Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

AI in the Shadows: Governance Mechanisms Organisations Use to Manage the Risks of Unauthorised AI Tools

Schnitzer, Peggy LU ; Hörnfeldt, Amelie and Bergh, David (2026) SYSK16 20261
Department of Informatics
Abstract
The rapid adoption of generative AI in organisations has given rise to a growing phenomenon known as Shadow AI, which refers to the informal and unsanctioned use of AI tools by employees outside organisational oversight. This study examines what governance mechanisms organisations in Sweden, using Microsoft Copilot, implement to manage risks associated with Shadow AI. A qualitative research approach was adopted, combining semi-structured interviews with fourteen representatives from seven organisations and documentary analysis of internal AI policies. The findings show that organisations implement governance mechanisms across both technical and organisational dimensions, and that neither category is sufficient on its own. The primary risks... (More)
The rapid adoption of generative AI in organisations has given rise to a growing phenomenon known as Shadow AI, which refers to the informal and unsanctioned use of AI tools by employees outside organisational oversight. This study examines what governance mechanisms organisations in Sweden, using Microsoft Copilot, implement to manage risks associated with Shadow AI. A qualitative research approach was adopted, combining semi-structured interviews with fourteen representatives from seven organisations and documentary analysis of internal AI policies. The findings show that organisations implement governance mechanisms across both technical and organisational dimensions, and that neither category is sufficient on its own. The primary risks identified in relation to unsanctioned AI tools were data leakage, output quality and over-reliance, and vendor and supply chain exposure. The study further suggests that Shadow AI is best understood as a structural outcome rather than individual non-compliance, and that restrictive governance approaches risk pushing unsanctioned use further from organisational oversight rather than reducing it. (Less)
Please use this url to cite or link to this publication:
author
Schnitzer, Peggy LU ; Hörnfeldt, Amelie and Bergh, David
supervisor
organization
alternative title
AI i skuggorna: Styrningsmekanismer som organisationer använder för att hantera riskerna med icke-godkända AI-verktyg
course
SYSK16 20261
year
type
M2 - Bachelor Degree
subject
keywords
Shadow AI, Organisational Risk, AI Governance Mechanisms, AI Policy, AI Adoption
language
English
id
9239051
date added to LUP
2026-06-16 10:32:49
date last changed
2026-06-16 10:32:49
@misc{9239051,
  abstract     = {{The rapid adoption of generative AI in organisations has given rise to a growing phenomenon known as Shadow AI, which refers to the informal and unsanctioned use of AI tools by employees outside organisational oversight. This study examines what governance mechanisms organisations in Sweden, using Microsoft Copilot, implement to manage risks associated with Shadow AI. A qualitative research approach was adopted, combining semi-structured interviews with fourteen representatives from seven organisations and documentary analysis of internal AI policies. The findings show that organisations implement governance mechanisms across both technical and organisational dimensions, and that neither category is sufficient on its own. The primary risks identified in relation to unsanctioned AI tools were data leakage, output quality and over-reliance, and vendor and supply chain exposure. The study further suggests that Shadow AI is best understood as a structural outcome rather than individual non-compliance, and that restrictive governance approaches risk pushing unsanctioned use further from organisational oversight rather than reducing it.}},
  author       = {{Schnitzer, Peggy and Hörnfeldt, Amelie and Bergh, David}},
  language     = {{eng}},
  note         = {{Student Paper}},
  title        = {{AI in the Shadows: Governance Mechanisms Organisations Use to Manage the Risks of Unauthorised AI Tools}},
  year         = {{2026}},
}