Written by Michiel R. De Boer
I had a conversation last year with the CIO of a mid-sized financial services firm in Kuala Lumpur. He had just completed an AI readiness audit. The finding that unsettled him most was not in the technology stack. It was in the employee survey.
Eighty-three percent of his workforce reported using AI tools regularly at work. His organisation had approved two.
He had assumed the gap was maybe twenty percent. An optimistic number, he now understood. The actual picture was that every department‚ AI compliance, risk, finance, operations, customer service‚ AI had made its own AI decisions, independently, quietly, and without reference to the tools the organisation had officially sanctioned.
This is shadow AI. And it is not a future risk. It is the present condition of most organisations in APAC today.
What shadow AI actually is
Shadow IT‚ AI the use of unauthorised technology tools at work‚ AI has been a governance challenge for two decades. Shadow AI is its more consequential successor, and the stakes are higher for a specific reason: these systems do not just store or transmit data. They process, generate, and in some cases retrain on it.
When an employee used unauthorised cloud storage five years ago, the risk was data residing in the wrong place. When an employee today pastes a client contract into a free-tier AI platform to get it summarised, the data is processed by a system outside the organisation’s control, potentially used for model training, potentially retained in ways the platform’s terms of service describe only in footnotes, and transmitted across jurisdictions in milliseconds.
The scale of this is not a niche concern. Research from Microsoft and LinkedIn’s 2024 Work Trend Index found that 78% of AI users at work are bringing their own AI tools ‚Äî tools not provided by their employers.
A separate study found that nearly half of knowledge workers are using AI in ways that explicitly violate their organisation’s stated policies. Not because they are acting in bad faith. Because the tools make their work genuinely easier, because the organisation has not offered a sanctioned alternative, and because there is no visible consequence for the behaviour that is happening anyway.

Why APAC organisations are particularly exposed
For organisations in APAC, the shadow AI exposure is compounded by the regulatory and jurisdictional context in which it is occurring.
When an employee in Kuala Lumpur pastes customer data into a US-hosted AI platform, Malaysia’s Personal Data Protection Act obligations may already be triggered. The PDPA requires that personal data be processed in accordance with its seven principles, including the security principle and the retention principle. A free-tier commercial AI platform operated by a US company is not, by default, a PDPA-compliant processor.
When a finance analyst in Jakarta summarises a board paper using a consumer-grade tool, that data may be transmitted across multiple international borders and used for model training by default. Indonesia’s Personal Data Protection Law, enacted in 2022, contains provisions on cross-border data transfers that the analyst is almost certainly not consulting before using the tool.
When a compliance officer in Singapore uses an AI assistant to draft a regulatory response, the question of whether that tool has appropriate data handling controls for financial services content is one that Bank Negara’s equivalent, MAS, would expect the institution to have answered. In most cases, it has not been asked.
The regulatory environment is evolving faster than most organisations are tracking. The ASEAN Guide on AI Governance and Ethics released in February 2024 signals the direction: governance of AI use, not just AI development, is moving toward formal requirement. Organisations building their governance posture now are ahead. Organisations waiting for mandatory requirements are accumulating exposure.
The distinction that matters: shadow IT versus shadow AI
Shadow IT was a containment problem. The typical governance response‚ AI acceptable use policies, endpoint controls, cloud access security brokers‚ AI was designed to limit what data could reach unauthorised systems.
Shadow AI requires a different frame because the problem is not primarily containment. Employees are not going to stop using AI tools that make them meaningfully more productive. Attempts to ban or block without offering a sanctioned alternative reliably produce two outcomes: the tools move to personal devices outside corporate network controls entirely, and employee trust in the organisation’s AI approach is damaged before that approach has been articulated.
The governance question is not how to stop shadow AI. It is how to bring it into view‚ AI to understand what tools are in use, what data is being processed, what the risk profile of each use case is, and where the organisation needs to establish controls, provide alternatives, or formally accept risk.
This is not a technology audit. It is an information governance exercise that requires someone with authority, mandate, and the GITO Govern discipline to execute it.
What organisations actually find when they look
The organisations that have conducted proper shadow AI assessments tend to find a consistent pattern. The volume of AI tool usage is higher than expected‚ AI often by a factor of three to five compared to leadership estimates. The range of use cases is broader than expected, extending well beyond the writing and summarisation tasks that most AI strategies focus on. And the data sensitivity of what is being processed is more varied than expected, including not just productivity content but customer data, commercial information, and internal strategic material.
They also find that the employees doing this are, overwhelmingly, not the organisation’s troublemakers. They are the high performers. The people who are using AI most extensively are the people who saw what the tools could do and integrated them into their workflow because they are good at their jobs and want to keep being good at their jobs.
This matters for the governance response. A blanket enforcement posture directed at these employees is a posture directed at the organisation’s most productive people. The better response is to bring governance to where the usage already is: classify use cases by data sensitivity, establish a tiered acceptable use framework, create a rapid-approval pathway for new tools, and offer supported alternatives for the use cases with the highest risk profiles.

The GITO ® Govern response
The GITO Govern domain addresses exactly this challenge: creating the governance structures that enable AI use rather than simply prohibiting it, while managing the real risks that shadow usage creates.
The starting point is not policy. It is visibility. An organisation cannot govern what it cannot see, and most organisations cannot currently see their own AI landscape. A structured shadow AI assessment ‚AI combining a technology scan, an employee survey calibrated to surface honest answers, and a review of data flows‚ AI produces the baseline that governance decisions require.
From that baseline, the governance architecture can be built: an acceptable use policy that reflects how people actually work, a classification framework for data and use case risk, a process for employees to seek approval for tools rather than avoid the question, and a reporting structure that keeps the picture current as the AI landscape changes monthly.
The goal is not zero unauthorised AI use. That goal is not achievable and the attempt to achieve it is counterproductive. The goal is governance that knows what is happening, manages what matters most, and enables the organisation’s genuine AI capability to develop on a foundation that can be defended.
What to do: practical recommendations
Map before you govern. Before drafting policy, conduct a structured assessment of what AI tools are currently in use across the organisation. Anonymous employee survey combined with a technology scan will produce a picture that surprises almost every leadership team that commissions it. The picture is the starting point.
Classify use cases, not just tools. The risk profile of an AI tool is not constant‚ AI it depends on what data it is processing and what the output will be used for. A tool used to draft internal communications carries different risk from the same tool used to summarise client data. Classification by use case and data sensitivity gives governance something to act on.
Create a rapid-approval pathway. The reason employees bypass approval processes is that those processes are slow and the answer is usually no. A governance framework that includes a fast-track approval route for low-risk use cases removes the incentive to avoid the process entirely.
Offer alternatives before enforcement. For use cases with high risk profiles, the governance response should lead with a sanctioned alternative where one is available. Telling an employee they cannot use the tool they have been using productively for six months, without offering something else, produces a different behavioural response than saying here is a tool that does the same job with appropriate controls.
Update monthly, not annually. The AI tool landscape changes faster than annual policy reviews can track. Governance of shadow AI requires a standing process for staying current‚ AI a designated owner, a review cadence, and a mechanism for employees to surface new tools they are considering rather than adopting them quietly.
The bilateral truth about shadow AI
Shadow AI exists because employees are trying to do their jobs better. The governance response that treats this as a discipline problem will not work. The governance response that treats it as information ‚AI about what your people need, what your current tooling is not providing, and where your organisation’s AI capability is actually developing‚ AI is the response that produces both control and capability.
The question is not whether your employees are already using AI you haven’t approved. More than 80% of organisations in APAC with knowledge workers have this picture in some form. The question is whether you know what they are doing, and whether your governance is keeping up with the reality it is supposed to govern.
Most are not. That gap is closeable. But it requires looking at it first.
