It’s coming through the door. Shadow AI is here.

Artificial intelligence (AI) has quietly entered the workplace through the front door, the side door and in many cases, the back door as well. Across South African organisations, employees are increasingly turning to generative AI tools to draft emails, summarise documents, analyse spreadsheets and speed up research. The productivity benefits are obvious, and for many workers, these tools are already becoming a normal part of the working day.

The problem is that much of this adoption is happening outside official company systems.

Generative AI use in South African companies has surged, with adoption rising from 45% in 2024 to around 67% in 2025, yet only about 15% of organisations have formal policies governing how employees use it. The result is a growing wave of what is now widely referred to as shadow AI. Employees are using AI tools to improve their work, and in some cases do their work, but they are doing so without oversight from IT, governance frameworks or clear security controls.

In other words, AI has already arrived in the enterprise. It just has not always arrived through approved channels.

The reality gap between policy and behaviour

This gap between organisational policy and employee behaviour is becoming one of the defining challenges of the AI era. Many companies are still in the early stages of determining how generative AI should fit into their technology environments. Questions around security, data protection and compliance are legitimate, particularly when organisations are dealing with sensitive information.

Employees, however, are moving much faster.

Faced with demanding workloads and increasing pressure to deliver more with fewer resources, many workers see AI as a practical productivity tool. If a generative AI platform can summarise a lengthy report in seconds or draft the first version of a presentation, the temptation to use it is strong.

In many cases, the decision is not driven by risk-taking behaviour but by simple pragmatism. Employees want to work more efficiently, and AI helps them do that. The unintended consequence is that organisations can find themselves in a situation where AI is widely used internally but largely invisible to leadership and IT teams.

When productivity creates new risks

Shadow AI raises concerns for one key reason. It often involves employees sharing company information with tools that were never designed to operate inside corporate governance frameworks.

Prompts can include internal reports, customer details, financial data or proprietary intellectual property. Once that information leaves the organisation’s controlled systems, it becomes difficult to track how it is stored or used. For regulated industries or organisations handling sensitive data, the implications are frightening.

This challenge is not entirely new. A decade ago, many companies faced a similar problem with shadow IT, where employees installed unapproved software to solve immediate business needs. The difference today is that AI tools can process and absorb large amounts of information at once, which raises the stakes considerably.

The instinctive response from some organisations has been to block or restrict access to AI platforms entirely. While understandable, this approach rarely works in practice.

Why banning AI rarely works

Attempting to prohibit generative AI tools often pushes their use further underground. Employees who see clear value in these tools are unlikely to abandon them simply because they are not formally approved. Who is going to write all those blogs and social content? Instead they may access them on personal devices, through web browsers or via unsanctioned accounts.

This creates exactly the kind of environment organisations are trying to avoid. AI is still being used, but now it is happening with even less visibility or control.

A more realistic approach is to recognise that generative AI is becoming a permanent feature of the modern workplace. The question is not whether employees will use it, but how organisations can ensure they use it responsibly.

Bringing AI into the light

This is where enterprise-grade AI platforms play an important role. Rather than allowing employees to rely on external tools, organisations are increasingly exploring secure AI environments that integrate directly with existing productivity platforms and governance frameworks. When implemented correctly, these systems allow employees to access the benefits of AI while keeping company data within protected environments.

Tools such as Microsoft Copilot illustrate how this model can work in practice. By embedding AI capabilities directly within familiar applications like Microsoft 365, organisations can provide employees with the assistance they want while maintaining control over how information is accessed and processed.

For partners and organisations navigating this transition, the role of enablement becomes critical. Businesses need guidance not only on deploying AI tools, but also on building the policies, training and governance structures that support responsible adoption.

The opportunity behind the risk

Shadow AI is often framed purely as a security concern, but it also reveals something important about how employees view AI. Workers are not resisting these tools. In many cases, they are actively seeking them out because they recognise the productivity gains. For organisations, that signals a significant opportunity.

When AI is introduced in a structured and secure way, it can unlock efficiency, reduce repetitive tasks and allow employees to focus on higher value work. Instead of operating in the shadows, AI becomes a visible and managed part of the organisation’s digital toolkit.

By Vanessa Munnik, Microsoft AI Business Solutions Lead, Westcon-Comstor Southern Africa

Related Articles

Latest Articles