Skip to main content
We have begun the founding chapter. Be among the first
+1 (888) 885-5991|[email protected]|[email protected]

Policy Analysis

Governing What You Cannot See: Why Shadow AI Outruns Every AI Policy Manual

Shadow AI now shows up in 43% of security incidents, roughly double a year ago, while more than two thirds of organizations still have no way to detect it. You cannot police every browser tab. You can verify what comes out the other end.

Anuraag Karangle, EU Policy and Regulatory Affairs Lead, The AI LabAugust 27, 20265 min read
Policies don't dictate behavior, deadlines do: how to address Shadow AI in the enterprise

You cannot police every browser tab. You can verify what comes out the other end.

August has been a relentless month. Article 50 of the EU AI Act has been enforceable since August 2, 2026, and my days have been a marathon of risk frameworks, transparency mandates, and compliance audits with organizations serving the European market.

But the reality of enterprise is not in a policy document. It is in the trenches of daily delivery, inside teams trying to meet the market's expectations and Friday's deadline at the same time.

Over evening coffee here in Switzerland, listening to my wife describe her week as an IT project manager, the ground truth arrived in a single sentence.

Policies do not dictate behavior. Deadlines do.

You can draft the strictest, most legally sound corporate AI guidelines in the world. You cannot make a team under pressure use only the approved internal model. When a sprint is due Friday and the approved tool is slower, people reach for whatever is fastest. Usually that is an unverified public chatbot, and usually it gets the job done.

Welcome to the era of Shadow AI.

The Numbers Are Worse Than the Anecdotes

Every executive I speak with recognizes this behavior in their own organization. Very few know how large it has already become.

IBM's Cost of a Data Breach 2026 found shadow AI involved in 43% of security incidents, roughly double the 20% reported a year earlier. In the same report, more than two thirds of organizations had no governance process capable of limiting shadow AI exposure. The exposure is growing faster than the controls built to contain it.

Cyberhaven's 2026 AI Adoption and Risk Report, published in February, found that 39.7% of all AI interactions involve sensitive data, and that the average employee feeds sensitive data into an AI tool roughly once every three days. The route matters as much as the volume. Cyberhaven measured 58.2% of Claude usage and 60.9% of Perplexity usage running through personal accounts, outside any corporate agreement, audit log, or retention policy.

A July 2026 survey of 500 employed US adults commissioned by Kolmogorov Law found 38% had entered work information into a personal AI account their employer does not control. Nine percent had pasted in code or technical material. Nearly two thirds, 64.4%, did not know that doing so can in some circumstances be unlawful.

The behavior is also deliberately quiet. Microsoft and LinkedIn's Work Trend Index, surveying 31,000 knowledge workers across 31 markets, found 52% of people who use AI at work are reluctant to admit using it for their most important tasks. The work that matters most is the work least likely to be declared.

Management believes it has an AI governance strategy. The delivery team knows it has an undeclared data flow.

Higher Walls Are the Wrong Instinct

The traditional response is to build higher walls: block the IP ranges, lock down the browsers, issue a stern memo. In 2026 that is whack-a-mole against a capability that runs in any browser tab, on any phone, on any personal device sitting beside a work laptop.

It also fails on its own terms.

A blocked tool does not become an unused tool. It becomes an unlogged one.

Moved onto a personal device, the same work carries on somewhere the organization has no visibility at all. Every wall you raise pushes the behavior further outside your field of view, and the data still leaves.

In Europe the stakes are not theoretical. Article 50 transparency obligations do not ask whether the AI system your employee reached for was sanctioned. Under Article 99(4), Regulation (EU) 2024/1689, failing those obligations can draw administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, with GDPR exposure sitting on top. The organization carries the liability for a tool it never approved, never procured, and cannot see.

So enforcement is the wrong question. You cannot police every browser tab, and you should not want to. The productivity your people are chasing is real, and the organizations that punish it will lose the people who deliver.

Stop Policing the Input. Verify the Output.

This is the shift we are building toward at The AI Lab. Instead of defending a perimeter that no longer exists, the Trust Identity Protocol (TIP™) moves verification to the artifact itself.

TIP binds a post-quantum cryptographic signature to a verified human identity and to the declared origin of the work: human, AI-assisted, AI-generated, or mixed. The signature travels with the asset. It survives copying, reformatting, and re-upload, because it is not metadata that a platform can strip on ingest.

That changes what governance is able to ask.

Blocking unsanctioned AI compared with verifying provenance
Policing the inputVerifying the output
The questionDid someone use an unapproved tool?Does this artifact carry a signature?
Can it be answeredNo, not reliablyYes, by anyone, independently
Effect on the employeePushes the work out of sightLeaves the workflow intact
What the regulator seesA policy you intended to enforceA record they can check
Direction of travelDegrades as tools proliferateHolds as tools proliferate

The same primitive extends into engineering, where the exposure is sharpest. A Repository CTID issues one trust identity for a source repository, binding commits, releases, and published artifacts to a verified maintainer. Applied at the point where work enters the official pipeline, undeclared material stops being invisible by default and starts being conspicuous by default.

I want to be precise about maturity, because the compliance market is full of vendors who are not. The cryptographic layer is built and running today. The enterprise workflow that turns a missing signature into a blocked merge is a design direction we are working through with early adopters, not a product you can buy this quarter. What exists now is the ability to make provenance verifiable at all, which is precisely what the perimeter model never provided.

I made the underlying argument in Truth as a Service, and it holds here for the same reason. Detection asks a question after the fact that gets harder every year, because the cost of producing convincing output keeps falling. Verification asks a question at the point of creation that gets easier, because the signature is created once by the party who already knows the answer.

What This Actually Changes

Shadow AI is not an employee discipline problem. It is a visibility problem wearing a discipline problem's clothing, and it will not be solved by a firmer memo. That 43% figure falls when artifacts start carrying their own proof, and the absence of proof becomes the thing that stands out.

For a compliance function, that is the difference between a claim and an audit. Asserting that your organization governs its AI use is a position you defend. Producing a signature for a specific document, on a specific date, from a specific verified person, is a fact a regulator can check without taking your word for anything.

It is also why governance of the standard matters as much as the cryptography. A provenance layer that one vendor controls simply relocates the trust problem, which is why TIP is overseen by the AI Trust Council™ as an independent, multi-stakeholder body rather than a company function.

The organizations that come through the next few years intact will not be the ones with the thickest AI policy manuals. They will be the ones that moved from asserting governance to demonstrating it, on any single piece of work, to a regulator, a client, or a court.

Policies do not dictate behavior. Deadlines do. Build for the deadline, and verify what comes out the other end. If you are working through this in a European organization, reach out directly, or visit theailab.org to see how TIP is being adopted.


Anuraag Karangle is the EU Policy and Regulatory Affairs Lead at The AI Lab Intelligence Unobscured, Inc., where he represents the Trust Identity Protocol to regulators, institutions, and standards bodies across the European Union, with a particular focus on the DACH region. He brings more than fourteen years of international experience across enterprise software, information security, and market-entry strategy in Europe and Asia.