Shadow adoption is the normal case
Every organisation has more AI use than it knows about, and starting from that fact produces better decisions than starting from a policy.
The pattern is consistent. A tool is useful, it is free or cheap, it needs no procurement, and it visibly makes someone's work faster. So people use it. They do not report it, not through defiance but because it does not feel like a system: it feels like a website that helps you write.
That categorisation error is the root of most of the exposure. Software gets procured, reviewed and approved. A website you type into does not trigger any of those instincts, even when what you type into it is a customer list.
The second route is quieter still. Features appear inside tools the organisation already uses. A meeting platform adds transcription and summarisation. A document editor adds drafting. A support tool adds reply generation. Nobody adopted anything, a vendor shipped an update, and data is now flowing somewhere it was not.
What follows for anyone responsible for this.
A ban does not produce zero usage. It produces unreported usage, which is the same exposure with no visibility and no ability to guide it. Organisations that banned these tools generally discovered later that use had continued on personal devices, which is strictly worse.
The productive first move is an amnesty question rather than a policy: what are people actually using, asked without blame. That produces an accurate picture, which is the precondition for any sensible decision.
And then providing an approved option that is genuinely good enough, because the demand is real and it will be met somewhere.

