by Jelena Relić
How to avoid common HRIS implementation mistakes
I have seen organizations invest heavily in a new HRIS and still struggle six months later. The system is live. The contract is signed. The dashboards...
Your company probably uses more AI than its official software list suggests.
You can name the tools the company purchased: perhaps an approved assistant, a coding tool, and several integrations. The list feels complete because each product passed through a purchasing process and appears on a monthly invoice.
Actual usage is rarely so orderly.
An employee may activate an AI feature inside an existing CRM. A contractor may process company files through a personal AI account. Someone may build a small automation with a personal API key and gradually turn it into part of a weekly reporting process.
Many activities remain absent from procurement records, invoices, and formal software inventories. Together, they create shadow AI: the gap between the AI systems a company officially manages and the systems already shaping how work gets done.
Personal chatbot accounts represent one common source of shadow AI, covered separately in our guide to Bring Your Own AI. The broader management problem begins when any form of AI use becomes invisible to company leadership, leaving founders with unreliable adoption data, unowned workflows, and an incomplete view of team capacity.
Shadow AI refers to AI tools, features, models, or workflows used for company work without adequate visibility, approval, ownership, or oversight.
Common examples include:
Shadow AI extends beyond unauthorized software. An approved product can still become part of the shadow AI environment when the company cannot see which features employees use, what data enters the system, who owns the resulting work, or which processes depend on the output.
The tools a company approves and pays for rarely match the full set of AI systems supporting daily work.
Several common situations create the gap:
Shadow AI usually develops through informal adoption rather than deliberate concealment. Employees find useful capabilities, add them to existing workflows, and continue working without documenting which tools were introduced or how the process changed.
Across a company of 30 or 50 employees, small individual decisions can create a substantial difference between the official AI inventory and actual usage. Leadership may believe the company uses two or three AI products while employees, contractors, embedded features, and automations interact with many more.
Employees usually adopt unapproved AI tools because the products solve immediate work problems.
Several conditions make informal adoption more likely.
Employees may identify useful AI applications before leadership selects an official platform. Work continues during procurement and evaluation, so employees choose tools independently.
A general assistant may support basic writing and research while providing limited value to developers, designers, recruiters, analysts, or finance teams. Specialized products can offer stronger capabilities for specific tasks.
Employees may not know:
Without a shared standard, each employee develops an individual interpretation of acceptable use.
A low-cost AI subscription may require several weeks of security, legal, procurement, and management review. Employees facing immediate deadlines may choose the faster route and open personal accounts.
Employees may activate an AI feature without recognizing the feature as a separate technology decision. No new contract or application appears, even though the feature may introduce another model, data processor, or external service.
Leadership may encourage employees to use AI and work more efficiently without providing approved tools, training, access rules, or data boundaries.
Employees receive a productivity target without receiving a safe operating framework.
Security discussions often frame shadow AI as a data-protection problem for IT and cybersecurity teams.
Founders face a wider business problem.
A company can avoid a security incident for an entire year and still make worse decisions because leadership cannot see how AI supports daily work. Incomplete information can lead to unnecessary hiring, unsuitable software renewals, poorly allocated training budgets, and workload plans based on an inaccurate view of team capacity.
Shadow AI affects the information founders use to make decisions about:
A security-first view asks whether sensitive information could leak. A management view also asks whether leadership understands the tools, workflows, costs, and dependencies already operating inside the company.
Shadow AI creates exposure through personal accounts, contractor systems, embedded features, API connections, and undocumented automations.
A 2026 survey of more than 650 senior cybersecurity leaders found that 90% believed their organizations had visibility into their AI footprint, while 59% confirmed or suspected the presence of shadow AI. The findings reveal a significant gap between leadership confidence and operational visibility.
A contractor, employee, or agency may process company information through an AI system that leadership never selected or reviewed.
The information could include:
Without a complete tool inventory, the company cannot confirm where the information is processed, how long it is retained, or which external parties can access it.
Customer agreements may restrict which third parties can process customer data. Privacy obligations, confidentiality clauses, data residency requirements, and industry regulations may impose additional restrictions.
A company cannot confirm compliance without knowing which AI systems interact with protected information.
Source code, product plans, designs, pricing strategies, research, internal methods, and proprietary prompts may enter embedded AI features or contractor-controlled accounts without any formal record.
The absence of a clear record makes ownership, confidentiality, and recovery harder to manage.
AI-generated work can contain incorrect claims, fabricated references, insecure code, biased recommendations, and missing context.
Undocumented AI use also makes human review inconsistent. Managers may not know which work requires verification because the use of AI was never disclosed.
AI access may exist through personal accounts, API keys, browser extensions, or embedded features rather than through a named company application.
Standard offboarding processes can therefore miss:
An employee may retain access to company information or workflows after changing roles or leaving.
AI expenses can appear across:
Small individual charges can accumulate into a material spending category without giving leadership a reliable picture of total cost or value.
A useful shortcut can gradually become critical infrastructure.
An employee may begin with one prompt for a weekly task, then add files, templates, instructions, integrations, and automation steps. Other employees begin relying on the output, while the entire process remains tied to one account or API key.
The dependency may remain hidden until the employee changes roles, the account closes, the vendor changes its pricing, or the tool removes an important feature.
At that point, the company discovers that a real business process has no formal owner, documentation, or recovery plan.
Usage reports become unreliable when part of a team’s AI activity occurs outside visible systems.
Suppose a company purchases 100 seats for an approved AI assistant, but only 30 employees use the platform regularly. Leadership may conclude that AI adoption is low.
The real explanation may be different:
Licenses, logins, workflow adoption, and business impact measure different things.
| Measurement | What It Actually Shows |
|---|---|
| Licenses assigned | How many employees could use the approved tool |
| Active users | How many employees used the approved tool during a defined period |
| Usage frequency | How often employees interact with the tool |
| Workflow adoption | Whether AI supports a recurring work process |
| Business impact | Whether AI changes speed, quality, cost, or team capacity |
Shadow AI creates disagreement between the measurements because some activity never enters the official reporting system.
An employee-built AI process can work reliably for months without appearing in any formal system.
The process may exist inside:
Other employees may depend on the output without understanding how the process works.
A conventional software failure usually triggers an immediate response because the company knows which product failed and who owns it. An unowned AI workflow can operate quietly until access disappears. Recovery becomes difficult because nobody documented the configuration, prompts, data sources, or reason behind each decision.
Founders need to identify AI-supported workflows before employee departure, vendor changes, or account closures expose the dependency.
AI can reshape a role long before anyone updates the job description.
A marketer may turn one research project into five content formats instead of one. A developer may automate part of testing that previously required a full day. An operations employee may remove several manual steps from a weekly process.
The title and organizational chart remain unchanged while the employee’s actual capacity increases.
The hidden change matters during hiring and workload planning. A team may already have enough capacity to absorb additional work. Another team may appear efficient while depending on a fragile workflow that cannot survive the departure of one employee.
Consider two five-person teams performing similar work. One team has integrated AI into half of its recurring tasks, while the other still completes every task manually. The organizational chart presents identical team sizes, but the two teams have different capacity, skill requirements, and hiring needs.
Founders cannot plan accurately without seeing how AI already changes the work behind each role.
Shadow AI usually appears through operational patterns rather than a single obvious incident.
A team completes more work, but no new hire, software rollout, or process redesign explains the increase. Individual AI workflows may account for part of the change.
Employees produce work faster, but usage data from the official platform remains low. Other AI products, embedded features, or personal accounts may support the improvement.
A manager provides a vague or incomplete answer when asked which AI products support daily work. The uncertainty suggests that no complete inventory exists.
Small charges appear across expense reports, department cards, API invoices, and contractor costs rather than one predictable budget category.
The company removes access to email, HR software, and project systems, while AI accounts, API keys, custom assistants, and automations remain outside the checklist.
A recurring process slows down or stops when one person is unavailable because only that employee owns or understands the supporting AI workflow.
Each signal can have an ordinary explanation. Several signals appearing together usually indicate that AI adoption has developed faster than company oversight.
A company needs organizational and technical discovery methods. No single system will identify every tool, feature, account, or workflow.
Start with direct questions:
The review should focus on understanding real workflows rather than identifying employees for punishment. Employees provide more accurate information when valuable use cases can be formalized instead of automatically prohibited.
Search employee reimbursements, department cards, SaaS subscriptions, API charges, contractor invoices, and software add-ons.
Financial records will not reveal free accounts, but they can uncover products that never entered the official software inventory.
Single sign-on data, OAuth connections, browser records, and identity systems may reveal external AI applications accessed with company credentials.
Review AI functions inside CRM platforms, meeting tools, design software, development environments, HR systems, customer support platforms, analytics products, and productivity suites.
Employees may not consider an embedded feature a separate AI tool.
Larger organizations may supplement employee reporting with:
Technical discovery can reveal access to known services, but technical data cannot fully explain the business purpose, value, or operational dependency behind each tool.
Ask contractors, agencies, and service providers which AI systems they use when handling company information or producing important work.
The review should cover data handling, retention, human review, subprocessors, account ownership, and access removal after the engagement ends.
A complete ban usually reduces reporting without eliminating useful AI activity. A stronger process identifies current use, formalizes valuable workflows, and removes unacceptable risks.
Record:
A spreadsheet can support the first review. Growing adoption eventually requires a system that remains current as tools, employees, permissions, and workflows change.
| Decision | When It Applies |
| Keep and formalize | The tool provides clear value and presents an acceptable level of risk. Move the work to a company-owned account, assign an owner, and document the process. |
| Review further | The tool appears useful, but questions remain about data handling, ownership, cost, output quality, or vendor terms. |
| Replace | An approved product provides similar capabilities with stronger ownership, access control, data handling, or cost management. |
| Stop | The tool creates unacceptable risk, conflicts with company obligations, or duplicates an existing product without providing enough value. |
Approval should cover the use case as well as the product. A chatbot approved for public research may remain unsuitable for contracts, employee health information, credentials, or confidential source code.
Prioritize processes involving:
Company ownership improves continuity, billing visibility, access removal, configuration control, and recovery.
Each important tool and workflow needs someone responsible for access, cost, configuration, documentation, data handling, output review, renewal decisions, and periodic reassessment.
The first employee to discover a tool should not become its permanent administrator by default.
Developers, marketers, managers, HR employees, interns, and contractors require different tools, capabilities, data access, and spending limits.
Our guide to AI Access Management explains how permissions can follow employees as they join, change roles, move teams, or leave the company.
A written policy becomes useful only when the approved tool list reflects the products employees actually use.
The AI Policy Template provides a structure for defining approved tools, prohibited data, acceptable tasks, ownership, human review, and the process for requesting new products.
A tool inventory becomes outdated as vendors release new features and employees find new applications.
AI Governance for Growing Companies places visibility, ownership, access, cost, adoption, and workforce impact inside a recurring management process.
Governance should match the level of risk. Testing a tool with public information requires less oversight than connecting an AI model to customer records or production systems.
Thrivea’s AI Governance module gives founders one place to see which AI tools are actually in use, who’s using them, and how that’s changing team capacity, instead of piecing it together from expense reports and guesswork.
AI Visibility shows which tools exist across the company, who uses them, and how usage differs team to team — replacing assumptions with an actual list.
For tools connected through a company-managed provider account (an Anthropic or OpenAI account, for example), Thrivea lets you set spending budgets per employee or team, so cost stops being something you find out about at the end of the month. This applies to AI usage running through that company-owned connection — it’s not a general monitor of every AI product an employee might open in a browser.
Workforce Insights adds the adoption layer on top: which teams and people actually use AI day to day, where it’s become part of a real workflow, and where team capacity may be changing as a result — useful context for a hiring conversation, not a replacement for one.
Workforce Insights shows which employees and teams use AI regularly, where AI has entered recurring workflows, and where team capacity may be changing.
The data provides useful context for hiring and workload decisions while leaving the final judgment with managers.
Shadow AI usually indicates that AI adoption developed faster than the systems created to document and manage it.
Reports still arrive, code still ships, and customers still receive answers. Beneath the visible output, the company may depend on accounts, automations, embedded features, and workflows that leadership cannot properly evaluate or recover.
Founders should begin with an accurate inventory of current AI use. Once the real environment becomes visible, leadership can decide which tools should remain, which processes need company ownership, which access should change, and which risks are unacceptable.
Shadow AI refers to AI tools, features, models, or workflows used for company work without adequate visibility, approval, ownership, or oversight.
Examples include personal chatbot accounts, embedded AI features activated without review, contractor tools, personal API keys, browser extensions, and undocumented automations.
No. Personal ChatGPT and other personal AI accounts represent one form of shadow AI.
The broader category also includes AI features inside approved software, contractor-controlled tools, personal API connections, custom assistants, and company-owned products used outside their approved scope.
The level of risk depends on the data, tool, and business process involved.
Shadow AI can expose sensitive information, create compliance problems, weaken access control, fragment software spending, and leave important workflows without a company owner. It can also distort adoption and capacity data used for hiring, budgeting, and training decisions.
Start with a company-wide inventory covering AI tools, embedded features, accounts, owners, users, data, integrations, costs, and workflow dependencies.
Expense records, identity logs, OAuth connections, SaaS discovery, network monitoring, browser controls, and contractor reviews can supplement employee reporting.
Ask every team which AI tools and features support recurring work.
For each tool, record the account owner, business purpose, data involved, cost, users, and consequences of losing access. The resulting inventory will identify the workflows that require immediate company ownership or risk review.
Yes. A small company can accumulate several subscriptions, embedded features, personal accounts, and automations without anyone maintaining a complete record.
Smaller companies may face greater continuity risk because one employee often owns several important processes and no dedicated IT or security function reviews AI usage.
A company should prohibit tools and use cases that create unacceptable security, legal, contractual, or operational risk.
A blanket ban often pushes useful AI activity further out of view. Approved alternatives, company-owned accounts, clear data rules, role-based access, and regular reviews provide stronger control than a universal prohibition.
by Jelena Relić
I have seen organizations invest heavily in a new HRIS and still struggle six months later. The system is live. The contract is signed. The dashboards...
by Jelena Relić
In the last five years, the majority of industries in the global economy have faced severe challenges. It all started with the COVID-19 pandemic, whic...
Traditional recruitment methods are showing clear signs of aging. Today, more than 70% of the workforce is not actively looking for jobs, so employers...