Neurovia
Back to the blog

AI Governance · AI Adoption

Banning AI Isn't Governing It

When a company bans AI without offering a better alternative, it doesn't reduce usage — it hides it. Governing shadow AI starts by treating it as a demand signal, not a violation.

Article cover: Banning AI Isn't Governing It

At a large central bank, employees work on their secure, no-AI, bank-issued computers with their personal laptops open beside them, on the home page of their favorite language model. That's what an official at the institution told researchers from BBVA and several universities, in an account published by Harvard Business Review. It isn't an isolated case — it's the pattern they document as AI demand inside companies moves outside official channels, not out of carelessness, but because corporate tools don't match what people already know how to do with AI in their personal lives.

The typical response is to treat this as a leak: ban it, block domains, sanction it. But the available evidence points somewhere else. Banning without substituting doesn't eliminate usage — it hides it. And an organization that can't see what its employees are already doing with AI doesn't have less risk. It has less visibility.

Shadow AI is a signal, not a leak

Gartner surveyed 302 cybersecurity leaders between March and May 2025: 69% suspect or have evidence that their employees are using unauthorized public generative AI. The firm's forecast is stark — more than 40% of enterprises will experience AI-related security or compliance incidents linked to unauthorized shadow AI by 2030 — but the root cause isn't a missing ban. It's a missing sanctioned alternative that can compete with what anyone can get for free in a personal browser tab.

The BBVA researchers writing in Harvard Business Review put it plainly: unauthorized use of consumer AI tools by employees shouldn't be treated as a compliance problem, but as a signal of untapped demand that companies can redirect. When the official tool is slower, more limited, or simply doesn't exist for a task, people don't stop using AI — they switch channels.

Why people don't speak up

Blocking access solves the visible part of the problem and makes the invisible part worse. Recent Harvard Business Review research on why employees aren't transparent about their AI use finds that the strongest predictor of whether someone shares a useful AI workflow isn't formal policy or the tools on offer — it's organizational trust and psychological safety, which outweigh the effect of policies or sanctioned tools alone. People stay quiet for rational reasons: they fear being judged as less capable, assigned more work, or made easier to replace.

That has an uncomfortable implication for any governance program that relies on rules alone: a culture that punishes disclosure produces less disclosure, not less use. The result is an organization that believes it has control because it has a policy document, when in fact it has less information than before about how AI is actually being used in its day-to-day operations.

The real gap is governance, not technology

McKinsey's 2026 AI Trust Maturity Survey, covering roughly 500 organizations surveyed between December 2025 and January 2026, found that the average responsible-AI maturity score rose to 2.3 this year, up from 2.0 in 2025 — but only about 30% of organizations reach a high maturity level in strategy, governance, and agentic AI controls, well behind technical and risk-management progress. According to the study, that governance gap holds consistently across every region.

Nearly two-thirds of respondents cite security and risk concerns as the top barrier to scaling agentic AI — not a lack of use cases, but a lack of confidence in deploying it safely. And the gap between the risks organizations consider relevant and the ones they're actively mitigating is wide across nearly every category, especially intellectual-property leakage and privacy.

The most telling finding for anyone managing shadow AI: organizations that assign explicit ownership for responsible AI — a role, a team, not just a document — average 2.6 maturity points, compared with 1.8 for those that don't. Governing diffusely produces, in practice, the same result as not governing at all.

What to do instead of banning

Three concrete moves, in order of urgency:

  1. Audit before you ban. If no one in your organization can say, with evidence, what share of your team uses unsanctioned AI and for what, you don't have governance — you have a paper policy. The audit isn't punitive; it's the only way to know whether the problem is security, product, or both.
  2. Turn hidden demand into a product roadmap. If your employees use a personal AI tool for a specific task, that task is the spec for your next sanctioned tool. Ignoring that signal and buying a generic platform disconnected from real usage is the most expensive way to solve the wrong problem.
  3. Assign a named owner. The maturity gap between organizations with explicit accountability and those without isn't marginal. Governing AI diffusely — "everyone is responsible" — produces the same outcome as not governing it.

The question worth asking this week

Ask three people on your team, privately, what they're using today that IT never formally approved. If the answer is "nothing," you're probably not asking the right way. If you get an honest answer, you have the first line of your next AI tool's backlog — and a more accurate measure of your real risk than any policy you signed this year.

Newsletter

Get our new articles

We'll let you know when we publish practical analysis on data, automation, and Artificial Intelligence.

Sources

Book a meeting