Shady AI is what an empty chair looks like from the outside

The Hacker News ran a piece this week on “shady AI”, their sharper name for shadow AI, and called it security’s next big governance problem. They’re right about the diagnosis. I want to push on the cause, because I think most companies are misreading it.

The standard story goes like this: employees discovered that free AI tools make their jobs easier, IT hasn’t sanctioned any of them, so people quietly paste client contracts, patient notes, and source code into whatever chatbot loads fastest. Security finds out months later, usually by accident. Cue the panic memo and the blanket ban.

That story treats shadow AI as a discipline problem. It isn’t a discipline problem. It’s a vacancy.

Nobody owns the question

Walk into a mid-sized firm and ask a simple question: who decides which AI tools are allowed here? Watch what happens. IT says they handle security review but not AI strategy. Legal says they’ll weigh in on contracts when asked. The COO says it’s on the roadmap. Meanwhile a paralegal has a browser extension summarizing privileged email, a sales rep wired a free agent into the CRM with a personal API key, and an analyst is running quarterly numbers through a consumer chatbot that trains on inputs by default.

None of those people are being reckless in their own minds. They’re being productive. The tool worked, nobody said no, and more to the point, nobody was there to say no. Or yes. The chair where that decision should get made is empty at most organizations, and shadow AI is simply what fills a vacuum.

Bans don’t fix vacuums. A ban is a “no” issued by someone who wasn’t in the room when the work needed doing, and employees treat it accordingly. The Hacker News piece touches on this: prohibition pushes usage underground, off the corporate network, onto personal devices, where security has zero visibility instead of partial visibility. You traded a manageable problem for an invisible one and called it policy.

What actually fills the chair

This is the exact gap the fractional Chief AI Officer exists to close. Not a consultant who writes a 40-page acceptable-use policy and leaves. Someone who sits in the seat, part-time but genuinely accountable, and does four unglamorous things.

First, inventory. You can’t govern what you can’t see. Before any policy discussion, find out what’s actually in use: the browser extensions, the personal subscriptions, the API keys nobody logged. Most firms are shocked by this list. The shock is useful. It converts an abstract worry into a spreadsheet with names on it.

Second, sanctioned alternatives. Here’s the part the ban-first crowd skips. People adopted these tools because the tools work. If you take away the free chatbot without replacing the capability, they’ll find another free chatbot. The answer is a private AI workspace they can actually use, running on infrastructure you control, where the drafting and the summarizing and the analysis happen without the data ever leaving your jurisdiction. At Modular that’s not theoretical. Our own teams run daily on the same private stack we deploy for clients, hosted on US soil, at a fixed monthly price, so the finance conversation is as boring as the compliance conversation. Boring is the goal.

Third, a real AI Program Office. Small, standing, cross-functional. It reviews new tool requests in days instead of quarters, keeps the approved list current, and gives employees a place to ask “can I use this?” and get an answer before they’ve already used it. Speed matters more than people admit. An approval process that takes six weeks is a prohibition wearing a lanyard.

Fourth, policy that says yes with conditions. “AI is banned” and “AI is fine, go nuts” are equally lazy. The workable version reads more like: this class of data can go into these tools, this class cannot, here’s the sanctioned path for the gray areas, and here’s who to ask when you’re not sure. Employees follow rules they can actually follow.

The sovereignty thread underneath

There’s a reason this maps so cleanly onto how we think about infrastructure. Your data, your rules. That’s been the thesis all along, and shadow AI is what it looks like when the rules never got written. Every unsanctioned tool is a small, silent transfer of control: your client’s contract now lives in someone else’s training pipeline, under someone else’s terms of service, in someone else’s jurisdiction. And that includes the AI working on the data, not just the data itself. Your AI, your rules. Governance without agency over the models and the tooling is just paperwork about someone else’s decisions.

The firms that get ahead of this won’t be the ones with the strictest bans or the longest policies. They’ll be the ones where somebody actually owns the question, where the sanctioned path is easier than the shadow path, and where “which AI touched this data” has an answer you could give a regulator without sweating.

The empty chair is the whole problem. Filling it doesn’t require a full-time executive salary. It requires deciding that the question deserves an owner.

Here’s what I’d genuinely like to know from the people reading this: when you last found an unsanctioned AI tool inside your organization, how did you find it? An audit, an incident, or dumb luck? The answers to that question tell you more about your governance posture than any policy document will.