An employee at a company I know has spent four months quietly building the entire accounting process in AI. On a personal account. Because the business never wrote a policy telling them not to.

It works. It's fast. It's also sitting outside every control the company thinks it has. Now that employee is staring down the day IT hands them an approved work account and asks for it all back, and nobody has a good answer for how that handoff happens, or what already left the building in the meantime.

Most enterprise leadership has heard the phrase "shadow AI." Fewer have pictured what it actually looks like. It looks exactly like this: ordinary, well-intentioned, and already four months deep before anyone in a position to notice does. The first rule of Shadow AI Club is that nobody talks about Shadow AI Club, mostly because nobody in IT knows it exists yet.

It's not a ChatGPT problem

Not because ChatGPT or Claude are inherently unsafe. Because humans are curious, and curiosity doesn't wait for a governance committee.

All it takes is one employee using a personal AI account instead of the company-approved environment. One customer list pasted in for analysis. One confidential strategy deck uploaded for a summary. One contract dropped in to "check something quickly." One spreadsheet containing commercially sensitive information. One person connecting an app, granting a permission, or experimenting with a feature they don't fully understand. And suddenly information that was protected by your corporate systems, access controls, retention policies, and governance has moved somewhere your organization doesn't control, doesn't monitor, and may not even know exists.

That's the part I think a lot of executives are underestimating. Shadow AI isn't coming. It's already sitting in another browser tab, on a device your MDM policy already covers, being used by someone who had no bad intentions at all.

Banning it won't fix it

The instinctive response is to lock it down. That doesn't work, for the same reason banning USB drives never stopped anyone from copying a file. It's Whac-A-Mole, except the mole has a personal ChatGPT Plus subscription, a strong opinion about your policy, and a new tab open before IT finishes writing the memo about the last one. The answer isn't "don't use AI." It's giving people safe, governed tools, and teaching them how to use them. AI literacy is a cybersecurity issue, not a training-module checkbox.

But literacy alone doesn't answer the harder question underneath it, the one most companies haven't sat down to answer at all:

Who at your company can shut down an AI agent that's about to do real damage? Does that person actually know it's their call?

If you can't answer that in one sentence, you don't have an AI strategy. You have an AI purchase.

Somebody already owns this. They just don't know it yet

Ask most companies who's executing their AI strategy and you'll get a shrug, or you'll get IT. Not because anyone appointed them. Because IT decides what data a model can reach, whether an agent gets write access or read-only, and whether a rollout gets adopted or quietly dies in month three. Nobody held a meeting about it. It just landed on them by default, the way most real authority does.

There's no bench for this either. Nobody has ten years of experience governing AI agents, because the tools didn't exist ten years ago. The people doing this well learned it in the last eighteen months, on live systems, with no playbook, usually because they were the ones who noticed the accounting-process problem before it became the audit-finding problem.

So stop asking whether AI is coming for IT's job. It's not. It's expanding it, fast, without asking permission. The people who move with it are about to become the most important people in the building. The ones who wait for a committee to sort it out are going to find out, the hard way, that standing still was never actually on the table. Life moves pretty fast for an AI rollout. If you don't stop and write the policy once in a while, you could miss it — and by the time you look up, the entire accounting department has been quietly rebuilt in someone's personal account.