Shadow AI in the Stockroom What Employees Reaching for Unapproved Tools Are Actually Telling You About the Process
When a warehouse coordinator or buyer runs a prompt on a personal device, the compliance flag is the surface. Underneath it is a process diagnostic: where friction lives in your approved stack, and how far behind that stack has fallen. What your organization does next depends on who owns the response.

The room at 2:30pm
It is 2:30pm on a Wednesday. The governance review started on time. The IT lead is walking through a slide from the organization's endpoint monitoring system, and the number on the slide is fourteen: fourteen instances of unapproved AI tool usage detected on personal devices in the past thirty days. The VP of operations is sitting two seats to the left of the presenter. An hour before this meeting, her director had sent a message flagging a discrepancy in the weekly receiving report, the kind that requires pulling from three systems and then manually reconciling what they disagree on. She had planned to work through that before EOD. Instead she is in this room. The slide does not say what those fourteen people were trying to do. It says they did it on personal devices, on unapproved tools, and that this represents a compliance exposure. The room agrees. Someone mentions policy tightening. Someone else mentions a monitoring escalation. The conversation moves toward remediation. She does not say what she is thinking, because she does not have the air cover to reframe a compliance conversation that has already decided what it is about. She is thinking: those fourteen flagged devices are a process map. When people reach for personal devices and unapproved tools, they are marking the exact coordinates where the approved process broke down. That information belongs in the governance room before the remediation plan is set, and this post is about why it almost never gets there, and what it costs when it doesn't.
TL;DR
The research on shadow AI has grown dense and fast. Here are the numbers that matter most for operations leaders in retail.
81% of employees use unapproved AI tools (UpGuard, 2025)
UpGuard's 2025 State of Shadow AI report, drawn from 542 security leaders and 1,020 employees globally, found 81% of the general workforce and 88% of security leaders using unapproved AI tools (UpGuard, 2025). The pattern runs through every layer of an organization, not only the departments with the loosest controls.
30% of AI users rely on personal apps only (Netskope, 2026)
As of mid-2026, Netskope's AI Report 2026 found that 30% of enterprise AI users run exclusively on personal, unmanaged applications. A trend toward managed accounts stalled and reversed around March 2026.
AI governance frameworks lag far behind AI adoption, with only 8% of organizations maintaining comprehensive oversight (Economist Impact, 2024)
McKinsey's State of AI 2025 report found 78% of organizations had adopted AI in at least one business function, up from 55% the prior year (McKinsey, 2025). Economist Impact research published in 2024 found only 8% of organizations maintain a comprehensive AI governance framework (Economist Impact, 2024). Usage has scaled. Oversight has not.
Shadow AI is widespread: 69% of organizations report evidence of employees using banned AI tools (Gartner, 2025)
Gartner surveyed 302 cybersecurity leaders from March to May 2025 and found 69% of organizations suspect or have confirmed evidence of employees using prohibited public generative AI (Gartner, 2025).
Providing a sanctioned route moves people onto it
Netskope's 2026 Japan-specific data showed that when organizations provided enterprise-grade managed alternatives, the shift from personal to managed accounts was dramatic and rapid. The behavioral change was not driven by policy. It was driven by removing the gap between what was convenient and what was permitted.
AI is a stated top priority for retail and CPG executives, yet measurable returns remain rare (Deloitte, 2026)
Deloitte's 2026 survey of 200 retail and CPG executives found this gap. 75% call AI a top strategic priority, but only 16.5% can quantify a return (Deloitte, 2026). The implementation has moved faster than the understanding of what it is delivering, or failing to deliver.
What shadow AI is actually measuring
The VP sitting in that governance review knows something the IT lead's slide does not contain. She knows what a discrepancy report actually looks like at the receiving dock. She has seen the process: the warehouse coordinator pulls the vendor packing slip, opens the WMS to check what was expected, opens a second system to pull the PO, and then sits with three documents that do not speak to each other and a time window that closes in twenty minutes before the inbound truck needs to be released. The synthesis step, reading across those three sources, identifying the discrepancy, drafting a readable summary for the buyer who needs to decide whether to accept, reject, or escalate, that step has no approved tool. The WMS records. The ERP calculates. Nothing synthesizes and narrates. So the coordinator opens ChatGPT on a personal phone, pastes in what she has, and asks it to reconcile and summarize. The task takes four minutes instead of twenty-five. The truck gets released. That is one of the fourteen flagged instances. Netskope's AI Report 2026 documented that 30% of enterprise AI users are still running exclusively on personal, unmanaged applications, even after years of enterprise AI investment (Netskope, 2026). A migration trend toward managed accounts stalled and reversed around March 2026. That reversal is not random. It tracks with implementation stalls, with approved tools scoped for the use case a vendor pitched rather than the use case the floor actually has, and with change management programs that prioritized access controls over workflow redesign. The fourteen flagged instances in the compliance slide are fourteen workflow steps your approved stack cannot complete at the speed the job requires. They are flags planted in your process map. Before the remediation plan is locked in, someone needs to write down what each of those fourteen people was trying to do.
The J.Caresse point of view
I want to say something about that governance room, because I have sat in versions of it, and I know what it costs to stay quiet. There is a specific kind of silence that happens when you can see the right read of a situation and you also know you do not have the air cover to say it. You do the math very fast. If I reframe this as a process diagnostic right now, I am contradicting the IT lead in his own presentation, in a room where he has the slide and I have a hunch and no data organized in a form anyone here will accept. So I stay quiet. I let the compliance frame win. I tell myself I will raise it separately, in a different conversation, with better preparation. Sometimes that separate conversation happens. Very often it does not, because the remediation plan gets built in the forty-eight hours after the governance review, and by the time I am ready to make the case for the process read, the policy response is already drafted. What I have learned, slowly and with some cost, is that the decision to stay quiet in that room is not neutral. It is a choice. And it is a choice I sometimes made before I even walked in, because I had already decided in advance what was possible there. I am not saying you should have picked a different fight at 2:30pm on a Wednesday in a room that had already organized around compliance. I am saying: before the meeting ends, write down what each of those fourteen flagged instances was trying to accomplish. One sentence per instance, if you know it. Two or three instances if that is all you can reconstruct. You do not need air cover to do that. You do not need to reframe anything out loud. You need a piece of paper and five minutes before the remediation discussion closes. That note is the process map. It is what you bring to the separate conversation. And it is, very concretely, the thing that determines whether the response to those fourteen flags produces a policy or produces a redesign. The AI implementations I have watched fail in retail operations, over and over and over, have not failed because the tool was wrong. They failed because the process the tool was dropped into was not redesigned to meet the tool. Or because the tool was scoped for a use case that looked clean in the vendor pitch and did not map to the messy reality of how buying, planning, or receiving actually works on a Tuesday morning. Shadow AI is the floor telling you this, in real time, with specificity. What you do with that information starts with whether you write it down before you leave the room.
Where the friction shows up in retail operations specifically
Retail and consumer operations have a particular shadow AI problem because the jobs that generate the most unapproved usage are concentrated in the middle layers: buyers, planners, warehouse coordinators, store operations managers. These are roles that require rapid synthesis across multiple systems, high-frequency decisions under time pressure, and constant translation between structured data and unstructured judgment. Active AI deployment in retail reached 58% in 2026, a 16-point jump in a single year, according to NVIDIA's State of AI in Retail and CPG report (NVIDIA, 2026). The CIOs who approved that deployment mostly aimed it at customer-facing and forecasting functions. Associate-facing and operations-layer tools were planned for later. The operations layer did not wait. The approved stack in most retail operations organizations was designed from the top down: what the enterprise needs to govern, audit, and secure. Shadow AI emerges bottom-up: what the person doing the job needs to get through the next two hours. When those two designs do not meet, the gap fills itself with whatever the employee already knows how to use on a Saturday afternoon. Consider what the buyer's morning actually looks like before her 8am planning call. The ERP is not fully responsive until the overnight batch completes, usually around 7:30am on a good day. She has a reorder decision to bring to the call. She needs to pull sell-through from one system, on-hand from a second, and vendor lead times from a shared spreadsheet that was last updated by someone who is now on leave. The synthesis step, turning those three inputs into a readable reorder rationale, has no approved home. So at 7am she opens Claude on her phone and she builds the summary she needs. That is flagged. That is one of the fourteen. BCG and the Consumer Goods Forum's 2026 survey of senior retail and CPG executives found that nearly half of CPG executives identified a core commercial process as their top priority for AI, yet only 11% had scaled AI there (BCG and Consumer Goods Forum, 2026). The employee reaches for a personal device because the approved tool does not do what the job requires, or requires three more steps to do the same thing.
The mechanism: why people reach for personal tools
The research on why employees use unapproved AI is more instructive than the research on how many do it. PagerDuty's 2026 Shadow AI Survey, conducted by Wakefield Research among 1,250 office professionals at organizations with at least $500 million in annual revenue across four countries, found that 89% of workers who use AI for work first encountered the tool in their personal lives (PagerDuty, 2026). The pathway into the enterprise is consumer-to-enterprise, not the reverse. No enterprise procurement cycle runs at consumer adoption speed. By the time an organization has evaluated, contracted, configured, and trained on a tool, the floor has been using the public version for eight months. UpGuard's 2025 research found a positive correlation between employees reporting that they understand AI security requirements and those employees using unapproved tools regularly (UpGuard, 2025). Knowing the rules does not stop the behavior. What stops the behavior is removing the gap between the sanctioned option and the convenient one. Netskope's cross-market data confirms this: where organizations provided a managed alternative with feature parity, personal account usage dropped fast. This is the mechanism the compliance frame misses. The coordinator who opened ChatGPT in the receiving dock was not confused about the rules. She knew. She opened it anyway because the approved path required more time than the task had. The behavioral driver is friction, not awareness. A policy response addresses the awareness. A process response addresses the friction.
The one thing to do before the meeting ends, and what comes after
Go back to 2:30pm. The remediation discussion is about to start. The operations leader in that room has one thing she can do right now that does not require air cover, does not require reframing the conversation out loud, and takes five minutes. Write down what each flagged instance was trying to accomplish. One sentence per instance. What task created the pull toward the personal device? That is the single ask in this piece. One decision, before the meeting ends. If you know four of the fourteen and not all fourteen, write down the four. If you can only reconstruct two from context, write down the two. The specificity matters more than the completeness. A remediation plan built on those two sentences is already a better plan than one built on the compliance slide alone. The three-question diagnostic that follows belongs in the conversation after that note exists. It is not the ask for 2:30pm. It is what the note makes possible. For that later conversation, here is the sequence.
What job was the person trying to do?
Not what did they do with the tool, but what task in their workday created the pull. A warehouse coordinator prompting for discrepancy analysis is telling you that the receiving reconciliation process has a synthesis step the approved tools do not support at the speed the job requires. That is the process gap. The synthesis step in a receiving reconciliation typically means: reading the vendor packing slip against the PO quantity, identifying line-level discrepancies, and producing a summary the buyer can act on. If none of the approved tools produce that summary without manual formatting, the gap is at the output stage, not the data stage.
Where in the approved workflow does friction concentrate?
Map the unapproved usage back to a specific step in the current-state process. Is it at the data-gathering stage, where the approved tool requires pulling from too many systems? At the synthesis stage, where the output requires human formatting the tool does not do? At the communication stage, where the person needs a readable artifact in a format the system does not produce? The type of task tells you which step is broken.
Who owns the response?
This is where IT governance and business operations diverge. If IT owns the response, the likely action is a policy tightening, a block, or a monitoring escalation. If the business owns the response, the likely action is a process redesign question: what would the approved stack need to look like for this task not to generate a workaround? Both have a role. The problem is when only one of them is in the room when the remediation plan is written.
The governance split that determines what happens next
Deloitte's State of AI in the Enterprise, which surveyed 3,235 senior leaders across 24 countries from August to September 2025, is clear on one point: enterprises where senior leadership actively shapes AI governance achieve significantly greater business value than those that delegate governance to technical teams alone (Deloitte, 2026). The survey split equally between IT and line-of-business leaders, and the findings from that split are the relevant part. Deloitte's 2026 State of AI Adoption in Retail and CPG survey of 200 executives found that 54% of AI strategy ownership sits with tech leaders, not the P&L owners who have to deliver business results from it (Deloitte, 2026). The structural failure tends to be binary: organizations either lock AI inside technical teams, creating bottlenecks that starve adoption, or they open access without governance, generating exactly the shadow AI problem described above. What the organizations closing that gap share is that business teams own AI workflows and IT owns how those workflows operate. Those are different responsibilities, and they require different people in the room. In a governance review where only IT is presenting, the frame is almost always compliance and risk. That is a legitimate frame. Sensitive data pasted into unmanaged tools is a real exposure. PagerDuty's 2026 survey found that employees have shared work-related information with public AI tools at meaningful rates, including customer data and financial information or confidential documents (PagerDuty, 2026). But the compliance frame applied alone produces blocking rather than redesign. And blocking, the data is clear, does not eliminate the behavior. UpGuard's 2025 report found that 45% of workers find workarounds to access blocked applications (UpGuard, 2025). Blocking converts a visible compliance problem into an invisible one. The operations leader who is thinking about why those fourteen employees did what they did, and what it means about the process they are supposed to be using, needs air cover to say that out loud in a room that has already organized around the risk frame. Most people do not have that air cover at 2:30pm on a Wednesday. The note she writes before she leaves the room is what creates the opening for that conversation to happen somewhere else, with something more than a hunch.
What the data says about making the approved path more attractive
The most instructive finding in the 2025-2026 shadow AI research concerns what actually reduces unauthorized usage, and the mechanism is consistent across the data. Netskope's AI Report 2026 documents a gradual migration away from personal AI apps toward organization-managed apps since 2023. That migration slowed and reversed around March 2026, and as of the report's publication date 30% of AI users are still on personal apps only (Netskope, 2026). The report's reading of the reversal: organizations opted to place guardrails around personal and unapproved apps rather than continuing to move users onto managed platforms. Guardrails without capability parity do not move people. They generate invisible workarounds instead of visible ones. The organizations that did move users fully onto managed platforms showed a consistent mechanism. Netskope's Japan-specific 2026 data found that when organizations provided enterprise-grade managed alternatives, the shift from personal to managed accounts was rapid and durable. Policy enforcement produced compliance on paper. Closing the capability gap produced actual behavior change. In retail operations terms: the buyer who opens Claude at 7am before the ERP batch completes is telling you the approved tool is unavailable, not fast enough, or unable to perform the specific synthesis she needs before her 8am call. Close that gap and the shadow usage closes with it. The reorder rationale she is building in Claude in twelve minutes, from three disconnected sources, is the synthesis step your approved stack does not support. That is the gap to close. A policy that blocks Claude does not build that synthesis capability. It just makes the behavior harder to see. Grant Thornton's 2026 AI Impact Survey found that organizations with fully integrated AI are nearly four times more likely to report revenue growth than those still piloting, 58% versus 15% (Grant Thornton, 2026). The distance between piloting and integration is, in most retail organizations, a process design problem sitting in front of a technology problem.
The contrarian point the compliance conversation misses
The standard governance response to shadow AI is a policy: define permitted tools, restrict everything else, monitor for violations, escalate when violations occur. Compliance matters, and policy has a place. What policy alone cannot do is explain why fourteen people reached for a personal device, or what they were trying to accomplish faster than the approved stack allowed. In a year when active AI deployment in retail jumped 16 points to 58% (NVIDIA, 2026), running a compliance-first response to shadow AI optimizes for risk reduction in a context that is expanding regardless of what the policy says. The employees reaching for personal tools are a leading indicator of where the approved stack is underpowered for the job. They are doing process auditing your organization has not formally commissioned, and they are doing it in real time, at the exact workflow steps where the friction is highest. The Awareways 2025 Trend Report found that the vast majority of AI usage in the workplace occurs without IT visibility (Awareways, 2025). In retail operations, the workflows generating the most shadow AI usage, the receiving dock, the buying desk, the DC floor, were never inside the governance perimeter to begin with. They were not excluded by accident. They were excluded because AI governance frameworks in most organizations were written for the functions that requested them, not for the functions that needed them most. The organizations that will close the gap between piloting and integration in retail are the ones that treat the shadow AI log as a roadmap for where to build next. The fourteen flagged devices are a process map. Read them that way before the remediation plan is set.
What could go wrong
The framework above is useful and it has real failure modes.
The diagnostic conversation gets captured by IT before the business can engage
If the shadow AI report goes to the CISO and stays there, the process redesign question never gets asked. The operations leader who sees the log as a process map needs to be in the room, or to have a note ready, before the remediation plan is written. The window is shorter than it feels from inside the governance review.
The approved alternative is built for governance, not for the job
If the response to shadow AI usage is to build a managed version of the same tool with more access controls and a longer approval queue, the friction increases rather than decreases. The sanctioned route has to be genuinely faster and more capable for the specific synthesis step the shadow tool was handling. Safer alone will not move people off the personal device.
Sensitive data exposure in the meantime is real
PagerDuty's June 2026 Shadow AI Survey found that employees have shared work-related information with public AI tools at meaningful rates: 34% customer data, 31% financial information or confidential documents (PagerDuty, 2026). The process diagnostic frame does not reduce that exposure while the redesign is in progress. A parallel data governance track is not optional.
The process mapping exercise becomes a research project
Reading shadow AI as a process diagnostic only works if it produces a prioritized list of friction points and a person accountable for fixing each one. If it produces a presentation and a follow-up meeting request, the behavior will not change and the next compliance slide will show a larger number.
Shadow AI governance is overtaken by agentic AI before it is resolved
Netskope's 2026 AI Report identifies a new layer of complexity: agentic AI. Active agents in the Microsoft 365 ecosystem grew 15x year over year according to Microsoft's 2026 Work Trend Index (Microsoft, 2026). Unlike a chat interface, an agent can take actions autonomously. The governance frameworks most organizations are building now were designed for supervised prompting. They were not designed for autonomous action, and the shadow AI problem in its current form will be overtaken by that question before most organizations have resolved the chat-interface version.
Key takeaways
The research on shadow AI is large. Here is what operations leaders in retail need to carry out of it.
The one thing to do before you leave the governance review
The fourteen flagged devices are a process map. Write down what each one was trying to accomplish before the remediation plan is set. One sentence per instance. That note is what makes the next conversation possible.
Shadow AI is a friction signal, read it as one
Unapproved tool usage concentrates at the exact steps where the approved stack cannot keep pace with the job. The receiving reconciliation synthesis step, the pre-8am reorder rationale, the three-system pull that produces nothing readable: these are where the flags cluster. Map the usage back to the workflow step.
Blocking does not reduce the behavior, it reduces visibility
UpGuard's 2025 data: 45% of workers find workarounds to access blocked applications (UpGuard, 2025). A block converts a visible compliance problem into an invisible one. Visibility is the prerequisite for governance.
Providing a sanctioned alternative that is genuinely better moves people onto it
Netskope's cross-market 2026 data shows that where organizations gave employees a managed tool with real feature parity, personal account usage dropped rapidly. The mechanism is removing the gap between convenient and permitted, not enforcing the distinction between them.
Who owns the response determines what the response is
An IT-owned response to shadow AI is a compliance and monitoring response. A business-owned response is a process redesign response. Both are required. The problem is when only one of them is in the room when the remediation plan is written, and that is almost always what happens at 2:30pm on a Wednesday.
The person who sees the process diagnostic is right, and needs to write it down
The operations leader sitting in that governance review, the one who can see that the fourteen flagged devices are a process map and is calculating whether she has the air cover to say so, is reading the room correctly. The note she writes before she leaves matters more than it looks. A remediation built around policy produces a policy. A remediation built around a redesign produces a redesign. Which one gets built depends on whether someone in that room names what the data is actually showing.
Bring these ideas into the room.
If this essay sounds like the conversation you're sitting with, Jessica responds personally to every inquiry.
More insights.

They Approved the AI Pilot at the End of a Twelve-Hour Day. That Is Where It Went Wrong.

The C-Suite Said Yes to the AI Platform and No to Everything the Platform Needs to Work
