leaving them free to build their own use cases on top.

This is part 5 of Enterprise AI. Part 4 showed how data leaks through the paths around a model. The biggest of those paths is organisational: AI adopted team by team, with nobody looking at the whole.

01What is shadow AI?

Shadow AI is any use of AI that happens outside a shared platform or policy. It is the AI version of shadow IT, and it grows for good reasons: the tools are useful, cheap to start, and available with a credit card.

A typical picture after a year of enthusiastic adoption:

  • Several teams pay for separate chat or writing assistants.
  • Two teams have built their own integrations with different model providers, each with its own API key.
  • Support uses an AI feature inside its helpdesk tool; sales uses a different one inside the CRM.
  • Individuals use personal accounts for work tasks because the approved option is slower to access.

Each decision made sense locally. Nobody can answer the company-level questions.

02What does it cost?

Duplicated spend. The same capability is paid for several times, often at retail rates, with no volume leverage and no routing to cheaper models (see part 1).

Duplicated work. Three teams independently build a connector to the same knowledge base, each slightly wrong in a different way.

Inconsistent answers. The support bot and the sales assistant give customers different answers about the same policy, because they read different copies of it (see out of context).

Uncontrolled data flows. Customer and employee data goes to providers and regions nobody approved, under terms nobody reviewed.

No total. Finance sees a dozen small line items across cards and departments. Nobody knows what the company spends on AI, or what it gets for it.

03Why don't bans work?

Because the tools genuinely help, and people will use them anyway. A blanket ban moves usage to personal devices and accounts, which is worse for data protection, not better. It also signals that the company is not serious about AI, which pushes the most capable people to work around the rules.

The approach that works is the opposite: make the approved path the easiest path.

04What does a shared AI platform provide?

A small central team runs the shared foundations once, and every team builds on them:

Shared onceBuilt per team
Gateway: one entry point to all approved modelsUse cases and workflows
Routing: cheapest adequate model per taskPrompts and tool choices
Context layer: connectors, index, permissionsTeam-specific knowledge sources
Compliance: classification, redaction, retentionEvals for their tasks
Observability: cost, usage, quality per teamProduct decisions
platform/teams/support.yaml
team: support
budget_monthly_usd: 4000          # alerts at 80%, hard stop requires approval
allowed_models: [small-fast, mid-tier]
escalation_models: [frontier]
data_classes_allowed: [customer_contact, order]
context_sources: [helpdesk, orders, returns-policy]
owners: [support-eng@company.example]

Teams get faster, not slower: a new use case starts with access to approved models, company context and compliance already in place. The company gets one bill, one set of controls and one view of what AI is doing.

You cannot govern AI you cannot see. The fix is not a ban; it is a better default.

05What about AI features inside SaaS tools?

They are often the right choice for work that lives entirely inside that tool. Review them like any processor (what data they send, where, under what terms) and prefer tools that let you bring your own model endpoint or gateway, so their usage shows up in your cost and audit view.

06Where does this fit?

Shadow AI is solved at L0 infrastructure (one gateway, one set of controls) and L5 product and workflow (making the shared path the convenient one). It is the organisational side of the owned intelligence layer.

Previous: Data compliance with LLMs. Next: Avoid LLM vendor lock-in.

Building something like this?DESCRIBE A SYSTEM →