The Shadow IT Apocalypse is Upon Us
And it's a failure of leadership
When the recent MIT report about the high failure rate of AI pilots started making waves, I sat here, completely unsurprised. As a technologist and an educator, I’ve been getting pulled into a lot more AI-related consulting opportunities recently, and it’s not the technical side of AI implementation my clients are asking about. That was so late 2024. It’s late 2025, and businesses are finally waking up to what they really need.
And based on what I’m seeing, I’m deeply concerned.
FOMO is not a Strategy
Fear of Missing Out, as the cool kids call it, isn't just a social media thing anymore. It's become a primary driver of enterprise AI adoption. Organizations are moving at breakneck speed, terrified their competitors will gain some mythical first-mover advantage. Investors are rewarding it, so executives are trotting out grand plans and promises.
However, fear-based decisions rarely pay off. The MIT report drives this home: 95% of AI projects fail to generate ROI. Ninety-five percent. That is not something that can easily be brushed off. It’s a systemic failure at the leadership level.
I lived through the dot-com crash. I’m not a big believer in first-mover advantage because I often see that being first doesn’t correlate at all to being best.
What I’m Seeing in the Trenches
More often than not, when I start working with a client, I find teams running their own AI experiments. Marketing is using ChatGPT to write copy. Sales is feeding customer data into Gemini for lead qualification. HR is experimenting with resume screening tools they found online.
Experiments are good, a healthy company culture supports experimentation. However, the vast majority of these teams have not conducted proper risk assessments. Most don’t even know how LLMs work, what questions to ask, or how to separate marketing hype from business reality.
They’re operating under the assumption that if a tool is publicly available, it must be safe for enterprise use.
This is Shadow IT on steroids, and it’s happening at every level of the organization.
Shadow IT is an Organizational Threat
Shadow IT refers to technology solutions deployed without explicit organizational approval or oversight. In the pre-AI era, this meant employees using Dropbox instead of approved file-sharing services or setting up Slack channels outside of IT governance.
I remember delivering a data literacy workshop to leaders at a Fortune 500 company a few years back. I asked them if they trusted their data. All I got back was some uncomfortable chuckles. Root cause? Shadow IT.
That was before the AI hype train arrived. AI-powered shadow IT is exponentially more dangerous. Here’s why:
- Security Exposure: Every AI tool is a potential point of data exfiltration. When employees copy-paste proprietary information into external AI systems, they’re exposing that data to third parties. Even if the terms of service for AI tools state that user inputs won’t be used for model training… do we really believe them after they’ve been caught red-handed illegally consuming copyrighted materials?
- Data Issues: The holy grail of enterprise data is maintaining a single source of truth. The hallucination issues alone in LLMs should give organizations pause. Inconsistent outputs, contradictory analyses, and fragmented decision-making processes will cause long-term pain for organizations. What is your plan when your Marketing team’s AI-generated customer personas don’t align with your Sales team’s AI-generated lead scoring, which doesn’t match your support team’s AI-generated response templates?
- Regulatory and Legal Risks: AI systems can reinforce bias, generate false information, and make decisions that violate compliance requirements. When these tools operate in the shadows, organizations lose the ability to audit, explain, and defend themselves. I’m sure your legal team will be thrilled to find out your hiring process is biased against women.
Back to Basics: Risk Assessment
Too often, I find that teams aren’t performing proper risk assessment. Maybe it’s the pressure to move fast, maybe it’s the Peter Principle. Regardless, it underscores an educational gap in the business.
A proper risk assessment evaluates probability and impact across multiple dimensions: data security, regulatory compliance, operational reliability, and reputational damage. It asks hard questions about data governance, model transparency, and failure modes.
I am frequently finding myself explaining the basics of Risk Matrices to various levels of leadership. The concept is pretty simple. On one axis, you list out the likelihood of an event happening. On the other axis, you rate the impact (severity) of the event on your business. There are a few different ways people approach this, but here’s what I like to use in my workshops:

I like to put numbers in the grid because it allows us to poll the team and calculate averages to place risks in the proper cell. In general, if a risk falls into the green, it’s fine to experiment with, but it should be monitored. If it’s a yellow risk, you should involve subject matter experts and have contingency plans. In the red, I usually recommend not doing it at all or building “human in the loop” guardrails that often… don’t save any money at all.
Spoiler alert! Many AI initiatives are in the high yellows and reds.
“Ok, smart guy, that’s a cute chart, but make it real for me”. Happy to! Here are some examples of real-world risks, along with where I would plot them on the matrix.
- Legal Research: Lawyers are using AI for case research without understanding the hallucination risks. We have seen multiple examples of attorneys facing professional sanctions for submitting briefs with fabricated case citations.
As context windows (the amount of text an AI model can process at once) increase, the risk of hallucination also increases. This is particularly concerning in law, where briefs and cited cases can be very large. I rate both the probability and impact as high or very high, putting it squarely in the red. We must also consider the broader implications for society. Cases have the potential for outcomes determined by fantasy, not fact. That can range from inconvenience to life-destroying. - Financial Impacts: This category includes items such as loan approvals, applicant tracking systems, and other systems that have financial impacts on individuals and businesses. With AI tools reflecting bias, what is the risk of regulatory investigations or personal lawsuits?
- Code Generation Exposure: This is a good example of a case where it depends. If you’re vibe coding a small app that doesn’t contain any PII (personally identifiable information), medical, or financial data, the impact is on the lower side. If you’re a bank or healthcare provider, the impact can be catastrophic.
Even in cases where that type of data isn’t being handled, you still have to consider implications of customer perception, if a product is buggy or poor performing, and exposing details about your proprietary codebases to third parties. It’s likely fine if you’re building yet another chatbot, not so fine if you’re working on software that could kill people if it goes wrong, like flight control systems or medical device software. - Brand Perception: One of the harder risks to plot is how customer perception and attitudes may change based on how your business attempts to use AI. We’ve already seen some swift public backlashes against companies that attempt to displace human workers. Some of them are even rehiring after AI initiatives have failed.
It’s hard to calculate the damage done internally to morale when some executives gleefully announce layoffs. It’s easier to see damage to the brand in customer behavior, but in both cases, that trust, once lost, is very difficult to get back. As a personal example, I’d rather be homeless than work for Marc Benioff of Salesforce.
The Education Gap
You can't perform proper risk assessment if you don't understand current AI capabilities and limitations. Most leadership teams are operating with outdated mental models of what AI can and cannot do. This knowledge gap makes informed decision-making impossible.
The other reality: even when leaders understand the technology, systematic risk assessment rarely happens. The pressure to "do something with AI" overrides disciplined evaluation processes.
I previously wrote about Goodhart’s Law, which is currently being ignored by many leadership teams.
Leaders, it’s Time to Take Control
Your teams need approved alternatives, clear usage guidelines, and frameworks for evaluating new tools. They need to understand not just what they can do with AI, but what they shouldn't do and why. They also need to be taught how to run experiments effectively, how to measure the results, and when to consult a specialist.
Shadow IT emerges when official IT is unable to meet business needs. If your approved AI toolkit doesn't solve real problems your teams face, they'll find tools that do. The question is whether those solutions align with your risk tolerance and regulatory requirements.
The companies that will “win” will be those that treat AI as an engineering challenge, not a response to competitive pressure.
What’s Next?
I'm taking what I’ve learned over the last two years and developing a series of AI leadership workshops and courses specifically designed to address this challenge. Individual contributors need frameworks for evaluating AI tools responsibly. Middle management needs implementation playbooks with proper risk controls. Executive leadership requires effective strategic frameworks for AI governance.
The market has moved past the hype phase. While I personally think we’re in a bubble, I do not believe these tools are going away. So, what remains is the hard work of building AI capabilities that create ROI without exposing your organization to unnecessary risk. That starts with educated teams that understand both the technology and the stakes.