14 September 2026
AI adoption is no longer confined to formal technology projects.
Employees are using generative AI tools to draft documents, analyse information, summarise meetings, write code, research ideas and complete everyday tasks. In many organisations, that adoption is happening faster than policies, controls and governance can keep up.
The question is therefore not simply whether your organisation uses AI.
It is whether you know how it is being used, what information is being shared, which tools have been approved and where responsibility sits when something goes wrong.
Getting control of AI does not mean preventing people from using it. It means creating enough governance for the organisation to benefit from AI without introducing risks it does not understand.
What Is Shadow AI?
Shadow AI is the use of AI tools or applications without the organisation’s formal approval, oversight or knowledge.
It can be as simple as an employee opening a publicly available generative AI tool and using it to help with a piece of work.
The employee may be trying to work more efficiently and may have no intention of creating risk.
The problem is that the organisation may have no visibility of:
Blocking every AI tool is unlikely to be a sustainable answer.
Organisations need a controlled route for appropriate use.
What Are the Risks of Employees Using Public AI Tools?
The risk depends on what the tool is being used for and what information is involved.
Employees may inadvertently enter confidential company information, customer data, personal information, intellectual property, commercially sensitive material or internal technical information into an external AI service.
There are also risks associated with the output.
AI-generated information can be inaccurate, incomplete or misleading. If employees assume an answer is reliable simply because it has been produced confidently, errors can enter documents, analysis, customer communications or decision-making.
Organisations therefore need to consider both sides of AI use:
What information are we putting into AI, and what are we doing with the information AI gives back?
Do You Need an AI Policy?
For most organisations using AI, clear guidance is an important starting point.
Employees need to know what is acceptable rather than being expected to work it out individually.
An AI policy or acceptable-use framework might address:
A policy alone, however, does not create effective AI governance.
It needs to be understood, communicated and supported by appropriate processes and accountability.
Who Should Be Responsible for AI Governance?
AI governance should not automatically become the responsibility of IT alone.
AI can affect information security, data protection, legal obligations, intellectual property, procurement, HR, customer relationships and operational decision-making.
Responsibility may therefore involve several areas of the organisation.
What matters is clarity.
There should be defined ownership for AI governance, a route for assessing significant use cases and clear responsibility for approving tools or making decisions about risk.
Senior leadership also needs appropriate visibility of how AI is being adopted and where material risks exist.
Without that structure, individual teams can make separate decisions about AI without understanding their combined impact on the organisation.
Do You Know Which AI Tools Your Organisation Is Using?
Before designing extensive controls, establish what is already happening.
AI may already exist within software the organisation uses every day, while employees may also be accessing standalone tools independently.
An AI inventory can provide a clearer picture.
It could record:
The objective is not to create administration for every minor interaction with AI.
It is to identify where AI is being used in ways that could create meaningful business risk and ensure those uses receive appropriate oversight.
How Should New AI Tools Be Assessed?
The fact that an AI tool is useful does not automatically mean it is appropriate for organisational use.
Before introducing a new tool or significant use case, organisations should understand what it does and the risks it introduces.
Questions might include:
The level of assessment should reflect the significance of the use case.
Using AI to help brainstorm internal ideas is very different from using it to make or influence decisions affecting customers, employees, finances or critical operations.
How Do You Balance AI Innovation With Control?
Overly restrictive governance can push AI use underground.
If employees believe the organisation’s only response to AI is to prohibit it, they may continue using readily available tools without telling anyone.
Equally, allowing unrestricted adoption creates obvious risks.
The better approach is to establish clear boundaries.
Employees should understand where AI is encouraged, where additional approval is needed and where particular uses are unacceptable.
This allows organisations to benefit from experimentation and productivity while retaining oversight of higher-risk activity.
Governance should help people use AI responsibly, not simply make AI harder to use.
What Role Does AI Literacy Play?
Policies and controls are more effective when employees understand why they exist.
AI literacy helps people recognise the capabilities and limitations of the technology they are using.
Training and guidance can help employees understand issues such as:
The aim is to create informed users rather than relying entirely on technical restrictions.
How Does Third-Party AI Risk Fit Into This?
Many organisations will consume AI through external providers rather than developing their own models.
That makes supplier governance important.
Organisations need to understand how providers handle information, what contractual protections exist, how services may change and what dependencies are being introduced.
AI functionality can also be added to existing software products, meaning the organisation’s exposure may change even when it has not deliberately purchased a new AI system.
This makes AI part of the wider question of third-party and supply chain cyber risk, rather than a completely separate technology issue.
Where Does ISO/IEC 42001 Fit?
ISO/IEC 42001 provides a management system framework for organisations that develop, provide or use AI systems.
It can help organisations establish a structured approach to areas such as responsibility, risk, governance and the ongoing management of AI.
For some organisations, formal alignment or certification may become commercially valuable, particularly where customers want greater assurance about how AI is governed.
For others, ISO/IEC 42001 can provide a useful structure for establishing responsibilities, assessing AI risk and developing more consistent oversight.
Its value depends on how AI is being used and the level of assurance the organisation needs.
How Can KA2 Help You Strengthen AI Governance?
KA2 helps organisations understand how AI is currently being used and where greater control may be needed.
That can include reviewing existing AI use, identifying governance gaps, clarifying responsibilities, developing policies and assessing how AI tools and suppliers should be governed.
Where appropriate, recognised frameworks such as ISO/IEC 42001 can provide additional structure and a route towards greater assurance.
The objective is practical AI governance that enables responsible adoption while protecting the organisation, its information and its customers.
Take Control of AI Without Stopping Innovation
AI is already changing how people work.
The organisations that manage that change effectively will not necessarily be those with the most restrictive policies. They will be the ones that understand how AI is being used, establish sensible boundaries and give employees clear guidance about what responsible use looks like.
The starting point is visibility.
Talk to KA2 about assessing AI use and building practical AI governance across your organisation.