TL;DR SUMMARY: AI adoption has moved faster than most governance processes can comfortably track. Policies matter, although they can’t govern behaviour that security teams cannot see. Organisations need visibility into how people are using AI tools, where sensitive data may be exposed and which behaviours need guidance before shadow AI becomes normalised.
AI adoption as workplace pressure
AI is often described as a technology story, though inside organisations it is also a pressure story. People are asked to move faster, produce more and stretch limited resources further. In that environment, a tool that promises to summarise, draft, analyse or automate can feel less like a novelty and more like relief.
Relief can quickly become invisible. Employees may use consumer AI tools to review contracts, summarise customer notes, rewrite internal documents or troubleshoot spreadsheets (all plausible, useful and risky in the wrong environment). These actions don’t need to begin with bad intent. They’re often practical attempts to get work done, although each one can create a visibility gap if the organisation doesn’t know which tools are being used, what data is being entered and how outputs are shaping decisions.
Theo Botha, Global CISO at Dr. Martens PLC, has 20 years of experience in technology and puts the ambition plainly: “AI is a positive. So we want to enable the use of AI but align it to our governance structure.” That framing avoids the dead end of treating AI (artificial intelligence) as something organisations can simply wish away, while still recognising that enablement needs boundaries, visibility and proportionate control.
Botha describes this as a gap between enablement and governance. His view avoids default blocking and points towards something more useful: policy, awareness and technical guardrails that make responsible use easier to follow than risky workarounds. The distinction is important because people rarely abandon useful tools simply because a policy has arrived after the habit has formed.
When governance feels slow, vague or punitive, people often find another route, especially when deadlines are tight and the promise of faster output is sitting in an open browser tab. A clearer, quicker and safer sanctioned route gives employees something practical to follow, while giving the organisation a stronger chance of seeing how AI is being used before risky habits settle into normal practice.
Shadow AI, governance and the path of least risk
Visibility turns uncertainty into a map. Which teams are using AI most heavily? Are people relying on approved tools, or drifting towards unsanctioned ones? Are prompts exposing commercially sensitive, personal or regulated information? Do certain workflows create repeated AI governance risk because the sanctioned route is too slow, unclear or hard to access?
Once those questions can be answered, organisations can move from blanket anxiety to targeted action. That might include role-specific AI guidance, real-time interventions before sensitive data is shared, clearer acceptable use policies, or additional support for teams under the greatest workload pressure.
That is the kind of space where platforms such as Redflags become relevant, because the emphasis moves from abstract AI policy towards live behavioural support: seeing risky usage patterns, understanding the pressure behind them and intervening while the user still has a chance to choose the safer path.
The challenge reaches beyond stopping shadow AI. Organisations also need to learn what shadow AI is trying to tell them. Often, it signals unmet needs, process friction or unclear routes to safe adoption. When security teams listen to those signals, they can help the business use AI responsibly, before behaviour has gone so far underground that governance becomes a chase instead of a guide.
Key takeaways
- Shadow AI often starts as a productivity workaround instead of deliberate rule-breaking.
- AI governance needs visibility into tools, data flows and decision influence.
- Policies work better when the approved path is clear, practical and usable.
- Real-time interventions can guide safer AI use before risky behaviour is completed.
