AI in the Shadows: Governance Mechanisms Organisations Use to Manage the Risks of Unauthorised AI Tools
(2026) SYSK16 20261Department of Informatics
- Abstract
- The rapid adoption of generative AI in organisations has given rise to a growing phenomenon known as Shadow AI, which refers to the informal and unsanctioned use of AI tools by employees outside organisational oversight. This study examines what governance mechanisms organisations in Sweden, using Microsoft Copilot, implement to manage risks associated with Shadow AI. A qualitative research approach was adopted, combining semi-structured interviews with fourteen representatives from seven organisations and documentary analysis of internal AI policies. The findings show that organisations implement governance mechanisms across both technical and organisational dimensions, and that neither category is sufficient on its own. The primary risks... (More)
- The rapid adoption of generative AI in organisations has given rise to a growing phenomenon known as Shadow AI, which refers to the informal and unsanctioned use of AI tools by employees outside organisational oversight. This study examines what governance mechanisms organisations in Sweden, using Microsoft Copilot, implement to manage risks associated with Shadow AI. A qualitative research approach was adopted, combining semi-structured interviews with fourteen representatives from seven organisations and documentary analysis of internal AI policies. The findings show that organisations implement governance mechanisms across both technical and organisational dimensions, and that neither category is sufficient on its own. The primary risks identified in relation to unsanctioned AI tools were data leakage, output quality and over-reliance, and vendor and supply chain exposure. The study further suggests that Shadow AI is best understood as a structural outcome rather than individual non-compliance, and that restrictive governance approaches risk pushing unsanctioned use further from organisational oversight rather than reducing it. (Less)
Please use this url to cite or link to this publication:
https://lup.lub.lu.se/student-papers/record/9239051
- author
- Schnitzer, Peggy LU ; Hörnfeldt, Amelie and Bergh, David
- supervisor
- organization
- alternative title
- AI i skuggorna: Styrningsmekanismer som organisationer använder för att hantera riskerna med icke-godkända AI-verktyg
- course
- SYSK16 20261
- year
- 2026
- type
- M2 - Bachelor Degree
- subject
- keywords
- Shadow AI, Organisational Risk, AI Governance Mechanisms, AI Policy, AI Adoption
- language
- English
- id
- 9239051
- date added to LUP
- 2026-06-16 10:32:49
- date last changed
- 2026-06-16 10:32:49
@misc{9239051,
abstract = {{The rapid adoption of generative AI in organisations has given rise to a growing phenomenon known as Shadow AI, which refers to the informal and unsanctioned use of AI tools by employees outside organisational oversight. This study examines what governance mechanisms organisations in Sweden, using Microsoft Copilot, implement to manage risks associated with Shadow AI. A qualitative research approach was adopted, combining semi-structured interviews with fourteen representatives from seven organisations and documentary analysis of internal AI policies. The findings show that organisations implement governance mechanisms across both technical and organisational dimensions, and that neither category is sufficient on its own. The primary risks identified in relation to unsanctioned AI tools were data leakage, output quality and over-reliance, and vendor and supply chain exposure. The study further suggests that Shadow AI is best understood as a structural outcome rather than individual non-compliance, and that restrictive governance approaches risk pushing unsanctioned use further from organisational oversight rather than reducing it.}},
author = {{Schnitzer, Peggy and Hörnfeldt, Amelie and Bergh, David}},
language = {{eng}},
note = {{Student Paper}},
title = {{AI in the Shadows: Governance Mechanisms Organisations Use to Manage the Risks of Unauthorised AI Tools}},
year = {{2026}},
}