Shadow AI is any AI tool — or software built with AI — used inside a company without IT's knowledge, approval, or controls. It's already in your business. This guide covers how it got there, what it risks, why banning it fails, and the path that actually works.
Vibe-coding — building software by chatting with an AI — is happening everywhere, with no rules and no category. Business people sit down with Claude, Cursor, or Copilot in the evening and have a prototype by morning. The sales director builds his own reporting tool. The HR manager builds a CV screener. The CFO builds his own invoice checks. All of it useful. None of it governed.
Those prototypes share four properties, and under NIS2 each one is a finding waiting for an auditor: nobody controls who accesses them, nothing they do is logged, nothing isolates them from company data — and they run on somebody's laptop. Company data flows through tools management has never heard of.
Useful. Ungoverned. Both.
Ban the tools and the building continues — on personal accounts and personal devices, where you can see none of it. The demand is legitimate: your people are trying to do their jobs faster. The problem was never the chisel; it's that nobody gave them a workshop. The fix is a sanctioned path where doing it properly is easier than going around — a governed runtime where anything built lands access-controlled, logged, and isolated by default. That's what a Bailey is, and the Scriptorium is the sanctioned way to build into it.
30 minutes. Real automations in real operation — no slides, no obligations.
The manual way isn't getting cheaper.