
Beyond the Shadows: A Data Leader's Guide to Governing AI
For years technology professionals have had to deal with Shadow IT. For data professionals, this has meant governing everything from Excel Hell to cottage solutions built using low-code technologies. Now, with AI tools and platforms commoditised, 75% of knowledge workers are using these, and of those, 78% are bringing their own tools without waiting for formal approval.¹
When employees use unvetted AI tools without understanding the implications, they create significant organisational risk. How then do Data Leaders and their peers deal with this challenge? An outright ban on these tools never seems to work and also seems counter productive. Data Leaders need to move from reactive security to proactive risk resilience.
The Cost of Inaction
Shadow AI breaches cost an average of $4.63 million which is $670,000 more than a typical data breach, due to longer detection times - an average of 247 days.² In 2023, Samsung employees in its semiconductor business uploaded source code to ChatGPT to check for errors. This source code was confidential, and once uploaded, became part of ChatGPT’s training data and could not be removed.
The stakes are now even higher with the introduction of the EU AI Act. “We didn’t know” is no longer a defence, with penalties potentially reaching €35 million or 7% of an organisation’s global revenue, significantly exceeding the GDPR’s maximum penalties of €20 million or 4% of revenue.³
The Current State
69% of cybersecurity leaders suspect or have evidence of unauthorised public generative AI use, yet 55% of these organisations lack clearly defined AI vulnerability management or incident response plans^4. Privacy is a clear concern but a massive risk is the lack of transparency in AI algorithms as this complicates data-driven decision making. Add to this that by 2030, 50% of organisations will face delayed software upgrades and rising maintenance costs due to the unmanaged technical debt (such as poorly documented AI integration and incompatible code) caused by the use of generative AI.⁴
Trying to address these challenges with policy only does not work. For example, an organisation that I recently worked with had a policy that only permanent employees would be assigned a Microsoft Copilot licence, driving contractors to use unvetted services such as ChatGPT, potentially creating the same data leakage risks Samsung experienced.
A Better Approach
To address the risk of Shadow AI, data leaders should first seek to understand what challenges users are facing and the tools they are using to get their work done. In addition to this, there should be a technical audit to verify what applications and services are actually being used. These findings can then be used to drive the organisation’s AI strategy, inform policy, and support learning and development initiatives.
Shifting governance from restricting tools and platforms to enabling responsible AI usage helps knowledge workers, and therefore the organisation, develop the skills and practices necessary to unlock value from AI.
The Opportunity
The goal isn’t for data leaders to kill productivity but to ensure that AI usage is governed and the organisation and its employees are protected. Organisations that can get this right are are predicted to achieve 30% higher customer trust scores and 25% better compliance ratings by 2028 compared to organisations without proper AI governance.⁵
References
(https://news.microsoft.com/source/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/) (https://www.ibm.com/reports/data-breach) (https://artificialintelligenceact.eu/article/99/#:~:text=Summary,1.) (https://www.infosecurity-magazine.com/news/gartner-40-firms-hit-shadow-ai/) (https://www.servicenow.com/uk/blogs/2025/view-from-ai-control-tower#:~:text=Trust%20will%20be%20a%20defining,Controlling%20AI%20sprawl)

Günter Richter
Founder & Principal Consultant, Umlaut Consulting
30+ years of experience in strategic consulting and data transformation. Helping organisations unlock the real value of their data.