The Shadow AI on Your Balance Sheet
In most regulated institutions, AI is already running that no one approved. Not in a pilot, not in a sandbox, but on real work, quietly, wherever the official path is slower than the pressure to use it. It is not in the model risk inventory. It has no owner, no lineage, no sign-off. And the wider the gap between what people need and what the governed path allows, the more of it there is.
Shadow AI is not unique to regulated finance. Every industry has it. The difference is that in a regulated institution it is not an inconvenience, it is a liability with a regulator attached.
This is the part of the AI conversation most boards are not having, because the metrics they watch cannot see it.
The stall does not reduce risk. It moves it.
Start with what happens when the official path stalls. Budgets come as pilots, the operating model cannot carry them to production, and the control function, doing its job, says not yet. The work does not stop. People still have targets. So the analyst opens a chat window, pastes in the client note, and asks for the summary. The associate drafts the credit memo with a model the bank never reviewed. The output is correct often enough to be trusted and wrong often enough to be dangerous, and none of it is logged anywhere the bank can see.
Governance that only knows how to say no does not lower AI risk. It relocates it, from a place you can supervise to a place you cannot. The tighter the front door, the busier the back door.
Why this is worse than the last time
We have seen this movie. The last operational-risk era ran on spreadsheets: critical processes built by individuals, outside the controlled estate, until a formula error moved a number that mattered. The industry spent a decade and a fortune bringing end-user computing under control.
Shadow AI is the same failure, and worse on every axis that matters.
A rogue spreadsheet left a file. You could find it, open it, trace the formula, and fix it. Shadow AI leaves nothing. The reasoning happens in a session that is never saved, the answer is pasted into an email, and the prompt, the model, and the data that produced it are gone. You cannot audit what left no artifact.
A spreadsheet was deterministic. The same inputs gave the same output, so you could reproduce it and test it. A shadow model is probabilistic. You cannot re-run last Tuesday's answer, because last Tuesday's answer no longer exists.
And a spreadsheet was built by the person who owned the process. Shadow AI is built by anyone, in seconds, including people who have never sat through a single hour of risk training.
You cannot scan your way out
The instinct is to treat this like the spreadsheet problem: scan the estate, find the artifacts, bring them under control. It will not get you far, because much of this does not live in your estate. It lives in a browser tab signed into a personal account, in a phone in someone's hand, in a consumer tool your perimeter never touches. Your data controls do not see a prompt typed into a device you do not own. The thing you most need to find is the thing your controls are least able to see.
The control that actually works
Here is the part that is hard for a control culture to accept. You rarely ban your way out of shadow AI. Prohibition does not remove the demand, it removes the supervision, and that is what pushes the work into the shadow in the first place.
The only control that works is a governed path good enough that the shadow path is not worth it. Governance has to compete with the shadow, not just outlaw it. If the sanctioned tool is slower, narrower, and three approvals away, people will route around it, and they will be right to, because their job is the work, not the policy. Make the governed path the fastest path and the shadow shrinks on its own. That is not a softening of control. It is the only version of control that survives contact with how people actually work.
What the board should ask
Most board questions about AI measure the visible estate. Are the pilots safe. Is the model inventory current. Did the high-risk use cases get reviewed. All necessary, all blind to the real exposure.
The question that surfaces the exposure is the uncomfortable one: where is AI already running in this institution that we did not authorize, and what would it cost us if it was wrong. The honest first answer is that no one knows, and that not knowing is itself the finding.
The institutions that handle AI well will not be the ones that kept it out the longest. They will be the ones that made the safe path the fast path, and pulled the work back into the light before it cost them.
If you carry risk in a regulated institution: do you know where AI is already running in your organization, or only where you allowed it?