re-ai-gov Join the waiting list

Kennisbank

The tool nobody approved, but everyone uses

An employee pastes a piece of text into a free chat window because it works faster than the internal system. A team takes out a subscription to an AI tool because the request for something official would take weeks. A supplier adds AI functionality to software that has been in use for years, without any conversation about it taking place. None of these people are trying to hide anything. They are trying to do their work.

That is the core of shadow AI: it does not arise from unwillingness, but from a gap between what people need and what the formal process delivers. As long as that gap exists, shadow AI will keep emerging, regardless of how much policy is written.

Why the IT list is not accurate

Most organisations have an overview of approved software. That overview is a starting point, not a reflection of reality. What people actually use is almost always ahead of it: the question of how to prevent company data ending up in a free chat window illustrates how easily a tool can slip outside all visibility. The same applies to a department that takes out its own subscription on its own initiative because the regular route feels too slow, or to a browser extension that gains access to email without any separate approval existing for it. None of these situations appear on an IT list. Yet they exist.

Why it does not disappear on its own

There is a tendency to treat shadow AI as an enforcement problem: prohibit, block, sanction. That backfires. Anyone who knows that an honest answer will lead to a problem stops giving honest answers. The tool does not disappear, it becomes less visible. Precisely the opposite of what an organisation needs.

A second reason it does not resolve itself: existing governance is often built for software that you buy and install, not for a service that someone opens in a browser and abandons again the next day. A pilot setup that was once meant to be temporary shows how something small, without a clear moment of review, can continue for years without anyone feeling ownership of it. Without a process that structurally notices this kind of use, it stays under the radar, however good the intentions.

What does work: asking without repercussions

The only way to know what is going on is to ask. Not as a control measure, but as stocktaking. Employees who know that an honest answer will not lead to a conversation with HR will actually give that answer. That requires a tone and a process that make clear beforehand: this is about gaining an overview, not about targeting anyone.

This also requires attention to the way new processes are placed alongside existing ones. A second process that is set up alongside the existing one without the first being adjusted or withdrawn is often ignored, simply because people stick to their habits. A stocktaking exercise that comes as an extra obligation on top of the work receives the same treatment.

From stocktaking to classification

Once it is clear what is actually being used, the next question follows: what does that tool do, and what risk goes with it? A tool that summarises text for internal use requires something different from a tool that helps decide on customer acceptance or personnel evaluation. That classification by role and risk level is what turns an inventory into something usable: a basis on which the board, CIO or General Counsel can explain what is going on and why it can be accounted for.

This governance layer connects to the risk structure an organisation already has, not to a new framework alongside it. The content of the rules that AI applications must comply with changes and is kept up to date elsewhere; what matters here is that the organisation has a working way of knowing what is running, who is responsible for it, and how that can be demonstrated to the board or a supervisory authority.

The next question: what can be handed over

Once it is clear which AI is actually being used and what risk is associated with it, another question naturally arises: which part of the work could an AI application actually take over, and which part not. That is a different question from one of approval and oversight, but one that logically follows from it. The work scan from FTE TO AI calculates, per task, what part of the work can be taken over by AI, based on what a role actually involves. Where the Responsible AI Scan brings order to what is already running, the work scan reveals what can still be gained.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.