Shadow AI in the Enterprise: A Governance Framework for Transitioning from Uncontrolled Experimentation to Secure, Accountable AI Adoption

Authors

  • Abhipray Mirke Senior Manager - Finance & CISO, India.
  • Sushmita Dey Banik GRC PRODUCT SPECIALIST, India.

DOI:

https://doi.org/10.70917/ijcisim-2026-5637

Keywords:

Shadow AI, AI governance, enterprise risk management, generative AI, autonomous agents, data privacy compliance, cybersecurity policy

Abstract

The rapid, low-friction availability of generative artificial intelligence (AI) has produced a class of unmanaged enterprise technology risk referred to as Shadow AI which means the use of AI tools, models, application programming interfaces (APIs), browser extensions, copilots, and increasingly autonomous agents for business purposes without formal approval, security review, or governance oversight. This paper synthesizes industry survey data, regulatory texts, and documented real-world incidents to characterize the scale, drivers, and risk surface of Shadow AI, and to propose a structured governance framework for converting unsanctioned use into accountable Governed AI. Using a qualitative document-analysis methodology applied to seventeen primary sources spanning vendor research, security standards bodies, and regulatory instruments, the paper finds that Shadow AI is driven primarily by a productivity gap rather than malicious intent, that organizations with high Shadow AI exposure incur materially higher data-breach costs, and that the emergence of autonomous AI agents constitutes a distinct and escalating governance challenge that traditional acceptable-use policies cannot adequately address. The paper presents a ten-principle governance model, a risk-tiering structure, an agent-identity control baseline, and a four-phase implementation roadmap, concluding that prohibition-based strategies are largely ineffective and that visibility, safe enablement, and embedded controls produce more durable risk reduction.

Downloads

Download data is not yet available.

Downloads

Published

2026-09-04

How to Cite

Abhipray Mirke, & Sushmita Dey Banik. (2026). Shadow AI in the Enterprise: A Governance Framework for Transitioning from Uncontrolled Experimentation to Secure, Accountable AI Adoption. International Journal of Computer Information Systems and Industrial Management Applications, 18(23s), 514–524. https://doi.org/10.70917/ijcisim-2026-5637

Issue

Section

Original Articles