Every Shadow AI Alert Is a Feature Request in Disguise by Abdul Mohsin
Every Shadow AI Alert Is a Feature Request in Disguise
In a regulated healthcare environment, the reflex when you catch an unsanctioned AI tool is to block it. I’ve come to believe that’s the fastest way to lose control, not keep it. Ban a tool people find useful, and you don’t end the behavior. You push it somewhere you can’t see, usually with sensitive data along for the ride. IBM’s 2026 report found shadow AI now turns up in 43% of breached organizations, more than double a year earlier, yet only about a third have any AI governance policy in place.
So we treat shadow AI as a signal, not a crime. When our monitoring flagged an internal system quietly reaching out to an unsanctioned external cloud database, we didn’t open with a takedown. We reviewed the logs, figured out what the person was trying to accomplish, and reached out to them directly. Most of the time there’s a real business need underneath. That conversation is the whole game.
Once we understand the need, we show them the sanctioned enterprise tool that does the same job with more capability and real guardrails. Adoption stops being something we enforce and becomes something people choose, because the approved path is genuinely better.
For net-new AI projects, the rigor lives upstream: every approved use case clears a joint business, IT, and security review before go-live. It’s the same evidence-first discipline I carried over from years in financial services and PCI, pointed at a much newer problem. I’m not trying to slow anyone down. I’m trying to reach the person before their workaround reaches our data. Get that right and the sanctioned path wins on its own, which means I spend far less time playing catch-up.
About the Author:
Abdul Mohsin is an enterprise security, risk, and AI governance leader at ATI Physical Therapy, where he built the organization’s AI governance program from the ground up. With 20+ years spanning cybersecurity consulting at KPMG, financial services at Discover, and healthcare, he brings a controls-driven, evidence-first approach to emerging technology. He holds GCCC, CISA, CISM, CRISC, and CDPSE certifications and writes and speaks on AI governance, responsible AI adoption, and securing enterprises through cloud migration and shadow AI.
LinkedIn: https://www.linkedin.com/in/ammohsin/
SHARE THIS ARTICLE