IRAIS 2026 Proceedings
Abstract
Generative AI tools available to the general public have given rise to a rapidly growing shadow technology. Employees naturally use public (or unapproved internal) AI to summarize lengthy documents, draft emails and messages, analyze data, and automate manual tasks. Meanwhile security, legal, and compliance teams have zero visibility into the prompts, uploaded data, outputs, retention practices, and downstream use. Attempting to outright ban risky use is unlikely to succeed, because employees will use proxies or figure out workarounds when approved tools cannot complete tasks quickly enough. How can organizations govern shadow AI risk without eliminating the productivity benefits that drove employee adoption in the first place?
This design science research study (current stage: artifact design, see Hevner et al., 2004) will present and evaluate the Shadow AI Governance Framework (SAGF). Specifically, the full paper will assess SAGF’s utility via structured expert review and scenario-based evaluation against four common enterprise use cases: document summarization, customer-support drafting, internal analytics, and proposal development. Evaluation will center on risk coverage, implementation feasibility, clarity of communication to nontechnical employees, and measurable impact on productivity.
SAGF combines elements from three major sources: the NIST AI Risk Management Framework (National Institute of Standards and Technology, 2023), academic and professional literature on shadow IT and AI-related cybersecurity risk, and industry guidance on organizational AI readiness (Cisco, 2024; Kshetri, 2023). The purpose-built framework both leverages and extends these resources without requiring buy-in from vendors, regulators, or open-source communities.
Unlike solutions that simply rename standard IT-security lifecycle steps with “AI” labels, SAGF adds three additional requirements specific to responsible AI use. First, AI use is explicitly treated as socio-technical workflow risk—not merely an unauthorized software problem—because risk emerges based on how the tool is used; similar output can be high risk in one situation and low risk in another. Second, practical AI governance distinguishes between tool approval and use-case approval; a given platform may be acceptable for some business scenarios but not others. A publicly hosted writing assistant may be fine for drafting customer-support emails but not confidential proposals. Third, instead of assuming AI tools maintain or improve productivity, SAGF operationalizes productivity measures as part of the governance feedback loop.
SAGF consists of five phases: discover, classify, approve, educate, and monitor. Phase 1, discover, means gaining visibility into shadow AI tools (cloud and on-premise), user accounts, browser plugins/extensions, and built-in tools used for work tasks. Classify covers analyzing common use cases for data sensitivity, business-criticality, model-access requirements, output quality, regulatory requirements, and intellectual-property concerns. Approve can follow classify directly or wait until useful guidance is available for employees. Like traditional IT asset approval, results will range from full usage permission to prohibited. Unlike shadow IT catalogs, where an approve/wait checklist means little beyond security controls, AI models produce output that workers consume or further operationalize; SAGF’s educate stage therefore provides context-specific guidance tailored to employees. This includes not only specific tools and prohibitions on data types or content but also helpful hints for secure prompt use, verifying tool outputs, escalating issues, and where to send feedback on this very policy. Finally, monitor means deploying lightweight tool usage controls where possible, requiring employees to attest to safe use periodically, reviewing unexpected use cases that need different guidance, watching for data loss indicators or suspicious usage patterns, and identifying security incidents that indicate abuse of AI tools or suggest employees are hiding their use.
SAGF addresses the productivity half of the overarching research question by defining where organizations can measure tradeoffs between control and enablement. Those measurable elements include: approval-cycle time (including for provisional permissions), adoption rate of approved tools for new or changed work, average and range of task-completion time, volume of exceptions requested, rework caused by negligent vs. purposeful AI output manipulation, raw security incident counts, and employee satisfaction with approved tools vs. shadow use. Instead of assuming employees are resistant to governance or that shadow use is always invisible, these measures give researchers and practitioners empirical ways to test whether AI governance supports productive work or just drives it into the shadows.
The expected contribution of this study is the development of the Shadow AI Governance Framework (SAGF), a design artifact that supports organizational governance of employee AI use in contexts where adoption often occurs outside formal approval processes. SAGF contributes to IS research by extending the shadow IT literature into the context of generative AI and by reframing shadow AI as a socio-technical governance problem rather than only an unauthorized technology-use issue. The framework also contributes to AI governance research by distinguishing between tool-level approval and use-case-level approval, showing that the risk of AI use depends not only on the technology itself but also on the data, task, user role, output use, and organizational context. For design science research, SAGF offers a structured artifact that translates existing AI risk management guidance into a practical governance process organized around discovery, classification, approval, education, and monitoring. The framework also identifies measurable indicators, such as approval-cycle time, approved-tool adoption, task-completion time, exception requests, rework, security incidents, and employee satisfaction, that can be used to evaluate the balance between risk control and productivity enablement. In doing so, the study provides a basis for future empirical research on whether AI governance reduces shadow use or unintentionally drives it further outside organizational visibility. From a practical perspective, SAGF provides organizations with a structured approach for identifying and managing shadow AI use without relying only on prohibition-based policies. The framework is especially relevant for organizations that need to respond to employee AI adoption while maintaining data protection, compliance, and productivity goals. As the study is currently in the artifact design stage, the proposed framework will be further assessed through structured expert review and scenario-based evaluation. This evaluation will help examine the framework’s clarity, feasibility, risk coverage, and usefulness across common enterprise AI-use cases.
References
Cisco. (2024). Cisco 2024 AI readiness index: Urgency rises, readiness falls. Cisco Newsroom.
Gregor, S., & Jones, D. (2007). The anatomy of a design theory. Journal of the Association for Information Systems, 8(5), 312–335.
Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–105. https://doi.org/10.2307/25148625
Kshetri, N. (2023). Generative AI and cybersecurity risk: Opportunities and challenges. IT Professional, 25(4), 73–77.
National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1
Recommended Citation
Pelfrey, Preston, "Silent Cybersecurity Threat: Practical Governance for Shadow AI Risk While Maintaining Employee Productivity" (2026). IRAIS 2026 Proceedings. 8.
https://aisel.aisnet.org/irais2026/8
Abstract Only