The Governance Loop · #04

Shadow AI is already here. Does your organisation know it?

By Daman David Pant (AIGP)

New on the Playbook

The AIGP Playbook is now used by 4,000+ professionals across 65+ countries. This week's updates:

Governance tip of the week: Shadow AI is already in your organisation. The question is whether you know it.

Last week we covered the first SEC 8-K disclosure linked to shadow AI. One employee, one unauthorised tool, one regulatory filing. That is how quickly unsanctioned AI use becomes a governance event.

Shadow AI is not a future risk. It is the unsanctioned use of AI tools by employees outside approved enterprise environments. Only 20% of organisations fully monitor or govern employee use of shadow AI. The other 80% are exposed without knowing it.

The risk is not malicious intent. Most employees simply want to work faster. But when sensitive data enters an unvetted AI tool, the organisation loses control of where it goes, how it is stored, and whether it is used for model training.

Three questions every governance team should be able to answer:

  • Do you know which AI tools your employees are actually using, including browser extensions, personal accounts, and free-tier tools?
  • Do you have a sanctioned alternative that meets their productivity needs, or are you governing by prohibition alone?
  • If an employee pasted confidential data into an external AI tool last week, would you know?

Banning AI does not eliminate shadow AI. It drives it underground and removes visibility entirely. The governance goal is not prohibition. It is governed enablement: clear policies, sanctioned alternatives, and monitoring that gives you sight without creating a surveillance culture.

What caught my eye this week

Recursive self-improvement: governance has not caught up yet

Anthropic recently acknowledged that AI systems improving themselves is no longer purely theoretical. Their own blog revealed that 80% of code added to their production codebase in May 2026 was AI-generated, up from less than 5% when Claude Code launched in February 2025.

The improvement cycles are still slow, gated by human approval and lengthy training periods. But the direction of travel is clear. Current regulations focus mainly on human misuse of AI. Recursive self-improvement is a different category of risk entirely, and governance frameworks have not caught up.

The question for practitioners is not whether superintelligence is coming. It is whether the oversight mechanisms we are building today will still make sense when the system doing the improving is the AI itself.

AI governance jobs: the market is moving fast

LinkedIn's 2026 Skills on the Rise report puts AI governance demand at +150% year-over-year. Open roles have tripled since 2023, with 85% of positions targeting professionals with five or more years of experience.

Median salary sits at approximately $158,750. Holding an IAPP certification correlates with 13% higher pay than non-certified peers. Multiple certifications push that to 27%.

The roles exist. The gap between supply and demand is real. The credential matters.

If you know someone genuinely interested in AI governance or building in this space, forward this to them.

The Governance Loop

What is actually moving in AI governance, plus what it means if you are sitting the AIGP. No fixed schedule, only when something matters.