The Decoupled Enterprise: Shadow AI and the Limits of Symbolic Governance
Abstract
Shadow AI is commonly treated as a security or compliance failure. This paper reframes it as organisational decoupling: governance structures exist, while AI use proceeds beyond them. Drawing on institutional theory, Australian regulation and directors’ duties, it distinguishes symbolic governance from controls enacted at the point of use.
1. Introduction: the visibility paradox
1. Introduction: the visibility paradox
Two findings, published within months of each other, define the current state of enterprise AI governance. McKinsey's most recent global survey reports that 88 per cent of organisations now use AI in at least one business function, up from 78 per cent a year earlier (McKinsey & Company, 2025). Protiviti's 2026 AI Pulse Survey, pointedly titled No Visibility, No Confidence, finds that nearly half of large enterprises lack full visibility into how their employees use AI, and only around 40 per cent have any formal AI governance framework (Protiviti, 2026).
Adoption is a near-universal organisational fact. Oversight of that adoption sits at or below half on every measure available. The space between these two numbers is where shadow AI lives.
The consequences of that space are no longer hypothetical. IBM's 2025 Cost of a Data Breach study found that one in five breaches now involves shadow AI, that such breaches cost an average of US$670,000 more than comparable incidents, and that in 97 per cent of AI-related security incidents the breached organisation had no AI access controls in place at all (IBM, 2025). At the same time, the threat environment is compounding: IBM's 2026 X-Force Threat Index reports AI-accelerated attacks escalating against basic security gaps (IBM, 2026), and Darktrace found 87 per cent of security professionals observed AI-driven threats affecting their organisation over the past year (Darktrace, 2026).
The standard reading of this evidence treats it as a maturity problem: organisations are early in their governance journey and will catch up. This paper advances a different reading. The gap between adoption and oversight is not a lag to be closed by producing more governance, more policies, more committees, more registers. It is a structural feature of how organisations respond to institutional pressure, and it has a name in the organisational literature: decoupling. Until AI governance is understood through that lens, organisations will continue to accumulate governance artefacts while the enacted reality of AI use diverges further from the documented one.
2. Defining shadow AI
2. Defining shadow AI
Shadow AI denotes the use of AI tools and services for organisational work outside formal approval, procurement, and monitoring processes. It spans three distinct forms, each with different visibility characteristics: individual subscriptions to consumer AI tools, often paid on personal cards and invisible to the general ledger; team-level accounts provisioned by managers without procurement involvement; and usage-based API access, where consumption-priced services scale from trivial to material cost without a procurement event. A fourth form cuts across the others: AI capability embedded in already-sanctioned SaaS platforms, activated by vendors and used by staff without any new domain, contract, or approval to observe.
Shadow AI is a descendant of shadow IT but differs from it in three ways that matter for governance design. Consumption-based pricing removes the per-seat cost anchor on which software budgeting rests. Near-zero onboarding friction, a browser and an email address, removes the procurement checkpoint at which oversight traditionally attached. And browser-based delivery leaves no footprint in software inventories, removing the asset register as a source of truth. Each removal strips away an observation point that legacy governance assumed would exist. Shadow AI is not merely faster shadow IT; it is shadow IT with the traditional instrumentation deleted.
The scale is documented, with caveats addressed below. Microsoft and LinkedIn's Work Trend Index found 78 per cent of employees using AI at work were bringing their own tools (Microsoft & LinkedIn, 2024). Torii's 2026 benchmark of enterprise SaaS estates finds the average organisation running more than 830 applications, 61 per cent outside formal IT oversight, with more than half of the most widely adopted shadow applications now AI-first tools (Torii, 2026).
3. The evidence, and a note on its quality
3. The evidence, and a note on its quality
Intellectual honesty requires acknowledging that the evidence base on shadow AI is uneven, and a paper arguing that governance artefacts substitute for governance substance should not itself rest on unexamined numbers.
Three tiers can be distinguished. The first is regulatory evidence: ASIC's review of 624 AI use cases across 23 licensees (ASIC, 2024) and APRA's supervisory observations (APRA, 2026) derive from direct examination of regulated entities and carry no commercial incentive to inflate the problem. The second is large-sample commercial research with published methodology: IBM's Cost of a Data Breach series and McKinsey's global surveys are widely used, though the former's reliance on self-reported incident costs via the Ponemon methodology is a known limitation, and both should be read as directionally rather than precisely reliable. The third tier is vendor telemetry and vendor-commissioned surveys, Protiviti, Torii, Darktrace, which draw on convenience samples and are published by firms with commercial interests in the problem being large. This paper uses third-tier sources only where they converge with the first two tiers, and deliberately excludes the widely circulated per-company cost estimates for shadow AI (figures in the hundreds of thousands of dollars annually), which trace to vendor marketing content without published methodology.
What survives this filter is still a consistent picture. Regulators examining actual entities, researchers surveying thousands of organisations, and vendors instrumenting real estates all observe the same structure: near-universal adoption, minority oversight, and a growing population of AI use that no formal system records.
Exhibit 1. The adoption–oversight gap
| Finding | Figure | Source | Evidence tier |
|---|---|---|---|
| Organisations using AI in at least one function | 88% | McKinsey (2025) | 2 |
| Employees who bring their own AI tools to work | 78% | Microsoft & LinkedIn (2024) | 2 |
| Breaches involving shadow AI | 1 in 5 | IBM (2025) | 2 |
| Added cost per shadow AI breach | +US$670,000 | IBM (2025) | 2 |
| AI incidents where no AI access controls existed | 97% | IBM (2025) | 2 |
| Large enterprises with full visibility into employee AI use | 53% | Protiviti (2026) | 3 |
| Organisations with a formal AI governance framework | ~40% | Protiviti (2026) | 3 |
| Enterprise applications under formal IT oversight | 39% | Torii (2026) | 3 |
| Boards with limited to no AI knowledge or experience | 66% | Deloitte (2025) | 2 |
4. A theoretical reading: decoupling, practice, and routine
4. A theoretical reading: decoupling, practice, and routine
4.1 Governance as myth and ceremony
4.1 Governance as myth and ceremony
Meyer and Rowan (1977) observed that organisations facing institutional pressure adopt formal structures that signal legitimacy, policies, committees, reporting lines, while buffering day-to-day work from those structures. The formal structure functions as myth and ceremony: it satisfies external audiences that the organisation is properly constituted, precisely so that actual work can proceed undisturbed. Bromley and Powell (2012) later sharpened the concept into two variants: policy–practice decoupling, where adopted policies are simply not implemented, and means–ends decoupling, where policies are implemented and complied with but bear no relation to the outcome they nominally serve.
Contemporary AI governance exhibits both variants, often within the same organisation. The acceptable-use policy that no technical control enforces is policy–practice decoupling in its classic form: IBM's finding that 97 per cent of AI-related incidents occurred in organisations without AI access controls (IBM, 2025) is a measurement of exactly this gap. The AI ethics committee that meets quarterly, reviews use cases nobody submits, and reports on a register nobody reconciles against discovered usage is means–ends decoupling: every element operates as designed, and none of it governs anything.
This reading explains a feature of the landscape that the maturity narrative cannot: why governance artefact production has accelerated alongside the growth of ungoverned use. Organisations under institutional pressure, from regulators, insurers, boards, and markets, respond by producing the structures those audiences can inspect. Whether the structures reach the point of use is a separate question that inspection of the artefacts cannot answer. The audit file describes an organisation; it is simply not the organisation that exists.
4.2 Technology-in-practice
4.2 Technology-in-practice
Practice-based studies of technology supply the second half of the explanation. Orlikowski (2000) distinguished between technology as designed or mandated and technology-in-practice, the structure that emerges from what people actually and recurrently do with the tools at hand. An organisation's espoused AI estate is the approved-tools register. Its enacted AI estate is the sum of what employees recurrently do: the open browser tab, the personal subscription, the copilot a SaaS vendor switched on last quarter. Governance regimes built exclusively on the espoused estate govern a fiction.
Routine dynamics completes the picture. Feldman and Pentland (2003) distinguish the ostensive aspect of an organisational routine, the routine in principle, the process as documented, from its performative aspect: the routine as actually performed, adapted in real time to get work done. When an employee under deadline pressure uses an unapproved AI tool because the sanctioned path is slow or absent, they are not engaging in misconduct in any sociologically meaningful sense. They are performing the work routine, and the performance has absorbed a tool the ostensive routine does not mention. This is why prohibition fails as a governance strategy: bans operate on the ostensive routine, while adoption occurs in the performative one. Prohibition does not stop the performance; it stops the performance being visible.
4.3 The implication
Assembled, these three literatures yield the paper's central claim (Figure 1). Shadow AI is not a deviance problem, a training problem, or a tooling problem. It is the predictable product of governance designed to be inspected rather than to operate, symbolic structure decoupled from enacted practice. It follows that the remedy is not more or better artefacts but a change in the kind of governance produced: governance that exists in the flow of work, observable through what employees do rather than what documents say they should do.
5. The regulatory turn: from principles to supervision
5. The regulatory turn: from principles to supervision
The Australian regulatory environment has moved faster than most organisational governance, and the trajectory of that movement is itself evidence for the decoupling thesis, regulators are increasingly designing their interventions around the gap between stated and enacted governance.
ASIC's Report 798, Beware the Gap, reviewed 624 AI use cases across 23 licensees in banking, credit, insurance, and financial advice. Its title names the phenomenon directly:
"When it comes to balancing innovation with the responsible, safe and ethical use of AI, there is the potential for a governance gap, one that risks widening if AI adoption outpaces governance in response to competitive pressures." (ASIC, 2024)
Notably, ASIC's method was to examine actual use cases against governance arrangements, an inspection of the enacted estate, not the espoused one. The finding that governance was lagging deployment at roughly half the licensees reviewed is a regulatory measurement of decoupling.
APRA's Prudential Standard CPS 230, in force since July 2025, deepens the exposure. CPS 230 requires regulated entities to manage operational risk end-to-end across critical operations, including material service providers (APRA, 2023). An entity cannot demonstrate end-to-end operational risk management over an AI estate it has never inventoried; the standard implicitly requires the enacted estate to be known, not merely the approved one. And in April 2026, APRA issued its first AI-specific letter to industry, setting expectations for boards and accountable executives across cyber security, governance, supplier risk, and change management. The letter's central observation, that AI adoption is accelerating while governance, risk management, assurance, and security practices are not keeping pace, is the decoupling thesis stated by the prudential regulator, and it announces an active supervisory program rather than a consultation (APRA, 2026). Among the letter's specific criticisms is overreliance on vendor presentations without genuine examination of model behaviour: symbolic assurance, ceremonially performed.
For directors, the duty of care and diligence under s 180 of the Corporations Act frames the exposure at the individual level (Corporations Act 2001 (Cth) s 180). The jurisprudence on s 180 has consistently required directors to take reasonable steps to inform themselves and to maintain oversight of material risks. A director who cannot answer the questions where is AI used in this business, who owns each use, and what controls operate at the point of use is relying on the espoused estate. Should an incident reveal the enacted estate, as one in five breaches now does, the gap between the two becomes the record against which the reasonableness of the director's oversight is assessed. Deloitte's global boardroom research suggests most boards are poorly positioned for that assessment: two-thirds report limited to no AI knowledge or experience, and nearly a third do not have AI on the board agenda at all (Deloitte, 2025).
6. From symbolic to enacted governance
6. From symbolic to enacted governance
If the diagnosis is decoupling, the design question becomes: what would AI governance look like if it were built to operate rather than to be inspected? Four architectural properties distinguish enacted from symbolic regimes. The register here is deliberately structural rather than operational; the concern is what the architecture must accomplish, not which products accomplish it.
Governance located at the point of use. Symbolic regimes govern at the point of documentation, the policy, the register, the approval form. Enacted regimes place controls where the work happens: centralised gateways through which AI traffic flows, carrying authentication, role-based access, and per-request logging; and centrally managed configuration of AI capability inside sanctioned SaaS platforms. The test of an enacted control is that it produces evidence as a by-product of operating. A gateway log is not a description of a control; it is the control, observed.
Discovery grounded in behaviour, not declaration. Symbolic regimes learn about AI use from self-reporting and procurement records, precisely the channels shadow AI bypasses by construction. Enacted regimes observe authentication behaviour (sign-ups, OAuth grants and their scopes, usage anomalies) and payment flows, surfacing the enacted estate independently of anyone's declaration. This is the empirical correction to the espoused/enacted gap: the organisation measures what its people do rather than what its documents assert.
Economic governance matched to the technology's cost structure. Consumption pricing broke the budgeting assumptions on which software governance rested; an enacted regime rebuilds them deliberately, structuring AI expenditure so that shadow adoption is a predictable, monitored category rather than a periodic surprise, and making the sanctioned path to a new tool fast enough that routing around it stops being rational. The design principle follows directly from the routine-dynamics analysis: if the performative routine absorbs whatever tool is fastest, governance must make the governed tool the fastest.
Accountability located where the levers are. Symbolic regimes assign AI governance to committees with unclear authority, structurally ideal vehicles for ceremony, since they can deliberate indefinitely without controlling anything. Enacted regimes assign it to the roles that hold the levers the architecture requires: the security function owns the control plane and its integration with enterprise risk frameworks; the finance function owns spend visibility and economic alignment; both report to the board on a shared picture of inventory, control posture, and economics. The point is not the particular titles but the principle: accountability must sit with roles that can act on the enacted estate, not merely opine on the espoused one.
Exhibit 2. Symbolic versus enacted AI governance
| Dimension | Symbolic governance | Enacted governance |
|---|---|---|
| Object governed | The espoused estate (approved-tools register, policy documents) | The enacted estate (observed usage, authentication, and payment behaviour) |
| Location of control | Point of documentation | Point of use |
| Source of evidence | Artefacts produced for inspection | Logs produced as a by-product of operation |
| Discovery model | Self-reporting and procurement records | Behavioural telemetry independent of declaration |
| Accountability | Committee with unclear authority | Roles holding operational and economic levers, jointly accountable to the board |
| Failure mode | Gap between documentation and practice widens invisibly | Gap is continuously measured and reported |
The standards environment increasingly encodes the same distinction. ISO/IEC 42001 requires a management system, operating processes with evidence of performance, rather than a policy suite (ISO/IEC, 2023), and the NIST AI Risk Management Framework's Measure and Manage functions presuppose instrumentation of actual AI use (NIST, 2023). An organisation whose governance cannot produce operational evidence will find that gap surfaced not only by incidents but by any serious conformity assessment.
This analysis connects to earlier Strategen AI work in two respects.¹ Within the APIG framing (Actors, Practices, Infrastructure, Governance), shadow AI is the signature of a governance layer specified without reference to the actors and practices it nominally governs, architecture misalignment presenting as employee misbehaviour. And it restates, at the level of individual work practice, the argument made previously regarding board-level AI adoption: that AI scaling failures are organisational architecture failures rather than technology failures. Shadow AI is what that architecture failure looks like from the bottom up.
7. Questions for boards
7. Questions for boards
The practical output of this analysis for directors is not a program plan but a set of questions that distinguish symbolic from enacted governance. Each is answerable only by an organisation observing its enacted estate.
What is the gap, in count and in spend, between our approved AI register and our discovered AI usage, and when was it last measured? Which controls on AI use operate technically at the point of use, and which exist only as policy? For AI capability embedded in our sanctioned SaaS platforms, who decided what is enabled, and on what evidence about model behaviour? Through what channel would we learn, within days rather than quarters, that a material new AI dependency had formed? And who, by name and role, is accountable for the enacted estate, not the policy suite?
A board that cannot obtain answers has learned something important: not that its organisation lacks AI governance, but that its AI governance is symbolic. Under CPS 230 and the April 2026 letter, APRA-regulated entities should expect their supervisor to reach the same conclusion by the same method.
8. Limitations and an empirical agenda
8. Limitations and an empirical agenda
Three limitations bound this argument. First, the evidence base, as Section 3 acknowledges, is dominated by commercial research; the regulatory evidence is direct but jurisdictionally and sectorally narrow. Second, the decoupling reading is an interpretive framework applied to aggregate data, not a tested hypothesis; alternative explanations, genuine transition lag chief among them, cannot be excluded on current evidence, though the acceleration of artefact production alongside ungoverned use sits awkwardly with a pure lag account. Third, the paper's architectural prescriptions are derived from theory and regulatory expectation rather than from outcome data, which does not yet exist at scale.
Each limitation defines a research opportunity. The decoupling thesis is directly testable: the gap between an organisation's espoused AI estate (its register) and its enacted estate (its discovered usage) is measurable, comparable across organisations, and trackable over time. A body of empirical work measuring that gap, its size, its correlates, its response to different governance architectures, would convert the argument of this paper from interpretation into evidence, and would give boards the benchmark that currently does not exist: not do we have AI governance? but how decoupled is ours?
9. Conclusion
9. Conclusion
The organisations accumulating AI policies, committees, and registers are not failing to govern AI. They are governing it symbolically, producing the structures that institutional audiences inspect, while the enacted reality of AI use diverges beneath them. The literature predicted this pattern half a century before generative AI supplied its sharpest instance. What is new is the speed at which the gap widens, the price attached to it, one in five breaches, at a premium, and the arrival of regulators who have stopped inspecting the artefacts and started inspecting the gap itself.
That last development should concentrate attention. ASIC measured the space between deployment and governance and titled its report after it. APRA has announced a supervisory program aimed at precisely the distance between adoption and practice. The gap between the espoused and the enacted estate is no longer a private organisational condition; it is becoming the object of supervision. The question facing boards is therefore not whether the gap will be discovered, but by whom, a supervisor, an attacker, or the organisation itself, and only one of those discoveries happens on terms the board chooses.
¹ Disclosure: the APIG framework and the board AI operating model argument referenced here are the author's prior work, published through Strategen AI.
References
APRA. (2023). *Prudential Standard CPS 230 Operational Risk Management.* [APRA](https://www.apra.gov.au/operational-risk-management) APRA. (2026, April 30). *APRA letter to industry on artificial intelligence (AI).* [APRA](https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai) ASIC. (2024, October 29). *Report 798: Beware the gap — Governance arrangements in the face of AI innovation.* [ASIC](https://www.asic.gov.au/regulatory-resources/find-a-document/reports/rep-798-beware-the-gap-governance-arrangements-in-the-face-of-ai-innovation/) Bromley, P., & Powell, W. W. (2012). From smoke and mirrors to walking the talk: Decoupling in the contemporary world. *Academy of Management Annals, 6*(1), 483–530. *Corporations Act 2001* (Cth) s 180. Darktrace. (2026). *State of AI cybersecurity 2026.* [Darktrace](https://www.darktrace.com/blog/state-of-ai-cybersecurity-2026-87-of-security-professionals-are-seeing-more-ai-driven-threats-but-few-feel-ready-to-stop-them) Deloitte Global Boardroom Program. (2025). *Governance of AI: A critical imperative for today's boards* (2nd ed.). [Deloitte](https://www.deloitte.com/global/en/issues/trust/progress-on-ai-in-the-boardroom-but-room-to-accelerate.html) Feldman, M. S., & Pentland, B. T. (2003). Reconceptualizing organizational routines as a source of flexibility and change. *Administrative Science Quarterly, 48*(1), 94–118. IBM. (2025). *Cost of a data breach report 2025.* [IBM](https://www.ibm.com/reports/data-breach) IBM. (2026, February 25). *IBM 2026 X-Force Threat Index: AI-driven attacks are escalating as basic security gaps leave enterprises exposed.* [IBM Newsroom](https://newsroom.ibm.com/2026-02-25-ibm-2026-x-force-threat-index-ai-driven-attacks-are-escalating-as-basic-security-gaps-leave-enterprises-exposed) ISO/IEC. (2023). *ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system.* [ISO](https://www.iso.org/standard/42001) McKinsey & Company. (2025, November 5). *The state of AI in 2025: Agents, innovation, and transformation.* [McKinsey](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai) Meyer, J. W., & Rowan, B. (1977). Institutionalized organizations: Formal structure as myth and ceremony. *American Journal of Sociology, 83*(2), 340–363. Microsoft & LinkedIn. (2024, May 8). *2024 Work Trend Index annual report: AI at work is here. Now comes the hard part.* [Microsoft](https://news.microsoft.com/source/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/) NIST. (2023). *Artificial Intelligence Risk Management Framework (AI RMF 1.0).* [NIST](https://www.nist.gov/itl/ai-risk-management-framework) Orlikowski, W. J. (2000). Using technology and constituting structures: A practice lens for studying technology in organizations. *Organization Science, 11*(4), 404–428. Protiviti. (2026). *AI Pulse Survey: No visibility, no confidence.* [Protiviti](https://www.protiviti.com/us-en/survey/ai-pulse) Torii. (2026). *2026 SaaS benchmark annual report.* [Torii](https://www.toriihq.com/saas-benchmark-annual-report-2026)