Your Company Already Adopted AI. Nobody Told You.
Vishal Sachar
Co-Founder & CEO of CLRT
In May 2024, Microsoft and LinkedIn surveyed 31,000 workers across 31 countries and found that 75 percent of knowledge workers were already using AI at work. The number that mattered sat underneath it: 78 percent of those users were bringing their own tools, personal accounts on personal logins, rather than waiting for anything official. This is vendor research, and Microsoft has an obvious interest in the answer, but the direction is confirmed from the failure side by researchers with no such interest. What these numbers describe is not an adoption curve a company is somewhere along. It is a fait accompli. Most companies are running a live AI deployment right now. It simply appears on no system diagram, no risk register, and no budget line, because nobody in charge ever approved it.
The corroboration comes from research with the opposite incentive. MIT Project NANDA's 2025 study of enterprise AI, built to explain why so many corporate programmes show no return, found that only 40 percent of companies had bought an official model subscription, while workers at more than 90 percent of the companies surveyed used personal AI for their work regularly. Put the two findings side by side and the picture sharpens uncomfortably. The official channel is not lagging the shadow channel. It is the minority channel. Shadow use is not a fringe behaviour at the edge of a sanctioned programme; at most companies it is the main event, the only deployment running at scale. Meanwhile, in the same Microsoft survey, 60 percent of leaders said their company lacks an AI vision and plan. The workforce has settled a question the leadership is still drafting an agenda for.
It is worth being precise about why this happened, because the mechanism decides what will fix it. The shadow path did not win because employees are reckless. It won on merit. For the individual, the personal tool is reachable in seconds, usually stronger than whatever the company licensed, and free of the friction that surrounds anything official, and the hours it saves accrue directly to the person using it. Adoption followed individual utility, exactly as it always does, and policy was never part of the equation. Now run the same task down the shadow route and a governed route and compare. The deliverables are identical. Every difference that matters to the organisation is invisible in the output: what data left the building, into which model, under whose terms, checked by whom, provable to whom. The company's entire stake lives in the part of the transaction the deliverable cannot show, which is why the deliverable keeps passing.
Faced with this, one reflex is to declare victory. Announce that the company embraces AI, bless the popular tools, and count the existing usage as strategy. This feels progressive and changes almost nothing, because blessing without observability does not govern the shadow path. It renames it. The usage becomes official while the visibility stays exactly where it was, which is nowhere. There is still no inventory of what runs where, no record of which data flows into which models, no checkpoint between a confident draft and the company record. The risk has not been managed; it has been industrialised, the same blindness now operating at greater scale and with encouragement. A policy document that no system enforces is a press release to the organisation, and the organisation can tell.
The opposite reflex is prohibition, and it fails even more predictably, because a ban touches none of the forces that created the behaviour. The workload that made the tool attractive still exists. The personal gain is still real. The cost of entry is still a browser and a login on a phone the company does not manage, which is also why detection barely exists; 2026 coverage of IBM's research put the share of organisations with any policy for detecting shadow AI at 37 percent. What a ban does change is the incentives, in the wrong direction. Disclosure becomes confession, so the honest go quiet. Training becomes impossible for tools that officially do not exist, so the heaviest users stay the least trained; Microsoft's survey found only 39 percent of AI users had received any company training. A ban does not end adoption. It ends your knowledge of it.
What works is quieter and harder, and it has three parts in a fixed order. First an amnesty, because no inventory is honest while admitting usage carries a penalty; people will not map what they are afraid to confess. Then the inventory itself, and this is where the reframe pays: shadow usage is not primarily a violation register, it is a map of demand. Every hidden workflow marks a place where an employee found enough real value to take a personal risk for it, which makes the inventory the best discovery document the company never commissioned. Then a sanctioned path that beats the shadow one on merit, because governance that loses a head-to-head with a personal login is not governance, it is decoration. Deciding which discovered uses to legitimise, which to close with cause, and what observability looks like when it reads as protection rather than surveillance is judgment work, and it is precisely the work most companies skip.
Shadow AI is not leakage around your AI programme. At most companies, it is the programme.
A deeper dive
The three moves are simple to name and easy to ruin, and the ruin is always second-order. An amnesty that quietly feeds a disciplinary file poisons the record permanently; the first person penalised for an honest answer is the last honest answer the company receives. An inventory run as a surveillance exercise, scanning traffic and interrogating teams, drives the behaviour it is trying to map one layer deeper, onto devices and accounts the company will never see, and produces a confident map of the wrong territory. And a sanctioned path that is slower or weaker than a personal login does not fail loudly; it fails silently while succeeding officially. Usage of the approved tool becomes the metric, the dashboard turns green, and the real work continues in the shadow channel underneath. That last state is worse than doing nothing, because the organisation now believes it has governed adoption when it has only built a decoy, and every downstream decision inherits the belief.
Getting it right turns on what better actually means, and this is where the judgment sits. The sanctioned path wins on speed of access, on model quality, and on the one advantage no personal account can safely offer: legitimate, bounded access to the company's own context, the data that makes AI output genuinely useful and that should never transit a personal login at all. It wins when its observability is experienced as protection, a record that covers the employee when the output is challenged, rather than as monitoring. And it wins only for the uses worth winning; part of the inventory's value is discovering the uses that should be closed with cause, named plainly, and engineered against rather than wished away. Sequencing the amnesty, weighing which discovered workflows carry real risk and which merely look untidy, and building the governed route people prefer is not a policy exercise. It is the same discipline as any production AI system: verification, scoped access, and an audit trail, applied to an adoption that already happened.
Work with CLRT
CLRT does this work in the order that makes it survivable: the amnesty and inventory that map where AI already lives in your business, the judgment about which of those uses to legitimise and which to close, and the governed path your people choose because it is better, not because it is policy. If you want to see the gap before you commit to closing it, CLRT Ascent at ascent.clrtstudio.com is where we run that diagnostic. Either way, the adoption has already happened. Talk to us about governing it while the visibility can still be recovered.

Vishal Sachar
Vishal Sachar is the Co-Founder and CEO of CLRT, where he helps UAE businesses make sense of applied agentic AI and put it to work. He writes on agentic systems, AI governance, and the economics of automation. Reach him at vishal@clrtstudio.com or on LinkedIn.


