Abstract

The rise of user-driven digital practices has long challenged organizational IT governance, with Shadow IT emerging as a widely studied phenomenon reflecting the unauthorized use of technologies within firms. However, the rapid advancement of Artificial Intelligence (AI) - and more recently Generative AI (GenAI) - has introduced new forms of shadow activity that are not yet fully captured in existing literature. This paper addresses this gap by offering a conceptual extension of the Shadow IT paradigm, arguing that Shadow AI and Shadow GenAI represent qualitatively distinct yet evolutionarily linked developments in shadow technology use. We conduct a Systematic Literature Network Analysis (SLNA) using Scopus-indexed data and bibliometric tools such as VOSviewer and Pajek to examine how the academic discourse on Shadow IT has evolved, and how emerging research is beginning to address the challenges posed by unauthorized AI and GenAI adoption. Our analysis reveals a deepening of risks: from governance and data privacy in Shadow IT, to ethical opacity and knowledge erosion in Shadow GenAI. The paper contributes to the literature by theorizing Shadow AI and GenAI as part of a continuum rooted in organizational strain and user rationalization. In doing so, we highlight the need for new governance strategies that go beyond infrastructure control to address the epistemic and cultural implications of AI-driven autonomy in the workplace.

Share

COinS