What is shadow IT?
Technology used for work without the knowledge or approval of the organisation's IT function — personal cloud storage, unapproved apps, a departmental subscription paid on a card, a spreadsheet running a critical process, and increasingly unapproved AI tools.
Why it happens. Almost never malice. It happens because the approved tool is inadequate, slow to obtain, or does not exist — and someone with work to do found something that worked. Long procurement cycles, restrictive policies and unresponsive IT departments are the reliable causes.
Why it is a genuine problem:
Data leaves controlled environments, ending up in accounts the organisation cannot access, audit or delete — including when the employee leaves.
No security assessment. Nobody has checked the vendor's practices, breach history or data location.
Compliance exposure. Data protection obligations apply regardless of whether IT approved the tool, and the organisation remains responsible.
No backup or continuity. A process running on one person's account fails when they are unavailable.
Licensing and cost duplication, with several teams paying for overlapping tools.
Integration debt, as unofficial systems accumulate dependencies.
Why purely restrictive responses fail. Blocking tools without providing alternatives moves the activity further underground — onto personal devices and personal accounts, where visibility is zero. The organisations with the worst shadow IT problems are frequently the most restrictive, which is the finding that matters.
What actually works:
Treat it as a signal. Every instance identifies an unmet need. Ask what problem the tool solved before removing it.
Provide a fast, light approval route for low-risk tools, rather than one heavyweight process for everything.
Make the sanctioned option genuinely good. People route around friction, not around policy.
Discover rather than assume — expense data, network and cloud access logs, and simply asking teams.
Amnesty, then register. Inviting disclosure without punishment surfaces far more than auditing does.
The current urgency is unapproved AI tools, where staff paste confidential material into services with unclear retention and training terms — the fastest-growing category and the one with the least awareness.