Governance-first approach needed to counter Shadow AIOrganisations should move beyond trying to eliminate Shadow AI and instead focus on governance, visibility and employee education to reduce cyber risk while enabling responsible AI adoption. “Shadow AI risks often do not originate from malicious intent and the use of AI tools to improve productivity is primarily driven by the good intentions of employees. “Addressing Shadow AI should not only be focused on restricting access to AI tools. “Organisations need to define AI policies and governance processes that align with companies’ environment and goals.” Following a routine review of AI-related firewall activity, the organisation identified dozens of different AI platforms in active use across the business.