Guide · Shadow AIFOR CEOS & CTOS

Shadow AI: the bomb
ticking in every second company.

Shadow AI is any AI tool — or software built with AI — used inside a company without IT's knowledge, approval, or controls. It's already in your business. This guide covers how it got there, what it risks, why banning it fails, and the path that actually works.

How it happens

It doesn't arrive as an attack. It arrives as initiative.

Vibe-coding — building software by chatting with an AI — is happening everywhere, with no rules and no category. Business people sit down with Claude, Cursor, or Copilot in the evening and have a prototype by morning. The sales director builds his own reporting tool. The HR manager builds a CV screener. The CFO builds his own invoice checks. All of it useful. None of it governed.

What it risks

IT rejects it. Rightly.

Those prototypes share four properties, and under NIS2 each one is a finding waiting for an auditor: nobody controls who accesses them, nothing they do is logged, nothing isolates them from company data — and they run on somebody's laptop. Company data flows through tools management has never heard of.

  • NO AUTH
  • NO LOGS
  • NO ISOLATION
  • ON A LAPTOP

Useful. Ungoverned. Both.

Why bans fail

Prohibition doesn't remove demand. It removes visibility.

Ban the tools and the building continues — on personal accounts and personal devices, where you can see none of it. The demand is legitimate: your people are trying to do their jobs faster. The problem was never the chisel; it's that nobody gave them a workshop. The fix is a sanctioned path where doing it properly is easier than going around — a governed runtime where anything built lands access-controlled, logged, and isolated by default. That's what a Bailey is, and the Scriptorium is the sanctioned way to build into it.

The checklist

Five moves for the next board meeting.

  • Inventory — ask each department head which AI tools their team actually uses. Expect surprises; don't punish honesty.
  • Trace the data — for each tool: what company data goes in, and where does it physically live?
  • Sanction a place — give builders a governed environment so the right path is the easy path.
  • Log by default — access control and audit trails as a standing requirement for anything touching company data.
  • Pilot one process — take the most-loved shadow prototype and rebuild it governed. First one can be live in a week.

Bring us a process.
We'll show you how it builds.

30 minutes. Real automations in real operation — no slides, no obligations.

The manual way isn't getting cheaper.