Shadow IT Risks in an Era of AI-Built Applications
Shadow IT built on AI refers to applications generated or configured using AI tools outside formal enterprise oversight, which means they can access sensitive data, reshape workflows, and drive financial transactions without passing through standard procurement, architecture review, or compliance controls that normally govern approved enterprise software. This new shadow IT does not appear as a rogue SaaS subscription; it appears as a small AI-generated app that quickly becomes part of daily work, while central IT has limited visibility into what it does or how it interacts with ERP system integration and financial processes. The uncomfortable truth is that existing controls were designed for slow, centralized software delivery. A business user can now describe an application in plain language and see a usable first version in minutes, long before IT understands the data it reaches or who will own maintenance when the first version breaks. A company may already run an ERP platform, yet inventory transactions are still recorded manually, processed in batches, and reflected in the system after the warehouse has moved on. AI-generated workarounds plug those gaps but bypass the checks that make enterprise AI governance reliable.

From Workarounds to Measurable Compliance and Financial Damage
What makes AI-driven shadow IT dangerous is not the novelty of the tools but the invisibility of the intent behind them. Many AI-assisted development platforms treat generated code as the main output, yet code is only one expression of the business logic, permissions and integration assumptions embedded in a workflow. When that context is missing, a clever workaround for a broken approval or inventory process becomes an unmanaged risk touching compliance, finance and data integrity. These shadow IT risks are no longer theoretical. IBM’s 2025 Cost of a Data Breach Report found that one in five breached organizations tied incidents to shadow AI, and that high levels of shadow AI added USD 670,000 (approx. RM3,082,000) to average breach costs. Those losses compound the visibility gaps already created when AI-built applications alter how approvals are granted or how employees complete a process without clear AI compliance controls. In ERP environments, that means governance, regulatory reporting and financial planning can be out of sync with the way work truly happens on the ground.
Enterprise Software Is Turning Into a Governance Business
Executives still buying AI like traditional enterprise software are missing the most important shift: the business model is moving away from pure technology toward governance, finance and strategy. For decades, the pattern was predictable—select a platform, negotiate a contract, approve a budget, issue licenses. Costs were tied mainly to users. Now, spending follows activity instead of headcount, with organizations increasingly paying for AI inference, API calls, workloads, data access and computational consumption. This change collides with the rapid spread of task-specific AI agents. Gartner predicts that 40 percent of enterprise applications will include such agents by the end of 2026, compared with less than 5 percent in 2025. Yet upwards of 80% of companies are still in the early stages of defining a clear AI strategy with enough specificity for enterprise-wide decisions. Only about 30 percent have reached meaningful maturity in responsible AI strategy, governance and agentic AI controls. In other words, AI is scaling much faster than the frameworks required to govern it.
Why Traditional Controls Fail and What Oversight Must Look Like Now
Traditional software governance assumes that anything touching approvals, inventory or finance passes through procurement and architecture review. AI upends that. A fully functioning application can now be created before IT has a clear view into what it does, what data it reaches, or who will support it when the first version breaks or must change. Governance has to be part of how software gets built, not a compliance layer added after a demo succeeds. Widener argues that organizational structure—not technology—is now one of the biggest barriers to effective enterprise AI governance, because too many companies still treat AI as a departmental initiative instead of an enterprise transformation. She suggests the first order of business is to get technology, finance and business leaders in the same room, since each decision now has shared financial and operational consequences. Governance also has to expand beyond security and regulatory oversight to include tollgating: who controls enterprise data, who can use it and who pays each time AI systems access it. Without that, shadow IT risks remain invisible until they show up as budget shocks or compliance failures.
What Comes Next: Oversight Frameworks for Hybrid, AI-Rich Enterprises
The next chapter of enterprise software will not be defined by the most advanced model but by the organizations that treat AI-built applications as part of a governed ecosystem. The build problem is largely solved; the ownership problem is not. As AI agents embed themselves across ERP, CRM, HCM and data platforms, enterprises will move toward hybrid architectures that mix vendor infrastructure with internal orchestration layers designed to mitigate tollgating costs and maintain control over data access. Widener does not expect organizations to become independent of major vendors, but she does expect them to adopt hybrid environments where governance is the main coordinating function. McKinsey’s 2026 AI Trust Maturity Survey shows only about 30 percent of organizations have reached meaningful maturity in responsible AI strategy, governance and agentic controls, which means most enterprises are still building these frameworks as AI spreads. The goal is not to eliminate uncertainty—technology, pricing and capabilities will keep changing—but to build an enterprise that can adapt without losing financial control or allowing AI-powered shadow IT to reshape mission-critical processes unchecked.




