AI governance and shadow AI

AI adoption stalls when nobody owns the outcome.

Most stalled rollouts do not have a tool problem. They have an ownership problem, and the clearest evidence is that people are already using AI nobody approved, to do work nobody assigned them to do that way.

Why does AI adoption stall even when the tools work fine?

Because a tool can be deployed by a department, and an outcome cannot. IT can make an assistant available to everyone in the company by Friday. Nobody in that chain is accountable for whether the work actually changes.

The abandonment numbers reflect that. S&P Global found 42% of companies abandoned most of their AI initiatives in 2025, up sharply from 17% the year before, and RAND puts overall AI project failure above 80%. Gartner found 88% of HR leaders saying their organizations have not realized significant business value from AI tools.

None of those failures are technical. A tool that works, that nobody is accountable for, produces exactly this.

How this gets found

A stall that survives working tools is not a technology finding, and it will not show up in a usage dashboard. It sits in one of the four PACE pillars and from the inside it looks like ordinary friction.

Naming which pillar is carrying it is what the AI Adoption Gap Diagnostic™ is for.

What is shadow AI, and why should a CEO care?

Shadow AI is employees using AI tools the company never approved, usually on personal accounts, to get their own work done.

It is rarely defiance. It is people solving a real problem with the fastest tool available, which makes it a signal of unmet need rather than a discipline issue. Somebody had a deadline, the approved path was slow or nonexistent, and a free tool was one tab away.

The reason it matters to a CEO is visibility. McKinsey found leaders believe about 4% of employees use generative AI for a meaningful share of their daily work, when the real figure is closer to 13%. Leaders are consistently wrong in the same direction about their own companies, which means the risk sits in a place nobody is looking.

What actually leaves the building is the exposure. Customer data pasted into a consumer tool. A proposal drafted by a model nobody reviewed. Advice given to a client that originated somewhere no one can reconstruct.

Does blocking AI tools stop shadow AI?

No. Blocking moves the same behavior onto personal phones and personal accounts, where the company can no longer see it at all. The usage does not stop, the visibility does.

The workable approach runs the other direction. Surface what people are already using, without punishing anyone for saying so. Sort it by actual risk rather than treating every use the same. Then channel the low-risk work into approved tools so it keeps moving, with the company able to see it.

That reframe only works if the first person who admits to using an unapproved tool is thanked rather than disciplined. A company that punishes the first honest answer will not get a second one.

Shadow AI is not a discipline problem.
It is a demand signal.

How this gets handled

Shadow AI is people solving a real problem with the only tool they were given, which is their own initiative. A block removes the tool and leaves the problem, so the behavior moves somewhere you cannot see it at all.

The first move is an amnesty rather than a rule, and an amnesty only produces honest answers when the person asking has no stake in the org chart and will not be in the room at anyone’s next review. That is usually the point at which an outside pair of eyes stops being a nicety.

What comes back is a Capability and Adaptive Culture finding, with a count attached.

Who should own AI in my company?

A named executive who is accountable for the outcome. Not a committee, and not a department that owns one slice of it.

IT can secure the tools. HR can support the people through the change. Neither of them can decide what the company is trying to become with AI, and that decision is the thing everything else depends on. Where it gets delegated to whoever seemed closest to the topic, the organization ends up with a tool owner and no outcome owner.

The evidence favors clarity at the top. KPMG found only 24% of organizations naming the CEO or executive committee as ultimately accountable for AI-informed decisions. Where accountability does sit clearly at CEO level, 14% report established ROI against 4% where it does not, and 57% report meaningful business value against 21%.

Underneath that, each domain needs a named human. Not a function, a person. “Marketing owns it” is how something ends up owned by nobody.

Does a mid-market company need a dedicated AI team for this?

No, and most cannot afford one. IBM found fewer than 40% of organizations have formal AI governance at all, so the realistic bar is lower than the conversation suggests.

Four things get a company most of the way:

  1. 01Named ownershipA specific person accountable for AI outcomes, and a named owner for each domain underneath.
  2. 02A policy people can followShort enough to read once and remember. A policy nobody can recall is a policy nobody is following.
  3. 03Risk tieringSeparate low-stakes internal work from anything touching customers, regulated data, or employment decisions. Most uses are low risk and should move fast.
  4. 04A human before it shipsSomeone accountable for review before AI output reaches a customer, and whose name is on it.

What does weak AI governance actually cost?

In the United States the enforcement precedent already exists. The EEOC settled its case against iTutorGroup over software that automatically rejected older applicants, which established that a company remains liable for what its automated systems decide.

The EU AI Act carries penalties reaching 7% of global revenue, with prohibited practices enforceable from February 2025. For a US company under that threshold the direct exposure is limited, but it sets the standard enterprise buyers increasingly apply to their vendors, which is where it starts to matter commercially.

The quieter cost is the one that shows up first. A company that cannot say who approved an AI-generated answer cannot defend it, to a customer, a regulator, or its own board.

Is AI governance only about avoiding risk?

Governance gets sold as insurance, which is why it keeps losing budget arguments to things that visibly make money.

What it actually does is let people move faster with less hesitation. When the boundaries are clear, an employee does not have to guess whether they are allowed to use a tool on a given task, and guessing is what slows everything down. Clear rules produce more experimentation, not less.

Governance is also what makes adoption measurable. You cannot show a return on something you cannot see, and shadow AI is invisible by definition.

Ethics, trust and governance is domain 08, and shadow AI visibility is domain 09, of the twelve


The sources

  • 42% abandoned most AI initiatives in 2025

    Up from 17% the year before.

    S&P Global, 2025
  • Over 80% of AI projects fail RAND Corporation, 2025
  • 88% of HR leaders report no significant business value Gartner, July 2025
  • Leaders estimate 4% meaningful daily use, the real figure is nearer 13% McKinsey, Superagency in the Workplace, 2025
  • Fewer than 40% have formal AI governance IBM, 2025
  • 24% name the CEO or executive committee as accountable for AI-informed decisions

    Where accountability is clear at CEO level, 57% report meaningful value against 21% where it is not.

    KPMG Global AI Pulse Q2 2026, n=2,145

Frequently asked questions

What is shadow AI?

Shadow AI is employees using AI tools the company never approved, usually on personal accounts, to get their own work done. It is rarely defiance. It is people solving a real problem with the fastest tool available, and it is a signal of unmet need rather than a discipline issue.

Who should own AI in my company?

Ownership has to sit with a named executive who is accountable for the outcome, not distributed across a committee. IT can secure the tools and HR can support the people, but neither can decide what the company is trying to become with AI. In a mid-market company that ownership usually belongs to the CEO or a directly accountable executive, with named owners for each domain underneath.

Does blocking AI tools stop shadow AI?

No. Blocking moves the same behavior onto personal phones and personal accounts, where the company can no longer see it at all. The workable approach is to surface what is already being used, sort it by actual risk, and channel the low-risk uses into approved tools so the work keeps moving with visibility.

Does a mid-market company need a dedicated AI team for governance?

No. What it needs is named ownership, a short written policy people can actually follow, a simple risk tiering that separates low-stakes uses from anything touching customers or regulated data, and a human accountable for review before AI output leaves the building. That is achievable without hiring anyone.


Start here

Find out what your people are already using.

If you cannot name the person accountable for AI outcomes, that is the finding. The Snapshot takes five minutes and will show you where else it is unowned.

Not ready to talk yet

Get the next one in your inbox

People who find this page are usually reading something that finally names a piece nobody had named for them. Every week or two I publish one more of those — where AI adoption is actually breaking down inside companies, built from the research and from what I see in real leadership teams.

No pitch, no sequence designed to wear you down. If it stops being useful, one click and you are out.

Would you rather start with a read on your own organization? The AI Adoption Gap Snapshot™ takes five minutes and covers all twelve domains.