{"id":15312,"date":"2026-09-15T18:50:40","date_gmt":"2026-09-15T13:20:40","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15312"},"modified":"2026-09-15T18:51:33","modified_gmt":"2026-09-15T13:21:33","slug":"shadow-ai-governance","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/","title":{"rendered":"Shadow AI Governance: Why Writing a Policy Is the Easy Half"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Shadow AI governance is the practice of finding, assessing, and managing the AI tools employees use without approval. Most organizations do the first half, writing a policy, and skip the second, auditing whether anyone follows it. IBM&#8217;s 2025 research found 63% of breached organizations had no AI governance policy, and only 34% of those with one audit for unsanctioned use.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#What_Shadow_AI_Is_and_How_It_Differs_From_Shadow_IT\" >What Shadow AI Is, and How It Differs From Shadow IT<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#How_Widespread_Shadow_AI_Is_Inside_Organizations\" >How Widespread Shadow AI Is Inside Organizations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#What_Shadow_AI_Costs_When_It_Becomes_a_Breach\" >What Shadow AI Costs When It Becomes a Breach<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#Why_Is_a_Written_AI_Policy_Not_Governance\" >Why Is a Written AI Policy Not Governance?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#The_Friction_Gap_That_Drives_Employees_to_Unapproved_Tools\" >The Friction Gap That Drives Employees to Unapproved Tools<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#How_to_Build_a_Shadow_AI_Inventory_Without_Blocking_Everything\" >How to Build a Shadow AI Inventory Without Blocking Everything<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#Metrics_That_Show_Whether_Shadow_AI_Governance_Is_Working\" >Metrics That Show Whether Shadow AI Governance Is Working<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#Where_Shadow_AI_Collides_With_Regulatory_Obligations\" >Where Shadow AI Collides With Regulatory Obligations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#Start_With_Discovery_Not_With_the_Policy\" >Start With Discovery, Not With the Policy<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Shadow_AI_Is_and_How_It_Differs_From_Shadow_IT\"><\/span>What Shadow AI Is, and How It Differs From Shadow IT<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Shadow AI is the use of AI tools, assistants, and agents inside an organization without security approval or visibility. The category covers a free chatbot open in a browser tab, a personal account signed into a corporate laptop, a browser extension that summarizes documents, and an agent wired into a mailbox through an integration nobody catalogued.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The comparison to shadow IT is useful up to a point and then misleading. Shadow IT was largely a data location problem: a file sat in an unsanctioned place, and someone had to act on it for harm to follow. Shadow AI moves data and delegates judgment at the same time. A summarization tool receives the contract, retains the prompt, and returns an answer an employee may act on without verifying, which means the exposure is both a copy of the data and a decision made on the organization&#8217;s behalf.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That second half is what makes shadow AI a workforce risk rather than an asset inventory problem. Employees adopting unapproved tools are not usually trying to cause harm, which places most shadow AI in the category of <a href=\"https:\/\/threatcop.com\/blog\/insider-threats-malicious-misguided\/\">insider risk that is misguided rather than malicious<\/a> and changes what an effective response looks like.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Widespread_Shadow_AI_Is_Inside_Organizations\"><\/span>How Widespread Shadow AI Is Inside Organizations<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Adoption moved faster than almost any workplace technology on record. Verizon&#8217;s 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% the previous year, and that 67% of those users sign in with non-corporate accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second figure matters more than the first for governance purposes. A corporate account leaves logs, enforces retention settings, and can be revoked when someone leaves. A personal account does none of that. Two thirds of AI use on company hardware is therefore happening in a place the organization cannot audit, cannot configure, and cannot switch off, which is a materially different problem from employees using a tool the company bought.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Scale alone does not make this urgent. What makes it urgent is that the usage is invisible by construction, so the organizations most exposed are the ones least able to say so. Visibility gaps of this kind are a recurring theme in <a href=\"https:\/\/threatcop.com\/blog\/enterprise-security-platforms-for-ciso-visibility\/\">CISO visibility across security platforms<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Shadow_AI_Costs_When_It_Becomes_a_Breach\"><\/span>What Shadow AI Costs When It Becomes a Breach<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">IBM&#8217;s <a href=\"https:\/\/www.ibm.com\/think\/x-force\/2025-cost-of-a-data-breach-navigating-ai\" target=\"_blank\" rel=\"nofollow noopener\">Cost of a Data Breach Report 2025<\/a>, conducted with the Ponemon Institute across 600 organizations, put numbers on the exposure.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Finding<\/th><th>Figure<\/th><\/tr><\/thead><tbody><tr><td>Organizations reporting a breach involving shadow AI<\/td><td>20%<\/td><\/tr><tr><td>Additional cost where shadow AI levels were high<\/td><td>$670,000 above the average breach<\/td><\/tr><tr><td>Average cost of a shadow AI breach<\/td><td>$4,630,000, against $3,960,000 for standard incidents<\/td><\/tr><tr><td>Organizations with an AI-related incident that lacked proper AI access controls<\/td><td>97%<\/td><\/tr><tr><td>Breached organizations with no AI governance policy<\/td><td>63%<\/td><\/tr><tr><td>Policy holders that regularly audit for unsanctioned AI use<\/td><td>34%<\/td><\/tr><tr><td>Shadow AI breaches involving customer PII<\/td><td>65%, against a 53% global average<\/td><\/tr><tr><td>Shadow AI breaches involving intellectual property<\/td><td>40%, against a 33% global average<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">One in five breaches now involves shadow AI, and those breaches compromise more sensitive categories of data than the average incident. The data-type skew is the part worth sitting with: shadow AI breaches hit customer records and intellectual property harder than breaches generally, because the data employees paste into an assistant is the data they are working on, and people work on the things that matter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IBM also reported that 32% of breaches resulted in regulatory fines, with 48% of those fines exceeding $100,000. Broader cost patterns for unmanaged human risk are set out in <a href=\"https:\/\/threatcop.com\/blog\/cost-of-ignoring-people-security-management\/\">the cost of ignoring the human layer<\/a>.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Is_a_Written_AI_Policy_Not_Governance\"><\/span>Why Is a Written AI Policy Not Governance?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A policy states an intention. Governance is the loop that checks whether the intention survived contact with the workforce, and the IBM figures show where organizations stop. Of breached organizations, 63% had no AI governance policy at all. Among those that did have one, only 34% regularly audited for unsanctioned AI use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Put those two numbers together and the picture is stark: the large majority of organizations either never wrote the rule or never checked it. A policy nobody audits produces documentation without control, and it can be worse than nothing in a regulatory context, because it establishes that the organization knew the risk and can be asked what it did about it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The audit half is skipped because it is genuinely harder. Writing an acceptable-use policy takes an afternoon. Establishing which of 4,000 employees pasted client data into an unapproved assistant last quarter takes instrumentation, a definition of what counts, and a decision about what happens when the answer is uncomfortable. Governance disciplines that survive that test are discussed in <a href=\"https:\/\/threatcop.com\/blog\/laura-sawka-on-strategic-governance-and-the-risk-aware-culture\/\">strategic governance and a risk-aware culture<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Friction_Gap_That_Drives_Employees_to_Unapproved_Tools\"><\/span>The Friction Gap That Drives Employees to Unapproved Tools<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Employees adopt shadow AI for a reason that is consistent enough to be treated as a design input: the approved path is slower than the unapproved one. When the sanctioned assistant requires a ticket, lacks the model the team needs, or blocks the file type they work in, the free tool in the browser wins on the only metric the employee is measured against, which is getting the work done.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That has a direct governance consequence. A shadow AI rate is not only a compliance number, it is a measurement of the gap between what the organization provides and what the work requires. A department with 70% unapproved usage is reporting a procurement failure as much as a discipline failure, and treating it purely as the second guarantees the behavior moves further underground.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Enforcement-first responses tend to produce exactly that. Blocking domains moves usage to personal phones, where no log exists at all, and disciplinary framing suppresses the self-reporting that would otherwise give security teams their cheapest source of visibility. Building the opposite instinct is the subject of <a href=\"https:\/\/threatcop.com\/blog\/what-is-incident-reporting-culture\/\">incident reporting culture<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_Build_a_Shadow_AI_Inventory_Without_Blocking_Everything\"><\/span>How to Build a Shadow AI Inventory Without Blocking Everything<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Discovery does not require perfect visibility on day one, and waiting for a complete picture is how organizations stay at zero. The sequence below produces a usable inventory in weeks rather than quarters.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Step<\/th><th>Action<\/th><th>Output<\/th><\/tr><\/thead><tbody><tr><td>1<\/td><td>Pull authentication and egress logs for known AI domains, then widen the list monthly as new tools appear<\/td><td>A first-pass list of tools in use and rough volumes<\/td><\/tr><tr><td>2<\/td><td>Survey the highest-exposure functions directly, with amnesty stated in writing<\/td><td>Named tools, and the task each one is solving<\/td><\/tr><tr><td>3<\/td><td>Inventory browser extensions and OAuth grants against corporate accounts<\/td><td>Agents and integrations holding standing access<\/td><\/tr><tr><td>4<\/td><td>Classify each tool by data sensitivity it touches and whether it can act, not just read<\/td><td>A risk-ranked list rather than an alphabetical one<\/td><\/tr><tr><td>5<\/td><td>Approve or provide an equivalent for the highest-volume legitimate use cases<\/td><td>A sanctioned path that competes on speed<\/td><\/tr><tr><td>6<\/td><td>Train the roles the inventory surfaced, on the specific tools they actually use<\/td><td>Role-level coverage, evidenced<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Step 2 is where most of the value sits and where most programs flinch. An amnesty window produces more accurate data in a fortnight than log analysis produces in a quarter, because employees know what they use and logs only know what they can see. Amnesty has to be real, though: one disciplinary action taken on survey data ends the honest reporting permanently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TLMS carries step 6, delivering role-based content on the specific tools a function uses and reporting coverage by role, so the people who showed up in the inventory are the people who get trained rather than the whole workforce receiving one generic AI module. Approaches to scoping that kind of program are covered in <a href=\"https:\/\/threatcop.com\/blog\/human-risk-management\/\">human risk management<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Step 3 catches the category that carries the most authority. An OAuth grant to a mailbox persists after the employee stops thinking about it, which places it closer to <a href=\"https:\/\/threatcop.com\/blog\/third-party-data-breaches\/\">third-party data breaches<\/a> than to casual tool use, and it survives password changes that people assume revoke access.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Metrics_That_Show_Whether_Shadow_AI_Governance_Is_Working\"><\/span>Metrics That Show Whether Shadow AI Governance Is Working<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Six measures tell a board or an auditor whether the loop is closed, and none of them is a policy acknowledgement rate.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Metric<\/th><th>What it reveals<\/th><\/tr><\/thead><tbody><tr><td>Known AI tools in use, by function<\/td><td>Whether discovery is running or stalled<\/td><\/tr><tr><td>Ratio of sanctioned to unsanctioned usage volume<\/td><td>Whether the approved path is winning on merit<\/td><\/tr><tr><td>Share of AI sessions on corporate rather than personal accounts<\/td><td>Whether usage is auditable at all<\/td><\/tr><tr><td>Standing OAuth grants and agent integrations, reviewed quarterly<\/td><td>Delegated authority nobody is tracking<\/td><\/tr><tr><td>Time from a new tool appearing to a classification decision<\/td><td>Whether governance keeps pace with adoption<\/td><\/tr><tr><td>Voluntary disclosure rate after an amnesty<\/td><td>Whether the culture supports visibility<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Two of these deserve a note on how to read them. A rising count of known AI tools is a good sign early in a program and a bad sign later, because it means discovery is working before it means adoption is sprawling. A falling voluntary disclosure rate almost never means shadow AI stopped; it usually means something happened to make disclosure feel unsafe. The second and third measures are the ones to watch over time, because they move when the underlying behavior changes rather than when documentation is refreshed. Selecting measures that behave this way is covered in <a href=\"https:\/\/threatcop.com\/blog\/measuring-human-risk-in-security-program\/\">metrics for a human risk program<\/a> and in <a href=\"https:\/\/threatcop.com\/blog\/employee-risk\/\">why an employee risk score matters<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_Shadow_AI_Collides_With_Regulatory_Obligations\"><\/span>Where Shadow AI Collides With Regulatory Obligations<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Shadow AI creates exposure under regimes that were not written with AI in mind. Data protection law is the immediate one: pasting customer records into a consumer assistant is a disclosure to a third-party processor with no contract, no documented transfer basis, and no retention control, which is a problem under GDPR and under India&#8217;s Digital Personal Data Protection Act alike.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sectoral rules compound it. An organization that must evidence where regulated data resides cannot do so when an unknown share of it has been sent to model providers outside its control, and IBM&#8217;s finding that shadow AI breaches disproportionately involve customer PII means the collision is not theoretical. Breaches spanning multiple environments also took the longest to identify and contain, at 276 days.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also a training obligation now attached. Where the EU AI Act applies, deployers must take measures supporting AI literacy among the people operating AI systems on their behalf, and an organization that cannot name which systems those are cannot evidence that its measures matched them. Governance and behavioral evidence are increasingly the same artifact, a point developed in <a href=\"https:\/\/threatcop.com\/blog\/dr-sergio-e-sanchez-on-longitudinal-behavior-profiling-and-ai-governance\/\">longitudinal behavior profiling and AI governance<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Start_With_Discovery_Not_With_the_Policy\"><\/span>Start With Discovery, Not With the Policy<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most organizations write the AI policy first because it is the artifact that can be produced in a week. Run discovery first instead. The inventory will tell you which rules are worth writing, which functions need them most, and where the approved path is losing to the free one, and a policy built on that evidence stands up to questions the generic version cannot answer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the inventory names the roles, the training has somewhere to land. <a href=\"https:\/\/threatcop.com\/threatcop-learning-management-system\">Deliver role-specific AI use content<\/a> to the functions the discovery surfaced, in the languages your teams work in, and report coverage by role so governance has behavioral evidence behind it rather than an acknowledgement log.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-17d5c830be46\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-f204a71d9c68\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-0be46\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-0be46'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is shadow AI?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-0be46'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Shadow AI is the use of AI tools, assistants, or agents within an organization without security approval, procurement review, or visibility. It includes consumer chatbots accessed through personal accounts, browser extensions, and agents connected to corporate systems through integrations that were never catalogued. The defining characteristic is that the security team cannot see the tool, the data going into it, or the access it holds.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-3ca9e0187b52\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-0be46\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-0be46'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow common is shadow AI in the workplace?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-0be46'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Verizon&#8217;s 2026 Data Breach Investigations Report found 45% of employees are regular AI users on corporate devices, up from 15% a year earlier, and that 67% of them sign in using non-corporate accounts. IBM&#8217;s Cost of a Data Breach Report 2025 found 20% of organizations suffered a breach involving shadow AI, making it one of the fastest-growing breach factors on record.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-8be6142f0da3\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-0be46\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-0be46'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhy is shadow AI more dangerous than shadow IT?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-0be46'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Shadow IT was primarily a data location problem, where files sat somewhere unsanctioned until someone acted on them. Shadow AI both moves data and delegates judgment, because employees act on outputs they have not verified and agents can take actions under an employee&#8217;s identity. An unapproved agent connected to a mailbox holds standing access that persists long after anyone remembers granting it.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-e5710c96ab84\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-0be46\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-0be46'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tCan blocking AI tools solve shadow AI?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-0be46'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Blocking rarely solves it and often makes visibility worse. Domain blocks move usage to personal phones and home devices where no corporate log exists, and disciplinary framing discourages the voluntary disclosure that gives security teams their cheapest source of discovery. Providing a sanctioned tool that competes on speed with the unapproved one addresses the reason people route around the policy.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-2408bd5e7f13\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-0be46\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-0be46'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat should an AI acceptable use policy contain?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-0be46'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">At minimum: which tools are approved and for what tasks, which data categories may never be entered into any AI system, the rule on personal versus corporate accounts, the requirement to verify outputs before acting on them, the approval path for new tools, and the process for disclosing tools already in use. A policy without an audit mechanism attached documents intent rather than establishing control.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Shadow AI governance is the practice of finding, assessing, and managing the AI tools employees use without approval. Most organizations do the first half, writing a policy, and skip the second, auditing whether anyone follows it. IBM&#8217;s 2025 research found 63% of breached organizations had no AI governance policy, and only 34% of those with [&hellip;]<\/p>\n","protected":false},"author":27,"featured_media":15336,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[424],"tags":[443,440],"class_list":["post-15312","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-cybersecurity","tag-ai-governance","tag-artificial-intelligence"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Shadow AI Governance: Why a Written Policy Is Not Enough<\/title>\n<meta name=\"description\" content=\"Shadow AI governance fails when nobody audits the policy. See the IBM breach data, a discovery sequence, and metrics that track real behavior.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Shadow AI Governance: Why a Written Policy Is Not Enough\" \/>\n<meta property=\"og:description\" content=\"Shadow AI governance fails when nobody audits the policy. See the IBM breach data, a discovery sequence, and metrics that track real behavior.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T13:20:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-15T13:21:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Shadow-AI-Governance-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Adhish Chakma\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Adhish Chakma\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/\"},\"author\":{\"name\":\"Adhish Chakma\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/7ce86f95d6eb24f0c7c51619b704defa\"},\"headline\":\"Shadow AI Governance: Why Writing a Policy Is the Easy Half\",\"datePublished\":\"2026-09-15T13:20:40+00:00\",\"dateModified\":\"2026-09-15T13:21:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/\"},\"wordCount\":2219,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Shadow-AI-Governance-blog-banner.png\",\"keywords\":[\"AI Governance\",\"Artificial Intelligence\"],\"articleSection\":[\"AI &amp; Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/\",\"name\":\"Shadow AI Governance: Why a Written Policy Is Not Enough\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Shadow-AI-Governance-blog-banner.png\",\"datePublished\":\"2026-09-15T13:20:40+00:00\",\"dateModified\":\"2026-09-15T13:21:33+00:00\",\"description\":\"Shadow AI governance fails when nobody audits the policy. See the IBM breach data, a discovery sequence, and metrics that track real behavior.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Shadow-AI-Governance-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Shadow-AI-Governance-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Shadow AI Governance, Why Writing a Policy Is the Easy Half, over an abstract stacked bar graphic on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/shadow-ai-governance\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Shadow AI Governance: Why Writing a Policy Is the Easy Half\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/7ce86f95d6eb24f0c7c51619b704defa\",\"name\":\"Adhish Chakma\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_27_1789477673-96x96.jpeg\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_27_1789477673-96x96.jpeg\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_27_1789477673-96x96.jpeg\",\"caption\":\"Adhish Chakma\"},\"description\":\"Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Shadow AI Governance: Why a Written Policy Is Not Enough","description":"Shadow AI governance fails when nobody audits the policy. See the IBM breach data, a discovery sequence, and metrics that track real behavior.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/","og_locale":"en_US","og_type":"article","og_title":"Shadow AI Governance: Why a Written Policy Is Not Enough","og_description":"Shadow AI governance fails when nobody audits the policy. See the IBM breach data, a discovery sequence, and metrics that track real behavior.","og_url":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-15T13:20:40+00:00","article_modified_time":"2026-09-15T13:21:33+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Shadow-AI-Governance-blog-banner.png","type":"image\/png"}],"author":"Adhish Chakma","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Adhish Chakma","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/"},"author":{"name":"Adhish Chakma","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/7ce86f95d6eb24f0c7c51619b704defa"},"headline":"Shadow AI Governance: Why Writing a Policy Is the Easy Half","datePublished":"2026-09-15T13:20:40+00:00","dateModified":"2026-09-15T13:21:33+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/"},"wordCount":2219,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Shadow-AI-Governance-blog-banner.png","keywords":["AI Governance","Artificial Intelligence"],"articleSection":["AI &amp; Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/","url":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/","name":"Shadow AI Governance: Why a Written Policy Is Not Enough","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Shadow-AI-Governance-blog-banner.png","datePublished":"2026-09-15T13:20:40+00:00","dateModified":"2026-09-15T13:21:33+00:00","description":"Shadow AI governance fails when nobody audits the policy. See the IBM breach data, a discovery sequence, and metrics that track real behavior.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/shadow-ai-governance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Shadow-AI-Governance-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Shadow-AI-Governance-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Shadow AI Governance, Why Writing a Policy Is the Easy Half, over an abstract stacked bar graphic on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/shadow-ai-governance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Shadow AI Governance: Why Writing a Policy Is the Easy Half"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/7ce86f95d6eb24f0c7c51619b704defa","name":"Adhish Chakma","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_27_1789477673-96x96.jpeg","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_27_1789477673-96x96.jpeg","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_27_1789477673-96x96.jpeg","caption":"Adhish Chakma"},"description":"Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.","sameAs":["https:\/\/threatcop.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15312","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15312"}],"version-history":[{"count":4,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15312\/revisions"}],"predecessor-version":[{"id":15356,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15312\/revisions\/15356"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15336"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15312"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15312"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15312"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}