By Bala Mathivanan · July 2026 · Based on delivering company-wide AI adoption and governance programmes inside regulated, export-sensitive environments.
Here's the uncomfortable starting point: if your business has more than a handful of staff, some of them are already using AI at work. Personal ChatGPT accounts, browser extensions, free summarisers — pasting in customer emails, price lists, maybe worse. Not maliciously. They're just trying to get through the day faster, and the tools are genuinely useful.
That's shadow AI: real usage, zero governance. And in a regulated or export-sensitive business — where a pasted drawing or specification can be a compliance breach, not just a data leak — it's not a theoretical risk.
The reflex response is a policy memo: AI tools are prohibited. Two things happen. First, usage doesn't stop — it moves to personal phones, where you have even less visibility. Second, you've now positioned the business as the obstacle, so nobody will tell you what they're using, which is the one thing you needed to know.
A ban converts a visibility problem into a trust problem. You had one problem; now you have two.
1. Find out what's really in use. Before policy, inventory. Network and endpoint visibility will show you the AI services being reached; honest conversations will show you why. The "why" is gold — it's a free map of where your processes are too slow.
2. Give people a sanctioned tool that's actually good. Shadow AI thrives when the official option is nothing. Rolling out something like Microsoft 365 Copilot — inside your tenant, covered by your existing data protections, with your access controls — removes the reason to go around you. The sanctioned tool has to be genuinely useful, or the shadow usage continues.
3. Write the policy people can follow. One page beats twenty. What data can go into which tools; what never leaves the tenant; what needs sign-off. Tie it to data classifications staff already understand, not abstract AI categories.
4. Put the guardrails in the infrastructure, not the memo. Access controls, data loss prevention, app control on the endpoints — the same zero-trust building blocks that protect everything else. Policy tells people what right looks like; the infrastructure makes wrong difficult.
5. Train with real work, not slideware. The training that lands is "here is how to draft a quotation follow-up in your actual job", not "an introduction to large language models". Adoption follows usefulness.
We've run this sequence in production inside regulated, export-sensitive environments — where a pasted document can be a compliance breach, not just an embarrassment. Governance in place first, tooling live and used by staff daily, safely. The lesson that surprises people: governance done properly accelerated adoption, because staff who know where the lines are stop hesitating a metre before them.
Not "should we allow AI?" — that decision was made for you the day your staff got smartphones. The real question: do you know what's in use today, and does anyone own the answer? If not, that's the first fix, and it costs a conversation, not a platform.