There is a version of this conversation happening right now inside a lot of companies. The executive team sits down to discuss the AI strategy. A senior leader states, with confidence, that the company is being deliberate, that use is limited to a pilot in one department, that a policy is under development. Meanwhile, three different teams in that same organization have already been pasting customer information into a personal-tier AI assistant for six months. Legal has not seen the terms of service. Security has not reviewed the data flow. General Counsel has not been asked. The data those teams uploaded is now sitting in vendor infrastructure, or being used to improve a model, or both. It does not come back.
That is the new evolution of Shadow IT. Same governance failure, different tool, running through most enterprises right now whether the executive team has decided to see it or not.
The rip cord is gone
Every previous chapter of Shadow IT came with a rip cord. Dropbox instances could be shut down. Unsanctioned SaaS licenses could be revoked. Third-party APIs could be blocked. When the enterprise woke up to the exposure, it could take action and unwind the risk. Personal-tier AI is different.
A prompt pasted into a personal-tier AI assistant is data that has left the enterprise perimeter. Depending on the vendor, that data may be retained, used to improve the model, or ingested into the training set. Once inside the training set, there is no meaningful right to erasure. The data cannot be removed from the model weights. The company has no visibility into which pathway applies. There is no contract because there is no procurement relationship. There is a personal account, a Terms of Service the enterprise has never seen, and a vendor whose interests are not aligned with the enterprise's.
Once the data is in a vendor's retention infrastructure, or memorized by a model, the enterprise cannot pull it back. There is no revocation. There is no takedown. There is no confidentiality claim that reaches inside a foundation model. Cross-user regurgitation is a documented but rare byproduct of the deeper problem, which is training-set ingestion with no recall mechanism. That is the difference between this chapter of Shadow IT and every previous one. The rip cord is gone.
Where the governance gap actually sits
The instinct is to describe this as a tool problem. It is not. The tool is a symptom. The problem is that the enterprise has never had a lower-friction path for data to leave the perimeter.
Every previous data-exit vector produced a signature event. A vendor invoice. A procurement review. A network access request. A file transfer that appeared in logs. Personal-tier AI has none of those. An employee pastes text into a browser. That is the transaction. No invoice, no vendor onboarding, no security review, no procurement gate, nothing for the governance function to see.
That is the real gap: the ease with which data can be moved and ingested without needing any special access. The enterprise built its data-governance apparatus around procurement, network, and vendor management, all of which assume a signature event has to happen for data to leave the building. Personal-tier AI has removed the signature event. The governance apparatus was not designed for this, and it is why the exposure keeps compounding while nobody sees an invoice.
Three exposures the board actually owns
None of these are IT problems. All of them are enterprise-risk problems the executive team carries.
The first exposure is legal and regulatory. Customer data, employee data, and regulated data pasted into a personal-tier assistant is a disclosure event under most privacy regimes. GDPR, CCPA, HIPAA, and sector-specific rules do not care that the disclosure was unintentional. They care that it happened. The enterprise carries the liability. The employee did not read the terms of service. The company did.
The second is intellectual property. Source code, product roadmaps, unpublished financial detail, negotiation strategies, and confidential internal communications pasted into a personal-tier model become vendor-hosted content at minimum, and in some vendor configurations become training material. The enterprise has just handed a future competitor its own thinking, with no chain of custody and no ability to recall it.
The third is brand and market position. When an AI-exposure incident produces a headline, the market will not ask whether the tool was authorized. It will ask why the company let it happen. Sophisticated adversaries, journalists, and regulators are already probing for these leaks. The company that first learns of its own exposure during a Wall Street Journal call is the company that lost the governance fight silently.
What actually works
Three moves separate the enterprises managing this exposure from the ones that discover it during an incident. All three are governance decisions.
The first is closing the friction gap. The enterprise cannot compete with a personal-tier assistant on convenience while the sanctioned option requires a ticket, a training session, and an approval workflow. Enterprise-tier tools like ChatGPT Enterprise, Claude for Work, and Copilot with a Data Processing Agreement contractually disable training on enterprise data. The governance move at most enterprises is channel migration from the personal tier to the enterprise tier, not tool prohibition, at speeds that match how employees already work. Anything else is theater. This is an executive-level spend and priority decision.
The second is moving governance upstream of procurement. The classical model, in which procurement gates new vendors and new data flows, no longer holds. Data-governance controls have to sit at the workflow layer, not the vendor-onboarding layer, because the vendor onboarding no longer happens. That is a redesign of the governance function rather than a policy update. It is the same shift information security made twenty years ago when the perimeter stopped being the network.
The third is naming a senior owner. AI-exposure risk is not owned by IT. Different enterprises are putting ownership at the CAIO, the CRO, the General Counsel, or the CISO. The specific title mix matters less than the fact of named single accountability, coordinated across GC, CISO, and CDO, reported to the board on a defined cadence. If no senior executive owns the exposure, the exposure has no owner, and the failure mode is exactly what the enterprise is doing right now. Naming the owner is a CEO decision, and there is now an international standard that formalizes what the owner is expected to run.
What ISO/IEC 42001 actually is
ISO/IEC 42001, published in December 2023, is the world's first international, certifiable standard for an Artificial Intelligence Management System, or AIMS. It is written in the same shape as ISO/IEC 27001, which every mature enterprise security program already knows. It defines a management-system framework for the responsible use and development of AI. It is auditable. It is certifiable. In the United States, the NIST AI Risk Management Framework is the parallel governance vocabulary. In the European Union, the AI Act's Article 50 transparency obligations became enforceable on 2 August 2026. Enterprises operating across those jurisdictions need a governance model that speaks to all three.
For a senior leader trying to close the exposure above, the standard matters for two reasons. First, it names the discipline. AI management is now a recognized enterprise governance discipline with a defined structure, the same way information security became one twenty years ago. Second, it gives the enterprise something to point at. Regulators, auditors, insurers, and enterprise customers are already asking what the AI governance program is. Being able to answer that question against an international standard, rather than an internal memo, changes the credibility of the answer.
Whether or not the enterprise pursues formal certification, the framework is worth adopting because it forces the questions the current exposure has been hiding. What systems are in use. What risks they introduce. Who owns those risks. And what evidence exists that the owner is managing them.
What the C-suite actually owns
The reflex is to treat this as an IT problem, staff a project, roll out a policy, and move on. That is the same reflex that produced the current exposure. AI-tool governance is an enterprise-risk problem the C-suite owns, in the same way that information security stopped being an IT problem twenty years ago and became a board-level concern.
The specific decisions belong to the executive team. Where to spend to close the friction gap. Whether to accept the current exposure or actively manage it down. Which senior executive owns the risk, and what reporting cadence to the board looks like. What the enterprise position is going to be when a regulator, an auditor, or an enterprise customer asks how AI governance is managed.
None of those questions can be answered by the CIO alone. They are questions the CIO puts on the table. The enterprises that will handle this well are the ones where those questions get asked, and answered, before the incident, not after.
Adam Cooper is a Marine Corps veteran who leads global technology operations across maritime, transportation, hospitality, and industrial environments. He writes about enterprise IT governance, distributed operations at scale, and the executive dynamics of senior technology leadership. Connect on LinkedIn or Send Email.