Anaiya Algorithm

Veridian: Episode 5_Shadow AI

Magdalene Amegashitsi Season 1 Episode 17

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 11:30

Send us Fan Mail

Most organizations are unknowingly risking heavy fines, legal liability, and reputation damage because of Shadow AI — an invisible, uncontrolled surge of unsanctioned AI tools infiltrating daily operations. If your teams are deploying AI without oversight, you could be on the hook under the EU AI Act today, even without realizing it.

In this eye-opening episode, Magdalene exposes how Shadow AI is creeping into every corner of your enterprise — from procurement and customer relations to HR and IT — often built in secret, with little or no governance. You’ll discover concrete examples of AI systems operating unnoticed, such as autonomous workflows in Microsoft Copilot, rogue agents making high-stakes decisions, and personal data processing that could breach regulations.

We break down a practical five-step framework to reclaim control: Ask every team about their AI use, review access logs, foster a culture of transparency, establish a comprehensive AI inventory, and build a toolkit for sanctioned, compliant AI development. Magdalene shares how leading organizations are transforming governance from a compliance burden to a strategic advantage — enabling faster innovation and reduced risk.

Ignoring Shadow AI isn't just dangerous; it's a strategic blind spot that can cost millions and erode trust. The organizations that act now to map and manage their AI landscape will set the pace in responsible, scalable AI adoption. This episode is perfect for C-suite leaders, compliance officers, and tech teams committed to staying ahead of AI regulations while empowering their workforce securely.

Veridian’s AI governance platform simplifies this process by automatically discovering, registering, and classifying AI systems across the organization — turning the invisible into actionable insight. Available today on Microsoft Azure Marketplace, it’s your first step toward safe AI scaling.

If you're ready to turn Shadow AI from a ticking time bomb into a competitive advantage, don’t miss this crucial episode. Serious about responsible AI? This is your blueprint to move faster, safer, and smarter.

  

━━━━━━━━━━━━━━━━━━━━━━━━━━

🔗 CONNECT WITH [GUEST NAME

LinkedIn: Magdalene Amegashitsi | LinkedIn

Website: www.anaiya.org

━━━━━━━━━━━━━━━━━━━━━━━━━━

🛡️ GOVERN AI WITH CONFIDENCE — VERIDIAN

AI governance isn't optional anymore. Veridian helps organisations make AI accountable, auditable and safe — without slowing down innovation.

 

Now available on the Microsoft Marketplace.

👉 www.veridian.anaiya.org

 

━━━━━━━━━━━━━━━━━━━━━━━━━━

📌 FOLLOW ANAIYA ALGORITHM

Spotify: https://open.spotify.com/show/6GTmU1TlDeaDRsG1SeGanz?si=d399a81cf4444495

Apple Podcasts: https://podcasts.apple.com/us/podcast/anaiya-algorithm/id1870675402

LinkedIn: Anaiya Group Ltd: Overview | LinkedIn

 

━━━━━━━━━━━━━━━━━━━━━━━━━━

#AIGovernance #ArtificialIntelligence #DigitalTransformation #AILeadership #Veridian

 

 

Support the show

SPEAKER_00

Right now, someone in your organization has connected an AI tool to your data without telling a tea they did not mean any harm. They were trying to do their job faster. The tool was free, it was clever, and nobody had told them not to use it. But that tool is processing personal data. It is making decisions or influencing them. It may be logging everything it processes to a server you have no visibility of and you do not know it exists. So under the EU AI Act, you are responsible for it. I'm Madeleine, and today I want to talk about Shadow AI, the governance crisis that is hidden in plain sight inside most organizations. Shadow AI is the unsanctioned use of AI tools, agents and systems within an organization. Without the knowledge or approval of IT, compliance or leadership, it is the AI equivalent of shadow IT. If your organization spent the last two decades fighting shadow IT, employees using personal dropbox accounts, running software on personal devices, connecting unsunctioned cloud services to company data, you already know how this story goes. Except AI moves faster, making decisions and carrying greater liability than a file sharing app. Let me give you the picture in concrete terms. So an employee in your procurement team has connected an AI assistant to your supplier contract. It is summarizing, extracting key terms, flagging renewal dates. Nobody in compliance knows it exists. And the tool's privacy policy says it uses uploaded documents to improve its models. A developer in your engineering team has built an agentic workflow using a low-code AI platform. It connects to your CRM, it reads customer data, drafts and sends follow-up emails autonomously. It was built on a Saturday afternoon. It has never had a risk assessment. But it is customer facing, it processes personal data, and it is making decisions that affect your customers every day. And a manager in your HR team has been using an AI tool to help screen CVs. That tool is an EU AI Act high risk system deployed without a conformity assessment, a human oversight mechanism, or a single line in your AI register. These are not edge cases, they are the norm. Research published in 2025 found that over 60% of enterprise employees were using AI tools not officially approved by their organization. Shadow AI is not a risk you might face. It is a risk you almost certainly already have. I want to be very direct about the liability picture. Under the EU AI Act, the organization that deploys an AI system is responsible for its compliance. Not the employee who set it up, not the vendor who built it, the organization. The we did not know defense does not work. Ignorance is not a governance strategy under the EU AI Act, and regulators have made that explicit. Under GDPR, processing personal data with an unsanctioned tool is a potential breach regardless of whether data was actually leaked. The moment your employee's AI assistant uploaded a client contract to a third party server, personal data left your controlled environment. That is a data processing event and you did not have a lawful basis for it because you did not know it was happening. And under common law principles of vicarious liability, if an employee uses an AI tool in the course of their employment and that tool causes harm to a third party, the liability lent with organization, not the employee. I'm not saying this to alarm you. I'm saying it because the organization that understand the liability picture are the ones that act early, and acting early means finding out what is actually running inside your organization before a regulator does. I want to spend a moment on a specific category of shadow AI that is increasingly relevant in financial services because it is both the fastest growing and the least visible. Microsoft Copilot is now embedded in the Microsoft 365 seat that most enterprises run. Teams, Outlook, Word, Excel, Copilot is there, integrated and powerful. And because it comes through your existing Microsoft tenant, it does not feel like an external tool. It feels like a feature. But copilot agents, the autonomous workflows that teams are building on top of Copilot Studio, are AI agents. They connect to your data, they execute tasks, they interact with customers. And in many organizations, they are being deployed by individual teams with minimal central oversight because the platform makes it easy. That ease is a feature. But from a governance perspective, there's also the problem. Every co-pilot agent your organization has deployed is an AI system. It needs to be registered, it needs to be classified. If it touches customer data, makes decisions or operates in a regulated context, it may well be high risk under the EMAI Act. Viridian's direct connection to Microsoft CoPilot Studio means that when you connect your Microsoft tenant, your deployed agents register automatically. You do not have to hunt them down department by department. The inventory builds itself. The principle extends beyond Copilot. Any AI capability embedded in a platform your organization already uses, your CRM, your ITSM tool, your HR system needs to be surfaced, registered and governed. The AI is often invisible inside the interface. That invisibility is exactly the risk. So what do you actually do about Shadow AI? A five-step practical framework. Step one. Ask. Go to every team, every department, every function, and ask what AI tools are you actually using, including the ones you signed up for yourself. You will be surprised by the answers and the fact that you asked changes the culture around AI adoption. It signals that governance is not about punishment. It is about protection. Step 2. Look. Review your network and data access looks. What external services are your devices connecting to? Your IT team can see this. In many organizations, nobody has looked at it through an AI governance lens. Step 3. Create a safe to declare culture. If people are afraid that declaring an AI tool will get them in trouble, they will not declare it. Make it explicit. The goal is to understand what is work, what is running, not to police individuals. Step 4. Register everything. Every AI system you find, built, bought, embedded or discovered in the shadows goes into your AI inventory. You cannot govern what you cannot see. The inventory is the foundation. Step 5. Build the sanctioned toolkit. One of the reasons employees adopt shadow AI is that they do not have access to good approved alternatives. Governance and capability are not opposites. Done right, they reinforce each other. The AI inventory is the foundation of everything I have described and it is exactly what Viridian was designed to build. You can register AI systems manually, import from a spreadsheet, or connect directly to Microsoft's Co-Pilar Studio for automatic registration of deployed agents. Every system built, bought, embedded, agentic or discovered in the shadows goes into the same register classified and monitored. The goal is simple. Make the invisible visible. Viridian is available today on Microsoft Azure Marketplace and I will share the links in the show notes. Shadow AI is not going away. As AI tools become more capable and more accessible, the temptation to deploy them without going through a governance process will only grow. The organizations that build the governance infrastructure now, the register, the classification, the oversight will be the ones that scale AI safely. Next week, episode six, the final episode in the series. We have spent five sessions on what goes wrong with AI governance. In the final session, which is episode six, I want to talk about what goes right. What does good AI governance actually look like? And why it is not a cost. It is the thing that enables you to move faster, not slower. Until then, keep leading intentionally. Thank you.