The proliferation of unauthorized or ‘shadow’ AI tools within workplaces is a widespread issue, frequently highlighted in recent reports on AI adoption. This phenomenon, where employees use unapproved applications, is driven by a few core reasons: employers may be overly restrictive with sanctioned tools, offering limited options, or they may lack a cohesive AI strategy altogether. The risks associated with this practice are significant, primarily involving the potential exposure of sensitive company data through leaks or its inadvertent use in training consumer-grade AI models, a risk mitigated by enterprise-grade solutions with enhanced security.
Shadow AI: A Symptom, Not the Disease
Many organizations mistakenly view shadow AI as a problem to be eradicated through stricter enforcement or more rigorous training. However, industry experts suggest that shadow AI is often a symptom of deeper issues within the workplace culture and strategy. Addressing the underlying causes is crucial for effective management.
Clear and Accessible Policies are Key
According to Shana Simmons, Chief Legal Officer at Zendesk, many current AI policies are overly formal and written in legalistic language that is difficult for the average employee to understand. “AI policies often fail because they’re written for lawyers, not for the people expected to follow them,” Simmons explained. “If people can’t understand the guidance, their behavior won’t change.” Furthermore, she noted that policies are frequently stored in inaccessible locations, such as obscure HR folders, rendering them ineffective. “If a policy is buried in a handbook or on a website, it’s not going to reach employees when they need its,” she stated, emphasizing that policies should be integrated into the user interface or workflow where employees already operate.
Rethinking AI Training and Enablement
Canva highlights that a common error is treating AI training as a one-time curriculum rather than an ongoing development process. The company advocates for learning through practical problem-solving rather than formal instruction on prompting techniques. This approach suggests that employees learn best by actively engaging with and resolving issues using AI tools.
Understanding the ‘Why’ Behind Shadow AI
Investigating the reasons behind shadow AI use reveals that it’s often a response to insufficient or unsuitable tooling provided by employers. Simmons indicated that most employees aim to act appropriately and that the prevalence of shadow AI is typically linked to poor tool provision. “If employees are given the tools they need and are informed of the rules and requirements in a way that’s understandable to them, and technical controls are in place to restrict the riskiest behavior, I’d expect shadow AI to be no greater a problem than any other form of employee misconduct.”
Instead of simply forbidding new AI applications, understanding why employees gravitate towards specific tools is vital for developing effective policies and safeguards. In some low-risk scenarios, shadow AI can even serve as valuable feedback, indicating areas where organizational tools or strategies are falling short. However, maintaining oversight is essential to prevent data leaks and other security threats.
AI Literacy is Learned Through Practice
Providing employees with greater guidance and support is essential, but the form this takes is debated. Simmons suggests that “training alone is not very effective for developing AI fluency,” although initial direction and pointers can establish a helpful foundation. Zendesk has found success by allowing employees dedicated time and space to experiment with AI tools independently.
Zendesk’s approach has included pausing non-urgent work for internal hackathons to encourage AI exploration, which has demonstrably improved employees’ practical skills and cross-team collaboration. While halting operations isn’t always necessary, it illustrates one method of fostering AI proficiency. Canva also pilots similar initiatives, encouraging its employees to dedicate time to AI experimentation. A spokesperson for Canva noted, “We give our team the room to step back, get out of business as usual, and try something genuinely new.”
Simmons concluded that “Practical AI training should go beyond introductory courses and prompting techniques and create space for employees to actually use the tools in a safe, secure environment.” Piloting AI tools with synthetic data, which carries no risk of harmful consequences, is an effective way to build employee confidence.
Shared Responsibility for AI Adoption
The responsibility for upskilling employees in AI is a point of discussion, with views differing on whether it lies primarily with employers or employees. Simmons, from a C-suite perspective, believes organizations should take the lead by providing access to tools and learning opportunities. This involves offering a broad range of support, including “ideation and experimentation through initiatives like hackathons, sandboxes, and collaboration opportunities.”
Ultimately, employees must also take initiative to leverage these opportunities for their own professional development and to remain relevant in an evolving AI-driven work landscape. Canva echoes this sentiment, stating, “Employers own the conditions: the time, budget, permission to experiment… Employees own the curiosity.” This highlights a symbiotic relationship where employers create the environment for learning, and employees drive their own engagement and skill development.
By understanding and addressing the root causes of shadow AI—such as inadequate policies, insufficient tooling, and a lack of practical learning opportunities—organizations can foster a more secure and productive AI-integrated workplace. This approach shifts the focus from punitive measures to proactive enablement, encouraging responsible AI use and innovation.


