Prepared by Dr Keketso Kgomosotho, for Techila Law. At the time of writing, much of the research underpinning this note derives from working papers, manuscripts and preprints that have not yet completed peer review. To date, there is no systematic empirical data on shadow Ai in South Africa.
Shadow Ai is the unsanctioned use of artificial intelligence (“Ai”) tools, models, copilots and browser extensions by employees, teams or business units without their organisation’s knowledge, assessment, procurement or approval. This policy note examines the phenomenon from the South African perspective, drawing on recent scholarly and empirical research. It finds that shadow Ai is a governance risk rooted in the structural gap between structural incentives, employee productivity needs and organisational technology provision. The policy note examines the incentives that drive shadow Ai, the organisational risks it creates, and outlines the South African legal position, before proposing a workable governance strategy. It concludes with observations for policymakers, grounded in the consistent empirical finding that prohibition-based governance approaches deepen the problem, whilst governance approaches based on encouraging visibility, usable alternatives and trust reduce the risk of shadow Ai. The policy note is written for organisational leaders, boards, executive committees, information officers, compliance and risk functions, and policymakers.
1. Introduction
Ai has entered the South African work space at a pace much faster than governance has responded. It is an open secret that employees use frontier consumer Ai tools (mostly Large Language Models or LLMs) that their organisations have neither selected nor approved, and in many cases do not know about. This policy note is about this undisclosed, ungoverned layer of Ai use, which the discourse calls “shadow Ai.” The policy paper examines and defines shadow Ai, the incentives driving it, the risks it introduces, and proposes a workable governance and oversight response to shadow Ai. The implication is uncomfortable. If adoption means that Ai capabilities are in productive use, then many organisations have already “adopted” AI; the adoption occurs without their knowledge, decision or approval, at the hands of their employees.
The policy note proceeds in six sections. Section 1 defines shadow AI. Section 2 examines the incentives that drive it, while section 3 sets out the cybersecurity risks it creates for organisations. Section 4 briefly states the South African legal position in relation to shadow Ai. Section 5 proposes a governance strategy, and section 6 makes closing remarks.
2. Defining shadow AI
Shadow Ai is the use of Ai tools, models, copilots, browser and extensions by employees, teams or business units without formal disclosure, authorisation, security assessment, procurement approval or compliance review by the organisation.1 For instance, “shadow” use of Ai occurs when an employee uses a private chatbot service to support the work they perform for the organisation, or activates an Ai feature embedded within software the organisation already uses, without the organisation’s knowledge, assessment, procurement or approval. The definition is deliberately broad to match the range of viable Ai applications; it covers the LLM chatbot used on a personal account, the browser extension that routes organisational data to an external model, and the recent Ai feature inside software the organisation already owns, etc.
Research on workplace Ai risk finds that ad hoc Ai use becomes culturally normalized within routine work, such that entering potentially sensitive organisational context into an Ai tool comes to appear commonplace rather than exceptional.2 In South Africa, where only 13% of companies have implemented Ai governance frameworks,3 this normalisation proceeds substantially without counterweight.
3. The incentives driving shadow AI
Understanding why shadow Ai occurs is a necessary precondition for its effective governance. If the shadow Ai is explained by misconduct, the remedy is straightforward, disciplinary measures. However, behavioural misconduct alone doesn’t satisfactorily explain why it occurs. In my view, it serves to treat symptoms that lie downstream of the cause, which is the structural environment and incentives. In that case the remedy is design. Four incentives seem to recur in the research, across sectors, organisations and jurisdictions, and none of which are about employees acting in bad faith.
a) People generally do not want to disclose that they use AI
Research evidence shows that people tend to devalue colleagues who use Ai tools, penalize outputs labelled as AI-assisted, and reduce compensation for such work, so that disclosing Ai assistance may invite reputational or even financial penalties.4 A 2025 study in radiology finds “remarkably low disclosure rate despite surveys indicating significant LLM adoption among researchers.”5 It also finds that this discrepancy is the result of “fear of stigma, perceived advantages of undisclosed use, disagreement with disclosure requirements for minor editing, or policy unawareness, among other reasons.”6 Another 2026 study on Ai disclosure and user trust in news writing found that “detailed disclosures (of Ai use in news writing) reduced trust and subscription rates.”7 As such, employees are systematically incentivized to hide their Ai use to protect their self-image or professional image.8
b) Filling in the gaps that official channels leave open
Employees turn to unofficial Ai where approved tools are unavailable, slow, difficult to use, outdated or perceived as inferior to public alternatives. Other drivers and incentives include pressure to deliver work faster, unclear Ai policy, and weak communication from leadership with regard to acceptable Ai use.9 As such, shadow Ai may also be caused by unmet organisational capability needs. The evidence locates the failure on the supply side, where employees reach for public tools at the moment the organisation’s own Ai systems are unavailable, outdated, less advanced or slower than the work schedule requires.
c) Punishment drives shadow Ai deeper into the shadow
Policies that require mandatory disclosure of Ai use have been found to lead to reduced visible use, but have also been found to correspond to an increase in covert or shadow use of Ai, which entails using Ai in ways designed to avoid detection.10 This empirical finding comes from a study conducted with 1,678 participants and 477 professional evaluators in an incentivized job-application task. In this study, the covert or shadow users produced the highest-quality outputs, as rated by professional evaluators who were unaware that the outputs were AI-assisted. As knowledge of this trade-off spread, covert adoption nearly doubled.11 The study concludes that policies designed to enforce ethical Ai use may inadvertently incentivize employees to hide their use of unauthorised AI. As it seems, a governance model based on surveillance and punishment of Ai use only exacerbates shadow AI.12
d) Formal governance fails against shadow Ai
According to a 2025 study by DELL, Intel and World Wide Worx, only 14% of surveyed South African companies have a company-wide Ai strategy in place, and only 13% have a comprehensive Ai governance framework in place that address safety, privacy, and bias. It also finds that monitoring for hallucinations is reported in only 7% of respondents, and security controls to prevent Ai data leakage reported at only 6% of surveyed organisations.13 Research also suggests that even in organisations that do have a written policy, the policy is often not implemented or enforced, creating a gap between policy and practice. Interview research by Semionovas across six organisations documents a persistent gap between managerial and employee perspectives, where managers describe Ai policies and Ai approval processes as already present, whilst employees experience the same mechanisms as unclear, difficult to find, or detached from everyday work.14
The interplay between the policy and practice occurs within a specific operational, historic and contextual setting, which in turn evolves over time. Thus, the gap between policy on paper, and practice can be understood as a failure to adapt to ongoing practices, or a failure to develop and update policies that match the shifting conditions of ongoing practices.15 This gap between policy and practice is known all too well in the South African context.
If shadow Ai is only a behavioural problem, the remedy is policy enforcement and discipline. However, if it is also a governance or an adaptation failure, the remedy is a redesign of the governance systems, to align with structural incentives and evolving conditions of work.
4. Shadow Ai broadens the cyberattack surface
Unsanctioned Ai tools multiply the interfaces available to adversaries, raise data leakage risks, and render the organisation’s data harder to regulate by creating multiple, unmonitored channels out of the organisation.16 Typically, employees paste organisational data into Ai prompts and because these flows run through browsers and personal accounts, they bypass IT’s security measures. Reports show that users shared conversations with Ai chatbots can be publicly assessable through various means.17 Research on critical infrastructure operators, drawing on interviews with senior executives across 27 organisations in the energy, water and communications sectors, shows that shadow Ai produces a misalignment between the assumptions on which formal governance rests (clearly bounded systems, observable behaviour, accountable operations) and AI-mediated practices that are informal, distributed and only partially visible, creating compliance gaps in which organisations may appear compliant whilst lacking the artefacts needed to demonstrate effective oversight.18 Three degradation mechanisms recur: boundary bypass, where data flows circumvent established perimeters; unassessed capability expansion, where embedded Ai features introduce latent risks; and loss of observability, which undermines forensic auditability.19
Shadow Ai agent compounds the problem. Ai agents can actively initiate external connections, executes code and may access login credentials, expanding the attack surface from data exfiltration into active security compromises. Multiple unmonitored data channels make the organisation’s data effectively ungovernable, and every instance of personal data entering a shadow Ai tool is also a potential violation of POPIA’s data-residency, transfer and processing requirements. This everyday shadow use of Ai embeds risks into routine work, with the result of eroding effective governance.20 For an SME, shadow Ai is often the only Ai capability employees have, since such organisations21 rarely have a dedicated IT, security or procurement functions through which tools are vetted and approved. The risks intensify in the context of critical sectors such as healthcare, legal adjudication, finance and education.22
Thus, shadow Ai multiplies the organisation’s external interfaces and converts each employee’s prompt box into an unlogged, uncontractual and ungoverned data channel that adversaries can increasingly reach through data leakage, supply-chain compromise, or increasingly through autonomous agents.
5. The South African legal framework
There is no AI-specific legislation that governs shadow Ai in South Africa. Instead, the catalogue of existing law that already applies to data, automated decisions and cybersecurity applies to shadow Ai in four principal ways.
First, POPIA applies where an employee enters customer, employee or patient information into a public Ai tool, that is processing of personal information, and questions of lawful basis, security safeguards and cross-border transfer arise immediately. Section 21 of POPIA restricts the transfer of personal information to third parties in foreign jurisdictions unless a section 72 exemption applies,23 and public Ai tools frequently process data in jurisdictions that satisfy none of those conditions. The written operator agreement POPIA contemplates does not exist in a shadow scenario. Section 71 further restricts automated decision-making through profiling, which is engaged wherever Ai outputs inform decisions concerning persons.24 Breach of these provisions carries regulatory and civil consequences under the Act. Whether the Information Regulator, resourced as it presently is, can police conduct that is invisible to the regulated parties themselves is an open question, and one which the interim approach leaves unanswered.
Second, and although not legally binding in its own right, the 2026 King V code treats Ai risk as enterprise risk, subject to board-level monitoring and assurance, and that legislation governing the conduct of organisations already holds businesses accountable for managing AI-related risks notwithstanding the absence of AI-specific legislation.25
Third, PAJA is also engaged where shadow Ai informs public decisions. Where Ai outputs inform administrative decisions by departments or organs of state, the procedural fairness requirements of the Promotion of Administrative Justice Act 3 of 2000 are engaged, and such decisions may be set aside where the Ai contribution is fails the standard of review.26
A policy vacuum, not a legal vacuum
South Africa drafted a National Artificial Intelligence Policy Framework in August 2024 as the first step towards eventual Ai regulation, following an extensive public consultation process led by the Department of Communications and Digital Technologies. The draft policy was subsequently withdrawn by Cabinet.27 In the interim, existing legislation carries the regulatory load. The practical consequence is that South African organisations cannot afford to await AI-specific legislation before rendering shadow Ai governable.
6. A governance strategy for shadow AI
Research shows that Blanket prohibition of Ai use fails against shadow AI, and a governance model based on prohibition and punishment tends to make the problem worse. Prohibition-first policy strategies create an organisational shadow economy in which Ai usage is driven deeper underground.28 In other words, it reduces visible use, whilst increasing hidden use through personal accounts and unmonitored browser tools.29 We propose the following governance architecture instead of prohibition-based approaches.
a) A shadow Ai audit
Organisations should catalogue every Ai tool in use, including Ai features embedded within approved software, and assess the risk and exposure of each. It is rather difficult to govern what you do not know about.30 The audit should distinguish between tools in active use and dormant accounts, and should treat embedded Ai features with particular attention, since they are the fastest-growing source of unassessed exposure.
b) Zone or triage use cases, rather than each tool
Classification and priority should be set at the level of the use case, not the tool. Each use case should be assessed against three criteria:31 the sensitivity of the data it touches, the impact of its outputs, and the depth of its integration with existing systems. The same tool can be acceptable in one context and unacceptable in another, and different use cases call for different levels of exposure. Thus, triage is equally necessary. As such content generation will be governed differently from algorithmic decision-making, which may require more immediate intervention.32
c) Sanctioned Ai alternatives must match frontier models capabilities
The strongest finding in the shadow Ai mitigation literature is that where the officially sanctioned Ai tool is slower, outdated or more restricted than the frontier consumer alternatives, employees will continue to use the consumer system, irrespective of organisational policy. A good place to start is a managed enterprise gateway to current commercial models, with data protection terms, enterprise data security and usage logging.33
d) Accelerate approval and procurement
Governance fails when it is slower than the behaviour it governs. Where standard IT procurement cycles run for months, employees do not wait; they adopt tools in the shadows, and the organisation loses visibility in the attempt to retain control. A fast-track pathway for low-risk Ai tools, with a target decision time of approximately 30 days, is therefore a useful security control. This can apply to tools falling within a pre-defined low-risk tier, or those that do not touch sensitive or personal data, produce low-impact outputs, and involve no deep integration with core systems.
e) Offer a time-limited disclosure amnesty
A no-penalty reporting period, within which employees may disclose past unauthorised use of Ai without disciplinary consequence, is the only reliable mechanism for establishing the true scale of exposure,34 and it operationalises the finding that in this context, that trust-based governance models outperform punishment-based approaches.35 An amnesty must nonetheless be designed with South African labour law in mind. It should be time-limited, documented, and framed as an exposure-assessment exercise.
f) Close the gap between policy and practice
The perception gap between managers, who believe the policy exists, and employees, who cannot find or use it, compounds the failure.36 At best they can give the illusion of governance on paper, without effectively achieving its purpose. Ai policy should therefore be short, findable, proportionate and adaptable.
The sequencing of these measures should also differ by organisational capacity, and this is itself a governance choice. Organisations vary widely in what they can execute at once. An organisation with mature risk and procurement functions can run discovery, classification and fast-track approval in parallel; one still building basic data governance may need to sequence them.
7. Conclusion
Shadow Ai is the default state of enterprise Ai adoption: it solves real productivity problems, it is culturally normalised, it occupies the space left by slow procurement and unclear policy, and it flourishes under punitive oversight.37 The legal position in South Africa does not await an Ai Act or policy before attaching consequences to shadow AI. POPIA, the Cybercrimes Act, PAJA and King V already apply. Whether that law can be made workable against conduct designed to be invisible is the question the interim approach leaves to the Regulator, to employers, and to the policy process.
Organisations that discover their Ai estate, zone their use cases, provide sanctioned alternatives their employees genuinely prefer, and build their Ai policy on trust rather than suspicion will convert shadow Ai from liability into governed capability. Those that persist with prohibition alone should expect the shadow layer to continue expanding beyond observation, and to encounter it only when an incident forces the issue to surface.38
References
- 1.Ross JAJ, Hibbert L and Moss EJ, ‘Shadow AI: Governance, Risk, and Organisational Resilience’ in 2025 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA) (IEEE 2025), accessed 17 September 2026.↩
- 2.Sebastian G, ‘Digital Shadow Ai Risk Theory (DART): A Framework for Managing Data Disclosure and Privacy Risks of Ai Tools at Work’ (2026) 229 Technological Forecasting and Social Change 124697, accessed 17 September 2026.↩
- 3.Arthur Goldstruck, The South African Generative Ai Roadmap 2025 Report, (World Wide Worx for Dell Technologies and Intel, 2026) Accessed on 18 September 2026, available at https://www.worldwideworx.com/wp-content/uploads/2025/10/The-SA-Gen-AI-Roadmap-2025.pdf↩
- 4.Dong, Mengchen and Yakura, Hiromu and Sherif, Omar and Bonnefon, Jean-Francois and Rahwan, Iyad, Shadow Ai Thrives Under Punitive Social Evaluation (August 26, 2025). Available at SSRN, accessed 17 September 2026.↩
- 5.Jonah Barrett D, Heng R, Perchik JD. Documenting Disclosure: limited Reporting of Generative Ai Usage in Radiology Research Manuscripts. Acad Radiol. 2025. doi: 10.1016/j.acra.2025.06.057 which finds that only 1.7% of manuscripts declared LLM use.↩
- 6.Ibid.↩
- 7.Pooja Prajod et al, ‘Full Disclosure, Less Trust? How the Level of Detail about Ai Use in News Writing Affects Readers’ Trust,’ (2026) arXiv:2601.09620v1 [cs.HC] 14 Jan 2026 available at https://arxiv.org/html/2601.09620v1.↩
- 8.Li Z, Liang C, Peng J, Yin M. How Does the Disclosure of Ai Assistance Affect the Perceptions of Writing? Miami, Florida, USA; 2024.↩
- 9.Dong et al., Shadow Ai Thrives Under Punitive Social Evaluation (2025).↩
- 10.Ibid.↩
- 11.Ibid.↩
- 12.Ibid.↩
- 13.Arthur Goldstruck, The South African Generative Ai Roadmap 2025 Report.↩
- 14.Semionovas T, ‘Governing Shadow Artificial Intelligence in Organizations’ (master’s final degree project, Kaunas University of Technology, 2026).↩
- 15.Martin J, Ellström P, Wallo A, Elg M (2025), ‘Bridging the policy-practice gap: a dual challenge of organizational learning’. The Learning Organization: An International Journal, Vol. 32 No. 7 pp. 18–34.↩
- 16.Puthal D, Mishra AK, Mohanty SP, Longo A and Yeun CY, ‘Shadow AI: Cyber Security Implications, Opportunities and Challenges in the Unseen Frontier’ (2025) 6 SN Computer Science 405, https://doi.org/10.1007/s42979-025-03962-x accessed 17 September 2026.↩
- 17.William Gallagher, ‘Privacy is dead, personal Ai prompts indexed by Google search’, (Apple Insider, 28 July 2026) Available at https://appleinsider.com/articles/26/07/28/privacy-is-dead-personal-ai-prompts-indexed-by-google-search Accessed 14 September 2026.↩
- 18.Chhetri MB, Tariq S, Aamir T, Grobler M, Thapa C and Singh R, ‘From Frontier to Shadow AI: A Simmering Threat to Assurance and Security in Critical Infrastructure’ (arXiv preprint arXiv:2606.00088, 23 May 2026).↩
- 19.Ibid.↩
- 20.Sebastian G, ‘Digital Shadow Ai Risk Theory (DART) (2026) 229 Technological Forecasting and Social Change.↩
- 21.Ross JAJ, Hibbert L and Moss EJ, ‘Shadow AI: Governance, Risk, and Organisational Resilience’ (IEEE 2025), https://doi.org/10.1109/ACDSA65407.2025.11166415 accessed 17 September 2026.↩
- 22.Balogun AY, Metibemu OC, Olutimehin AT, Ajayi AJ, Babarinde DC and Olaniyi OO, ‘The Ethical and Legal Implications of Shadow Ai in Sensitive Industries: A Focus on Healthcare, Finance and Education’ (2025) 27 Journal of Engineering Research and Reports 1, Accessed 17 September 2026.↩
- 23.Protection of Personal Information Act 4 of 2013, ss 21, 71 and 72.↩
- 24.Protection of Personal Information Act 4 of 2013, sections 21, 71 and 72.↩
- 25.Institute of Directors Southern Africa, King V Code Report on Corporate Governance for South Africa 2026.↩
- 26.Promotion of Administrative Justice Act 3 of 2000.↩
- 27.‘Cabinet approves withdrawal of Ai policy’ SAnews (5 June 2026).↩
- 28.Shaik AS, ‘Shadow Ai as Governance Failure: Unauthorized Model Use, Organizational Risk, and the Limits of Policy-Based Control’ (working paper, Golden Gate University, 2026).↩
- 29.Puthal D, Mishra AK, Mohanty SP, Longo A and Yeun CY, ‘Shadow AI: Cyber Security Implications, Opportunities and Challenges in the Unseen Frontier’ (2025) 6 SN Computer Science 405, Accessed 17 September 2026.↩
- 30.Ross JAJ, Hibbert L and Moss EJ, ‘Shadow AI: Governance, Risk, and Organisational Resilience’ (IEEE 2025); Shaik AS, ‘Shadow Ai as Governance Failure’ (working paper, Golden Gate University, 2026).↩
- 31.Ross JAJ, Hibbert L and Moss EJ, ‘Shadow AI: Governance, Risk, and Organisational Resilience’ (IEEE 2025).↩
- 32.Shaik AS, ‘Shadow Ai as Governance Failure’ (working paper, Golden Gate University, 2026).↩
- 33.Ibid.↩
- 34.Ibid.↩
- 35.Ibid.↩
- 36.Ibid.↩
- 37.Ibid.↩
- 38.Dong et al., Shadow Ai Thrives Under Punitive Social Evaluation (2025).↩
