Shadow AI is a Cultural Debt, Not a Technical Vulnerability
David Moskowitz – Founder Member and Chief Content Architect, at the DVMS Institute
The risk is not that an employee used AI.
The risk is that someone used AI to shape a significant outcome without authority, evidence, review, assurance, or accountability.
When that outcome fails, the organization cannot reconstruct the path. Where did the failure originate:
- Tool output?
- Employee’s interpretation?
- The prompt used?
- The decision context?
- A step nobody flagged as a decision at all?
Those questions do not describe a tool-discovery problem. They describe a governance problem for AI-shaped outcomes. That distinction matters because many organizations treat Shadow AI as if it were the next version of Shadow IT. That framing helps, but only to a point.
The End of the “Scan-and-Discover” Era
Discovery tools within IT configuration management were built on a simple premise: technology leaves a discoverable footprint. Configuration teams inventoried known assets, scanned installed software, and identified network-connected devices.
Automated discovery tools revealed Shadow IT because unmanaged hardware and software were still visible. But the scan-and-discover model only works if the “stuff” exists as an asset, an installation, or an observable service.
Cloud services and SaaS platforms strained that model; AI breaks it entirely.
An employee may use an approved browser to reach an AI service, create prompts, submit data, interpret outputs, test alternatives, and act. Technical telemetry (DNS records, proxy logs, endpoint telemetry) may show that access occurred, but it leaves the cognitive interaction chain entirely unrecorded.
A browser session may leave telemetry, but telemetry is not the same as a governance record.
Detection might surface traces of use, but it does not establish the authority, evidence, review, or assurance needed to govern how people use the AI.
The Cognitive Shift: Shadow IT vs. Shadow AI
Shadow IT spread because employees adopted unauthorized tools to solve problems faster than official channels allowed. Shadow AI follows the same logic, but moves faster. Shadow AI may:
- require no installation
- cost nothing
- fall below procurement thresholds
- shift the cost to the employee instead of the company
- require no provisioning workflow beyond an approved browser window
People using Shadow AI typically do not see themselves as policy actors. They focus on meeting objectives. They measure success by results, not compliance. When policies appear to obstruct effectiveness, people do the same things they’d do in a policy vacuum: they find workarounds. These people use AI to gain cognitive agency.
Absence of policy is not neutrality. It is distributed permission without accountability.
Diagnosing the Governance Gap: The DVMS 3D Knowledge Model
To understand why employees bypass formal controls, look beyond technical telemetry and examine the organizational system itself. That takes two lenses: how information and alignment move through the organization, and how its structure and leadership behave once that information arrives. The DVMS 3D Knowledge Model gives us both. It breaks down like this:
- Perspective 1 (Information & Alignment): Maps how knowledge flows across time (intra-team), how teams collaborate across dependencies (inter-team), and how closely daily work aligns with the organizational strategic and operational intent.
- Perspective 2 (Structure & Behavior): Maps the physical reality of the system, the behaviors of the teams, their structural patterns of interaction, and the leadership that enables (or inhibits) them.
Perspective 1: The Information & Alignment Gap (Why Shadow AI Happens)
When we analyze the organization through the lens of Perspective 1, we can see that Shadow AI is not a technical failure, but the direct result of a fractured information system across three axes:
- The Z-Axis (Strategic & Operational Alignment): If leadership issues a blanket AI ban without communicating why or outlining a safe path forward, alignment breaks. Because employees do not understand the strategic intent, they bypass the policy to achieve their immediate operational goals.
- The Y-Axis (Inter-Team Collaboration): When IT, Security, and business units operate in silos, they fail to understand their mutual dependencies. IT doesn’t realize that blocking a browser-based AI tool halts a critical business process, and the business team doesn’t realize the massive data risks they are introducing.
- The X-Axis (Intra-Team Knowledge): To avoid penalties, teams conceal their AI usage. As a result, the team’s past, present, and future use of the technology remains a localized secret. The organization loses its collective memory, meaning it never learns from critical errors or scales brilliant efficiencies.
Perspective 2: The Structural & Behavioral System (How Culture Is Enforced)
If Perspective 1 shows us where the alignment breaks, Perspective 2 shows us how the physical organizational structure and leadership style dictate the response. Perspective 2 reapplies the same three-axis structure, X, Y, and Z, to a different layer of the organization: not what moves through it, but how it behaves once that information arrives.
By looking at Team Behaviors (X-Axis), Patterns of Interaction (Y-Axis), and Leadership (Z-Axis), we can map the DVMS model directly to Ron Westrum’s three organizational typologies[i].
- The Pathological System: Leadership (Z-Axis) is power-oriented and relies on blame and punishment. The organizational structure (Y-Axis) is fragmented and hostile. Consequently, employee behavior (X-Axis) defaults to fear and active concealment. Shadow AI goes entirely underground.
- The Bureaucratic System: Leadership is rule-oriented, relying on rigid standard operating procedures. Cross-functional interaction is slow. Committees, required meetings, and a lack of empowerment bog it down. Employees behave by treating policy as a boundary to manage around rather than a standard to uphold. Compliance is superficial. The real work happens in the shadows.
- The Generative System: Leadership is performance-oriented, focusing on enabling the mission. Interdisciplinary teams collaborate dynamically. Because the culture dictates that failure leads to inquiry rather than blame, employee behavior defaults to blameless disclosure.
When the LL Hallucinates
Imagine a scenario: A mid-level analyst faces a brutal Friday afternoon deadline to synthesize a 100-page market research report. Desperate for speed, they copy-paste the raw text into a browser-based, unauthorized LLM and request a summary of competitor vulnerabilities.
The AI presents a high-confidence hallucination and “documents” a competitor vulnerability that does not exist. The analyst builds a strategic recommendation around this “finding,” presents it to leadership, and the company acts on it, only to discover the error weeks later when a major deal falls through.
How does your organization react to this failure?
In a Pathological culture, the reflex is punitive. Leadership singles out the analyst, reprimands them, or fires them for violating the corporate “No unauthorized AI” policy. The message to the rest of the company is clear: If you use AI to help you work, keep it a secret at all costs.
In a Bureaucratic culture, the incident triggers administrative overhead. Leadership forms a new committee, updates the 50-page security handbook with more restrictive rules, orders IT to block another dozen AI domains, and protects the policy. The underlying productivity gap that drove the analyst to AI in the first place goes untouched.
A Generative culture, however, aligns with Westrum’s most vital principle: Failure leads to inquiry.
Instead of scapegoating the analyst, a generative organization treats the incident as a systemic learning opportunity. The post-mortem doesn’t ask “who” questions (finger-pointing, blame-based); instead, it asks why and how to improve:
- What productivity bottleneck made the analyst feel they had no choice but to bypass official tools?
- How can we better educate our teams on the nature of LLM hallucinations and how to cross-reference AI-generated facts?
- How do we make our official, sandboxed AI environments easy enough to use that employees don’t feel the need to go “shadow”?
By removing the fear of retribution, the analyst is free to share their process openly. The organization gains a deep, invaluable understanding of how its people are using AI to solve real-world problems. By embracing the failure as an inquiry, you don’t just patch a security hole. You build a highly resilient, cognitive workforce.
Building a Culture of Assured Disclosure
Mechanisms alone do not create a healthy culture. Governance still needs them, but only culture determines whether they work. Organizations need:
- Policy Clarity: Defining what is authorized, what requires review, and what is prohibited.
- Decision Authority Mapping: Establishing where AI may support a decision and where human authorization must occur.
- Evidence Requirements: Defining what people must retain when AI influences a consequential outcome.
An amnesty path that gives employees a way to surface existing Shadow AI use only works if the culture is Generative. In a Pathological culture, employees will never trust it. Without credible assurance that disclosure will lead to review rather than individual blame, amnesty is just another policy artifact.
The organizations best positioned to govern Shadow AI are not those with the most sophisticated network detection capabilities. They are those where the culture made disclosure normal before the problem arrived.
Even if detection finds signals, culture determines whether people surface, review, and assure what those signals actually mean.
[i] Westrum, R. (2004). A typology of organisational cultures. Quality and Safety in Health Care, 13(Suppl 2), ii22–ii27. https://doi.org/10.1136/qshc.2003.009522
About the Author

David Moskowitz – Founding Member and Chief Content Architect, at the DVMS Institute
David is a Founding Member and Executive Director of the DVMS Institute LLC. He is the lead author of the “Digital Value Management System®” publication series which include the *Fundamentals of Adopting the NIST Cybersecurity Framework* and *A Practitioner’s Guide to Adapting the NIST Cybersecurity Framework*, and Thriving on the Edge of Chaos published by TSO
Digital Value Management System® is a registered trademark of the DVMS Institute LLC.
® DVMS Institute 2026 All Rights Reserved


