What if the most pressing AI risk facing your organization isn't a sophisticated cyberattack or a rogue agent behaving unexpectedly? What if it's your own leadership team using tools that IT doesn't know exist?
That's the finding from Nitro's research on enterprise AI adoption, which revealed that 68% of C-suite executives have used unauthorized consumer AI tools to work around gaps in their approved tools. In a recent appearance on the Tech Talks Network podcast, Nitro CEO Cormac Whelan made the case that this stat isn't just a governance failure, but rather a symptom of something deeper. Organizations are adopting AI without a framework for deciding where, why, and under what conditions it should be used. Until that framework exists, shadow AI at every level of the business is the predictable result.
Why shadow AI is concentrated at the top of the org chart
The pressure on executives to demonstrate AI progress is enormous and coming from every direction—boardrooms, investor calls, leadership meetings—and the tools themselves have never been easier to access. That combination is producing a specific behavior pattern: executives experimenting on their own because the approved tools either don't exist yet or don't meet the need fast enough.
"The hype and pressure and accessibility—AI is so accessible today," Cormac says. "And the pressure that a lot of executives are feeling, both in their senior management rooms and in their boardrooms, to show that they're making progress, that they're driving to an outcome leveraging AI. I think that's forced them into experimentation."
The instinct to experiment is understandable. But experimentation without a framework means the most senior people in the organization are making case-by-case decisions about which data to expose and which tools to trust, with no shared criteria for either.
What makes document workflows the highest-risk area for unapproved AI use?
The reason this matters more than a typical shadow IT issue comes down to what's inside the files being processed. Documents sit at the center of almost every core business function, and they carry some of the most concentrated confidential information an organization holds.
"Whether it's a procurement document with a supplier, a legal filing, a share purchase agreement, or an employee contract, there's a tremendous amount of highly confidential, domain-specific data in there," Cormac says. "Making sure the security and fidelity of that information is protected, that's what matters."
When an executive runs a contract through an unapproved AI tool to get a quick summary or comparison, they may be handing that data to a system with unknown retention policies, unknown training practices, and unknown access controls. Multiply that across an organization where two-thirds of the leadership team is doing the same, and the exposure adds up fast. That risk is already embedded in the daily workflow of every executive who needed an answer faster than their approved tools could provide one.
How an outcome-first frameworks solve both strategy and governance
The reason executives are reaching for unapproved tools is that they have a business outcome in mind—summarize this contract, extract these figures, compare these terms—but no sanctioned path to get there. Fixing that requires defining the outcomes AI should be delivering across the organization, and only then building the governance around those specific use cases."Sometimes executives get caught up in 'it has to be AI this, it has to be AI that,'" Cormac says. "The question worth asking first is: what's the outcome we're trying to achieve? And how is AI actually helping us get there?"
When the outcome is defined first, governance becomes significantly easier because the scope is clear. What data does this use case require? What sensitivity level does that data carry? What retention and training policies does the tool need to meet? Those questions are answerable when the use case is specific from the outset.
"Our legal team, our finance team, our marketing team all leverage AI," Cormac says. "And it's first starting with how does this help us achieve a better outcome, whether that's through productivity or swiftness to market or the ability to drive better quality into our code or better usability into our product. We start with the outcome in mind first."
Applied at the organizational level, the same discipline holds. When organizations map the outcomes they need, assess where AI genuinely accelerates them, and build governance around those specific deployments, shadow AI stops being an attractive workaround.
How to pressure-test your AI framework
As AI tools proliferate across the enterprise, the question of where data goes and how it's handled becomes a purchasing decision, rather than a compliance exercise. Organizations evaluating AI vendors (or assessing what their executives are already using) need to be asking specific questions: does this tool retain the data put through it? Is that data used to train models? Who has access to it, and under what jurisdiction?
"We've always looked at Europe as the highest common denominator when it comes to regulation around personal data," Cormac explains. "We see it as a strength. When we walk into markets in Asia, Australia, or the US, we're usually operating well above the local data privacy requirements."
Holding vendor selection and internal deployment to the highest available privacy standard rather than the minimum required reduces exposure, simplifies cross-border operations, and builds credibility with customers and partners in regulated industries. If your framework can meet the most demanding data privacy requirements, it can meet all of them.
Closing the gap
The 68% stat is a real indicator of how many executives have a business need that their organization's current AI approach can't meet. And every time one of them reaches for an unapproved tool, they're making a decision about data security, vendor trust, and compliance on behalf of the entire organization without the governance structure to support it.
"Focus on outcomes," Cormac says. "AI should be almost routine, in the background. You should never do anything that puts trust or the transparency of your data at risk. If AI helps enable a better outcome, fantastic. But there are other ways to get there if it doesn't."
The goal is a framework that makes unapproved experimentation unnecessary: one that starts with defined outcomes, deploys AI against those outcomes with clear governance, and holds every tool to the same standards of trust and accountability applied to every other part of the business. For organizations where the majority of the C-suite is already operating outside approved tools, the sooner that framework is in place, the smaller the gap to close.
Listen to the full conversation on the Tech Talks Network podcast, where Cormac discusses shadow AI, how to distinguish genuine innovation from expensive marketing, and why an outcome-first mindset matters more than ever.