Shiny Moose logo Shiny Moose

AI Governance Report

The Shadow AI Economy Inside Your Company

Employees already adopted AI. Governance hasn't caught up — and somebody's going to feel the token burn.

August 2026  ·  7 min read  ·  AI Governance & Compliance

Nobody rolled out AI at your company. It just showed up — in a browser tab, a Chrome extension, a personal account someone signed up for on a Tuesday because it was faster than waiting for IT. That's not a rollout problem. That's shadow IT wearing a new coat, and it's already inside the building.

01
Shadow AI

It's Not "If" Employees Use Unapproved AI — It's How Much

Shadow IT used to mean an unsanctioned Dropbox folder or a personal Gmail account. Today it means AI. UpGuard's 2025 State of Shadow AI research found that 8 in 10 employees are using AI tools their IT department never approved of — and that 98% of organizations have unsanctioned AI use somewhere inside them.

PagerDuty's 2026 workplace survey put hard numbers behind the trend: two-thirds of office professionals admit to using unauthorized AI tools at work. It isn't confined to the rank and file, either — UpGuard found 68% of security leaders, including CISOs, use unsanctioned AI in their own daily workflow.

What to do Assume shadow AI is already running in every department, then go find out where. You can't govern what you can't see.
02
Data Exposure

Compliance Doesn't Pause for Convenience

Every unmanaged AI tool is a new, unmonitored exit door for company data. A National Cybersecurity Alliance survey found that 43% of AI users admit to sharing sensitive company information with an AI tool without their employer's knowledge — contracts, source code, customer records, unreleased financials, pasted in for a quick summary or rewrite.

For regulated industries, that's not just a security incident waiting to happen — it's a GDPR, HIPAA, or PCI violation with your company's name on it, discovered the same way most compliance failures are: after the fact.

What to do Treat AI tools like any other data processor. If it touches regulated data, it needs a contract, a data-handling review, and a paper trail — not a browser extension someone installed on their own.
03
Training Gap

Awareness Training Alone Won't Close the Gap

It's tempting to treat this as an education problem — teach people the risks and behavior will follow. The data says otherwise: 40% of employees report they've received AI safety training and better understand the risks, and they're also among the heaviest users of unapproved tools.

Knowing the rules and having a faster way to hit a deadline are two different forces, and the deadline usually wins. Training raises awareness; it doesn't remove temptation, and it doesn't stop at security leadership either.

What to do Pair training with technical guardrails — approved tool lists, data-loss prevention, and monitoring — so good judgment isn't the only line of defense.
04
New Architecture

The New Shape of Workplace AI: 80% Local, 20% Frontier

The instinct in 2023 was to route every request to the biggest, most expensive public model available. That instinct is expensive, and increasingly unnecessary. In the deployments we're seeing across clients today, roughly 80% of day-to-day AI workload — drafting, summarizing, internal search, routine analysis — runs just fine on smaller, open-weight models hosted on infrastructure the company actually controls. The remaining 20%, the genuinely hard or high-stakes work, still gets routed to a frontier public model, deliberately and at a known cost.

80% Local Models
20% Frontier / Public
Where the typical day's AI workload actually runs, once it's architected on purpose

The payoff isn't just cost, though local inference commonly runs 60–80% cheaper than pure per-token cloud pricing at real usage volumes. It's also that sensitive data never has to leave a network you control, and it's a compliance story you can actually document.

What to do Route by task, not by habit. Most work doesn't need a frontier model — and every request that doesn't need one is a request you're overpaying and over-exposing on.
05
Guardrails

Guardrails Aren't Optional Anymore

Regulators stopped waiting. The EU AI Act is already phasing in obligations for employers, Colorado's AI Act sets requirements for high-risk automated decisions, and New York City's Local Law 144 requires bias audits for AI used in hiring. "We didn't have a policy yet" is rapidly becoming a legal liability, not a neutral default.

A governance program that arrives after the incident is a postmortem, not a guardrail. The businesses that get ahead of this are writing the policy, the approved-tool list, and the audit trail before regulators or a breach force the issue.

What to do Stand up an AI usage policy, an approved-tool catalog, and logging before you're doing it under a deadline set by a regulator or an incident.

The Bottom Line

Your employees aren't waiting for permission, and your AI bill doesn't know the difference between a Slack reply and a contract review. If every request defaults to the most expensive model available, you're not just exposed on compliance — you're feeling the token burn every single month, on tasks that never needed it.

Shiny Moose
Stop Feeling the Token Burn Free AI Governance Assessment · No commitment