Field Guide · Data governance
Shadow AI Is Already Your Operating Model
Staff and faculty are already using AI to survive their workloads. The question is whether the institution can turn hidden improvisation into responsible capacity.
The AI you did not approve is already doing real work on your campus. The question is not how to stop it. It is what to do now that it is here.
Ask the CIO how many AI tools the institution uses, and you may get a short, confident answer. One, maybe two, both under contract. Ask the staff the same question anonymously, and the number is not close.
A financial aid counselor is pasting dense award letters into a chatbot to rewrite them in plain language, because the template was written in 2014 and families call confused. An advisor is using one to draft outreach to students who have gone quiet. A department coordinator is summarizing meeting notes, a grant writer is tightening a narrative, an admissions counselor is generating first drafts of a dozen personalized emails before lunch. None of them filed a request. Most of them would be surprised to learn there was a request to file.
This is not a fringe behavior at the edge of the institution. For a meaningful share of the daily work, it is the operating model. It just is not written down anywhere, which means no one is governing the part of the institution that is changing fastest.
The institutional question
The reflex is to ask how to stop it. That is the wrong question, and chasing it tends to make things worse.
The better question is what to do with the AI use that is already happening. People are not reaching for these tools to be reckless. They are reaching for them to survive a workload that has been growing for years while headcount has not. Treat that as a discipline problem and you will spend your energy fighting the symptom while the cause keeps generating new cases. The useful work is turning that hidden improvisation into something the institution can actually stand behind.
What this looks like in practice
Start with what the real risk is, because it is easy to aim at the wrong one. The risk is rarely that a staff member used AI to rewrite a letter. The risk is what they pasted in to do it. A free consumer tool, used through a personal account, with no agreement governing what happens to the input, is a place institutional data can quietly leave the institution. The productivity is not the exposure. The data is.
Which leads to the part most institutions skip. You cannot expect people to make good decisions about data they have never been taught to classify. If no one has said, in plain terms, that a student’s record is one thing and a public course description is another, then every employee is improvising their own sensitivity tiers under deadline pressure. Good judgment about data requires that someone first defined the categories. Most have not.
The fix here is not a forty-page taxonomy, which would land exactly like the policy nobody read. It is a bright line simple enough to survive a busy Tuesday. Something close to “nothing above public goes into a tool the institution has not approved” does more real protection than an elaborate scheme that no one can recall at the moment of decision. Memorable beats comprehensive when the rule has to work in the wild.
It is also worth remembering that shadow AI is not only the tools people went out and found. It is the AI features quietly switched on inside the systems you already pay for. The note-taker in the meeting platform, the writing assistant in the productivity suite, the predictive features in the CRM. Those arrived without an evaluation too, and they often touch institutional data by default. The shadow extends into software you already own.
All of this comes down to one strategic fork. An institution can treat shadow AI as something to detect and punish, or as something to absorb and support. The punitive path feels responsible and performs poorly, because banning a tool people rely on to get through the day does not end the use. It drives it further underground, onto personal devices and personal accounts, exactly where you have the least visibility. The durable move is to give people a sanctioned path that is good enough that improvising is no longer worth it: an approved tool, clear rules about what data it can touch, and the training to use it well.
There is a reframe in here that is easy to miss. Shadow AI is not only a risk. It is a free, real-time map of where the workload has become unbearable and where the official tools are failing the people using them. The financial aid counselor rewriting that letter is telling you the letter template is broken. Read the pattern of unsanctioned use and it will show you, more honestly than most surveys, where the institution should invest next.
The Atlas connection
In Atlas, our AI operating map, this is the data governance domain, in the Defense group — and it is where Protect stops being abstract. It runs directly into policy and acceptable use, because the policy is what tells people which data can go where, and into security and risk, because data leakage is the exposure underneath the convenience. It also depends on governance and org structure, over in Foundation, since someone needs the authority to approve the sanctioned alternative quickly enough to matter. Shadow AI is the place where weak governance, vague policy, and slow decisions all show up at once, wearing the disguise of a productivity win.
Questions worth putting on the agenda
A useful starting point is to assume the shadow exists and find out its actual shape.
- Have we actually audited what AI tools are in use here, including personal accounts, browser extensions, and the AI features already turned on inside our existing systems?
- Have we classified our data clearly enough that an employee knows, without asking, what is safe to put into an AI tool?
- Do we have a bright-line rule simple enough to remember, or only a taxonomy no one will read in the moment?
- Is our current approach punitive or culture-driven, and which one is actually lowering our risk?
- What approved, governed alternative could we offer so people no longer have to improvise with their own accounts?
The bottom line
Shadow AI is not the exception to your AI strategy. For a real part of the institution, right now, it is the AI strategy. The work is not to pretend it away or to stamp it out. It is to bring it into the light, give it rules people can follow, and offer a path safe enough that the improvising stops on its own.
You can read the unsanctioned use as a confession to punish or as a map to follow. Only one of those makes the institution safer.
Also published on LinkedIn: read this guide on the newsletter .