Shadow AI: The Frightening Return Of Shadow IT
Adrian Carr is CEO of global master data management provider Stibo Systems, which empowers companies through trustworthy intelligence.
gettyA decade or so ago, most large organizations had the same quiet, faintly humbling discovery. Someone in IT worked out how much of the business ran on siloed spreadsheets, databases only one person understood. What if that person left the company? We saw SaaS tools bought and never run through procurement, adopted department by department without anyone much noticing. Think vendor sprawl, fragmented data.
We gave this phenomenon a spooky name, shadow IT, and we spent several expensive years cleaning up after it.
Agentic AI is reading off the script but with a plot twist. I fear we are about to learn the same lesson, but more costly this time around.
The earlier waves of shadow IT gave way to shadow applications. This one creates something more dangerous: shadow AI.
An unmanaged spreadsheet has the decency to sit there until someone opens it. But an unmanaged agent can go fully rogue—interpret context, choose a tool, kick off a transaction, alter a record or fire off an email externally. McKinsey’s recent work on AI trust puts it well: The risk is that a system does the wrong thing and does it with total confidence.
• Creation is almost insultingly easy now: Anyone can take on a sophisticated workflow without understanding code or traditional software disciplines.
• Execution never really stops: An agent can keep running, calling other agents or tools, long after you forget it’s running.
• The blast radius is bigger: Permissions into email, CRM or ERP systems can turn mistakes into consequences that go live before you notice them.
• Behaviors change: Prompts, models and data all shift independently, which means your agent needs ongoing scrutiny.
The economics of all this do not look good. The first agent you build might be charmingly cheap. The thousandth is a genuine CFO-level problem. One business request can trigger a whole chain of token usage or other charges, scattered across accounts and providers that were never built to trace cost back to an actual business outcome.
McKinsey’s research on agentic system economics (registration required) gets straight to it: Per-token pricing doesn’t capture what companies are really paying for generative AI anymore, because cost now scales with usage and reasoning, not a fixed license fee. I suspect a fair number of finance teams will discover this the hard way. It may be several quarters after the fact, but the bills will show up and be very difficult to explain.
Shadow AI also means governance and data quality stop being two separate conversations. Applications consume data. Agents reason with it, then act on it. If your customer, product or supplier information is fragmented across the business, your agent will amplify it, at machine speed, all before lunch.
Once an agent’s decision depends on data context, the accuracy of that data becomes part of the actual decision control.
This is the practical version of something I’ve written about before as trustworthy intelligence: AI is only ever as safe, and as useful, as the governed data underneath it. And you cannot govern what you cannot see clearly.
From where I’m sitting, trusted data is the only thing that makes governing agentic AI possible at all.
To be clear, none of this is an argument for shutting AI experimentation down. Teams still need room to try things quickly, and frankly, they should be encouraged to. What I think needs to change is what happens the moment an experiment turns into a production dependency: a named owner, an approved purpose, appropriate permissions, a real data contract and an actual plan for retiring the thing once it stops earning its keep.
Every leadership conversation about AI seems to land on the same question lately: How many agents can we deploy?
I can’t help thinking that’s the wrong one. The better question, the one I’d actually want an honest answer to, is how many we can govern, support and justify economically?
Shadow IT is back from the dead, and this time it can act on its own. But shadow AI is just one part of something bigger. Beating it, and winning this next wave, comes down to whether your data and its context are trustworthy enough to prove what each agent does, what it costs, what value it creates and who is accountable when it acts.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


