Artificial intelligence is entering companies at a dizzying speed that is beginning to generate a new challenge for technology departments: shadow AI. As happened with shadow IT, when employees began to use technological applications and services without the knowledge of the systems department, artificial intelligence tools may be reaching organizations in a decentralized way, without IT having visibility over what solutions are used, what information they process or what tasks and decisions are being delegated to them.

As highlighted by the consulting firm Setesca, the phenomenon of Shadow AI acquires special relevance with the expansion of AI agents, capable not only of generating content or answering questions, but also of executing tasks and participating in work processes. In this context, an employee can incorporate an AI tool, create an automation or use an agent to solve a certain task without there necessarily being corporate criteria about the data they can access, the permissions they must have or the level of human supervision necessary.

Microsoft’s Work Trend Index 2026 points precisely to this gap between the capacity of employees and the preparation of organizations. Only 26% of AI users say their organization’s leadership is clearly and consistently aligned on artificial intelligence.

Adapt structures and processes

The study also identifies an issue especially relevant to business management: organizational factors—such as culture, manager support, and talent practices—explain twice as much of the perceived impact of AI as individual factors. That is, the problem lies not only in employees learning to use technology, but in companies being able to adapt their structures, processes and standards to the new scenario.

For Jordi Damià, CEO of Setesca, “shadow AI is the logical evolution of shadow IT. The difference is that now an employee can not only incorporate an application, but also use it to analyze information, automate processes or even create an agent that executes certain tasks. If the company does not establish an action framework, it can end up having dozens of AI systems operating in parallel without knowing exactly what they do or under what criteria.”

From controlling tools to controlling processes

The challenge for CIOs is not just knowing which AI applications each employee uses. The emergence of agents makes the issue more complex: what processes are being modified by AI, what information these systems use, and who maintains ultimate responsibility for their results.

This transformation of shadow AI coincides with an evolution of the use of AI itself in the work environment. The Work Trend Index 2026 indicates that 16% of workers who use AI can already be considered “Frontier Professional”, a profile that uses agents to develop multi-step workflows, rethinks how work is done and establishes shared standards for its teams.

The appearance of these profiles shows that AI is moving away from being used exclusively as an individual tool and progressively becoming part of work processes. For Setesca, this change forces organizations to move from a policy focused on “what tools the employee can use” to one based on “what AI can do within the organization and under what conditions.”

“The CIO can no longer limit himself to controlling the company’s application catalog,” says Jordi Damià. “You also have to know what tasks are being automated, what agents are intervening in the processes and what level of autonomy they have. The governance of AI must evolve at the same pace as its execution capacity.”

Banning will not be enough

According to Setesca, one of the main risks is that companies respond to shadow AI by trying to prohibit the use of unauthorized tools. However, the ease of access to AI models and applications means that this strategy can be difficult to maintain.

The Work Trend Index 2026 concludes that organizations must redesign work and establish the necessary conditions so that people and agents can work together, instead of simply introducing new tools.

In this scenario, the role of the CIO also becomes that of designing the rules of coexistence between employees and AI systems: defining what information can be used in shadow AI, what processes can be automated, what decisions require human supervision, how the results are audited and who responds when an agent makes a mistake.

“The alternative to shadow AI is not to prohibit artificial intelligence, but to govern it,” concludes Damià. “Companies need to establish clear rules that allow employees to experiment and derive value from these tools, but within a framework that protects data, maintains process traceability, and makes it clear where AI autonomy ends and human responsibility begins.”