On May 7, 2026, a community bank in Pennsylvania filed something no public company had filed before. Its Form 8-K disclosed a material cybersecurity incident, as the SEC rules require, but there was no attacker in it. The bank had “become aware of an internal incident involving the handling of certain non-public customer information using an unauthorized artificial intelligence-based software application.” Names, Social Security numbers, dates of birth. An employee, a tool nobody had approved, and a regulatory filing that will be read by every bank’s board for years.
The uncomfortable part is that this bank almost certainly had a shadow AI program. Most enterprises do by now. The problem is not that leaders are ignoring shadow AI; it is that the programs they built rest on assumptions that were reasonable two years ago and are wrong today. We have written before about the two biggest ones: that blocking makes the problem smaller, when the data says it drives usage underground, and that shadow AI is purely a threat, when it is also the clearest demand signal a company will ever get for free. This post is about the seven mistakes that come after those two, the ones that quietly make a well-intentioned program worse.
1. Counting apps instead of interactions
The first number every shadow AI program produces is a count of tools. It is a natural place to start, and it is almost meaningless. Zscaler’s ThreatLabz saw AI traffic to more than 3,400 distinct applications in 2025, and the volume of data moving to those tools grew 93% in a year. A catalog of 3,400 names tells you nothing about which forty of them matter. Cyberhaven’s 2026 report found that the most aggressive adopters use 300 or more generative AI tools while cautious enterprises use fewer than 15, yet the share of data movements into AI that involve sensitive content, 39.7%, does not follow the app count at all.
The unit that carries risk and value is the interaction: who sent what, to which tool, for which task. A note-taking app with two users and a spike in data-processing prompts is a bigger exposure than a writing assistant with two hundred users drafting emails. The Olakai Shadow AI overview charts interaction volume by app and by task category precisely because a jump in “Analysis” or “Data Processing” is a stronger sensitive-data signal than the same jump in “Writing”. Measure the stream, and the catalog becomes a by-product rather than the goal.
2. Trusting what people tell you
Surveys are cheap, fast, and the only instrument many organizations had when the question first came up. They are also systematically low. A University of Chicago study presented at CHI 2026 asked the same population two questions: do you use AI, and do your peers? About 60% admitted to their own use while estimating 90% for everyone else. The subjects were students, not employees, and the gap is worth stating with that caveat. But the mechanism the authors identified, social desirability bias driven by concern about looking less competent, is not a student phenomenon. Ask a finance team whether they paste figures into a free chatbot and you will get the compliant answer, not the true one.
The fix is to replace the questionnaire with telemetry. Usage captured at the point it happens, in the browser, at the API, or in the developer’s terminal, does not have a social-desirability problem. It also does not need to be repeated every quarter. Self-reporting still has a place for understanding why people chose a tool, but it should never be the number that goes to the board.
3. Declaring victory after buying the sanctioned tool
Procuring an enterprise copilot is the right move, and it is also the moment many programs stop looking. The assumption is that once a sanctioned tool exists, the unsanctioned ones fade. The telemetry says otherwise. LayerX’s 2026 usage report found that 14.39% of AI conversations conducted under a corporate identity still ran through personal licenses, and Cyberhaven put personal-account usage of ChatGPT at 32.3% and Gemini at 24.9%, inside companies that in many cases had already bought the enterprise edition. People keep the side tool because it is better for a specific task, or because it was already open, or because the licensed one is locked behind a request form.
The sanctioned purchase is the beginning of a measurement problem, not the end of one. You now need to know how many of the seats you paid for are idle, which teams kept the alternative, and what they are doing in it. Olakai Assistive puts the licensed tool and the shadow tool in the same catalog, with seat counts and per-seat cost against actual usage, so the question “did the purchase work” has an answer other than the invoice.
4. Running a snapshot instead of a stream
A one-time AI visibility audit is a good first act. Treating it as the finished product is the mistake, because the inventory is accurate for roughly as long as it takes someone to sign up for something new. Verizon’s 2026 Data Breach Investigations Report recorded the share of workers using AI on corporate devices tripling from 15% to 45% in a single year. An audit from last spring describes a company that no longer exists.
Continuous detection changes the shape of the work. Instead of a project that ends with a slide deck, you get a queue: newly detected apps land in review, someone classifies them as authorized, monitored, or unauthorized, and the alerts fire on the unauthorized ones from then on. The review queue is never empty, and that is the point. It is the difference between knowing what your organization used and knowing what it is using.
5. Never reading the terms
Most shadow AI risk discussions focus on what an employee might paste. Far fewer look at what the vendor is allowed to do with it afterwards, and the answer sits in plain sight in the terms of service. Anthropic’s consumer terms, updated in August 2025, allow training on Free, Pro, and Max account data when the setting is on, and extend retention to five years for those who allow it. Google’s Gemini privacy notice says a subset of chats are reviewed by human reviewers, that reviewed chats are kept for up to three years even after a user deletes their activity, and, in its own words, “please don’t enter confidential information that you wouldn’t want a reviewer to see.” None of this is hidden. It is simply never read by the person signing up with a work email on a Tuesday afternoon.
Those are the consumer tiers of two of the most responsible vendors in the market. The long tail of 3,400 tools includes far looser terms on data retention, third-party sharing, and who owns the output. This is the layer of shadow AI risk that is contractual rather than technical, and it is why Olakai generates an EULA Risk Assessment for every detected app, scoring its terms across AI training, content license, data retention, third-party sharing, and IP ownership, with the source excerpt attached so a reviewer can read the clause instead of trusting the score.
6. Governing people instead of data
When a policy is written in a hurry, it tends to name users and tools: marketing may use this, engineering may not use that. It is understandable, because people and tools are what you can see. But the bank in the opening did not have a people problem or a tool problem. It had Social Security numbers in a place they should never have been, and that would have been true whichever employee and whichever application were involved. LayerX found that around 6% of enterprise AI conversations contain sensitive data. A blanket ban on a team or a tool mistargets the other 94%, and misses the 6% that moves to a tool you have not banned yet.
Governance that follows the data is tool-agnostic by construction. A rule that flags a prompt containing PII, PHI, a credential, or source code applies equally to the sanctioned copilot and to the app discovered yesterday, which is what makes it durable. That is how Olakai’s sensitivity detection works: it reads what leaves the organization, validates structured data like card numbers and national IDs, and flags interactions by what they contain rather than by who sent them. The employee-facing acceptable-use policy still matters, but it rides on top of data rules rather than replacing them.
7. Assuming the browser is the whole story
Browser-level visibility is where every serious shadow AI program should start, because that is where most assistive AI use happens, and Olakai’s own Assistive product is built on a browser extension for that reason. The mistake is assuming it is where the story ends. A growing share of AI activity never opens a tab. Browser extensions themselves are AI tools now, and LayerX’s 2026 extension report found roughly one in six enterprise users already running at least one, with AI extensions 60% more likely than others to carry a known vulnerability. Developers call model APIs directly from code and agents. GitGuardian’s 2026 secrets report counted 1.27 million leaked AI-service credentials, up 81% in a year, including 24,000 exposed in MCP configuration files. Each of those keys is an AI integration that no browser monitor will ever see. The unknown agents enterprises keep discovering in their environments are the same problem at larger scale.
Browser detection is necessary, not sufficient. Coverage has to extend to the API, the repository, and the SDK, which is what Olakai Agentic does for coding tools and autonomous agents, so that an engineer’s Claude Code session and a marketer’s ChatGPT tab show up in the same system of record. A program that watches only one of those surfaces is measuring the half of shadow AI that is easiest to see.
None of these are failures of intelligence
Every mistake on this list was the sensible move at the time it was made. Surveys were the only data. Blocking was the only lever. Counting apps was the only report anyone could produce. The organizations getting this right in 2026 are not smarter; they have simply swapped assumptions for measurement, one by one, and found that governance built on an interaction-level, continuous, data-centric view of AI use is both stricter where it matters and more permissive everywhere else. For a CISO, that is the version of shadow AI governance that survives contact with a regulator, and the version that would have kept a Pennsylvania bank out of the 8-K archive.
Which of the seven is your program making? Talk to an expert and we will show you, against your own environment, what interaction-level shadow AI visibility looks like across browsers, APIs, and agents.
