Why Prohibition Is Not a Risk Management Strategy

In 1736, the British Parliament tried to control a growing public crisis involving gin. Consumption had increased sharply in London. Lawmakers were concerned about public drunkenness, crime, health, and social disorder. Their answer was the Gin Act of 1736, which imposed an expensive license on gin sellers.

On paper, it looked like decisive risk management. In practice, it pushed the activity underground. People did not stop drinking gin. Illegal sellers multiplied, enforcement became harder, and evasion weakened respect for the law.

The legislation was eventually replaced by a more workable approach built around licensing and practical oversight. The government did not eliminate gin; it created enough visibility and control to manage the risk.

There is a lesson here for anyone responsible for governing Artificial Intelligence inside an organization.

You may worry that employees are adopting AI faster than you can govern it, or that acknowledging the problem will expose how little visibility you have. When demand for a technology is strong, banning it rarely eliminates its use. It eliminates your visibility into its use. That is how Shadow AI grows.

What Shadow AI Actually Means

Shadow AI is the use of AI tools, models, applications, or capabilities without appropriate organizational approval, inventory, risk assessment, or oversight. The obvious example is an employee pasting company information into a personal ChatGPT, Claude, Gemini or other public AI account.

But Shadow AI is broader than chatbots. It may include:

  • Installing AI browser extensions.
  • Activating meeting transcription tools.
  • Using unapproved AI coding assistants.
  • Building applications with public AI services.
  • Enabling AI features inside existing software.
  • Purchasing personal AI subscriptions for company work.
  • Downloading local models to analyze company data.

  • A tool does not need to be intentionally hidden to qualify as Shadow AI. Sometimes employees do not realize an application contains an AI capability. In other cases, a team assumes it is approved because the company owns the software, even though the AI feature processes data differently or introduces another third party.

    That makes Shadow AI difficult to govern: you cannot assess, protect, or monitor what you do not know exists.

    The Real Question Behind Shadow AI

    When risk professionals discover employees using unapproved AI tools, management often asks:

    “How do we stop this?” That reaction is understandable, but incomplete.

    The better question is:

    “Why was it easier for this employee to use AI outside our controls than inside them?”

    Shadow AI is not simply a technology problem. It is evidence that business demand, employee behavior, management expectations, and governance are moving at different speeds. The organization wants productivity; managers want faster results; employees want tools to keep pace.

    Risk teams want visibility and control. When those objectives are misaligned, employees create their own path.

    Most Shadow AI Is Not Malicious

    Most employees using unauthorized AI are not trying to steal information or damage the company’s reputation through a leak. They are trying to get work done. That distinction matters because intent should influence your response.

    AI can summarize documents, draft messages, create presentations, analyze information, and write code in minutes. Employees see the time saved immediately, not the potential consequences. When approved tools are limited or difficult to access, the fastest option wins.

    Some Are Responding to Workplace Pressure, Others Are Just Experimenting

    An employee may hear a senior leader say: “We need everyone to start using AI.”

    A manager may expect a report in half the usual time. Colleagues may appear more productive because they already use AI. The organization encourages adoption without enough approved tools, training, or guidance. Shadow AI fills that gap.

    On the other hand, curious employees often discover useful applications before formal programs. They may test a tool to improve customer service, analyze a spreadsheet, prototype an application, or automate a repetitive process. That can create risk but also reveal legitimate opportunities.

    Treating every experiment as misconduct may drive the next one underground.

    The Risks Shadow AI Introduces

    The primary risk is not that an employee used AI. The risk is that the organization cannot determine what information was shared, how it was processed, who accessed it, or how its output influenced a decision.

    Sensitive data may be entered into a public AI model, including customer records, employee information, source code, contracts, financial data, intellectual property, credentials, or strategy.

    AI outputs may be inaccurate, incomplete, biased, or fabricated. Without review, they can influence customer communications, software changes, legal analysis, financial decisions, or business strategy. Unapproved AI agents create a deeper risk. When an AI system can retrieve documents, read email, update records, execute code, or interact with business applications, an incorrect response can become an incorrect action.

    Shadow AI also creates governance gaps. The organization may be unable to maintain an accurate inventory, complete a privacy assessment, investigate an incident, respond to an audit, meet retention requirements, or explain how an important decision was made.

    From a risk-management perspective, that absence of accountability may be more dangerous than the tool itself.

    Five Practical Ways to Counter Shadow AI

    Many organizations get stuck by creating a restrictive policy before an approved alternative. Employees are told what not to do, but not given a practical way to accomplish the work expected of them.

    The answer is not unrestricted AI use or prohibition. Make the responsible path easier than the unauthorized one.

    1. Establish Visible Executive Sponsorship

    AI governance cannot operate solely as a security or compliance initiative. Executives must communicate that the organization supports responsible AI adoption while expecting employees to follow defined safeguards. Leaders cannot demand faster AI adoption while leaving security, privacy, legal, and technology teams without authority, funding, or access to decision-makers.

    Assign an accountable executive sponsor. Define the organization’s AI risk appetite. Clarify ownership across security, privacy, legal, procurement, architecture, and business adoption.

    2. Make the Approved Path Faster

    Employees will bypass a process that cannot keep pace with the business.

    Create a simple intake process separating low-, moderate-, and high-risk use cases. Drafting an agenda should not require the same review as connecting an autonomous agent to a financial system. Provide approved tools, controlled experimentation environments, reusable requirements, and clear turnaround times.

    Consider a temporary disclosure period that lets employees report tools already in use without automatic disciplinary action. The immediate goal is visibility.

    3. Deploy the Right Visibility and Protection Tools

    Policy alone cannot manage Shadow AI.

    Organizations need visibility across browsers, endpoints, networks, cloud environments, software repositories, identity systems, and enterprise applications. This may include secure web gateways, endpoint telemetry, SaaS discovery, data-loss prevention, AI gateways, and API monitoring.

    The objective is not employee surveillance. It is to identify which tools are being used, what data may be leaving the organization, and where intervention is required.

    4. Communicate Across the Enterprise

    Effective communication turns annual training into daily guidance.

    Employees need answers:


    Make guidance specific to each role. A developer needs different examples from a recruiter, financial analyst, or marketing employee. Employees are more likely to disclose experimentation when they believe the organization will help them use AI safely rather than punish them.

    5. Create Tight and Ongoing Governance

    AI governance must balance innovation with risk management. It cannot be a committee that meets once a quarter to review slides. It must operate continuously.

    Maintain an inventory of tools, models, vendors, agents, integrations, business owners, and use cases. Assign risk levels, record decisions, and reassess tools when vendors change models, terms, data practices, or capabilities.

    Monitor actual usage rather than relying only on initial approval. Define AI incident-response procedures, conduct periodic testing, and track unauthorized tool detections, review turnaround times, employee disclosures, and repeated policy violations.

    Governance must create a feedback loop. When the same unauthorized use appears repeatedly, the answer may not be stronger enforcement. Employees may have identified a legitimate need that the approved environment does not address.

    Why This Matters Right Now

    Shadow AI will not disappear because you publish an organization-wide policy. The tools are too accessible, productivity benefits too visible, and pressure to adopt AI too strong. Organizations that manage this well will not have the strictest bans. They will create the clearest path from experimentation to responsible adoption.

    The gin crisis offers a useful warning: when controls are detached from reality, activity moves underground. When governance creates visibility, workable boundaries, and accountability, risk becomes manageable.

    Shadow AI is not proof that employees cannot be trusted. It is evidence that organizational demand has moved faster than organizational control. Your role in risk management is to understand that demand and direct it safely.

    About the Author

    Aby Rao is a cybersecurity and risk management leader with two decades of experience in the American workforce, including roles with Fortune 500 companies and high-growth technology organizations. He hopes to make AI and cybersecurity conversations more practical, accessible, and useful for business decision-makers through his writing, speaking, and community engagement.

    References:

    Krantz, T., Jonker, A., & McGrath, A. (2024, October 25). Shadow AI. Ibm.Com. https://www.ibm.com/think/topics/shadow-ai

    The Gin Craze | Health and the People: The History of Medicine in Britain. (2026). Ncl.Ac.Uk. https://healthandthepeople.ncl.ac.uk/renaissance-medicine/the-gin-craze/