I argued a few weeks ago that shadow AI is a verdict on your culture, not your security — that employees reaching for unsanctioned AI tools are telling you the sanctioned path is too slow, and no amount of blocking fixes the thing that made them go around you. One reasonable objection to that piece was practical: it’s easy to talk about culture when you can’t even see what people are using. You can’t manage what you can’t measure, and until recently, shadow AI was genuinely hard to measure.
That excuse is gone. On 2 July 2026, Jamf shipped AI Governance, a native, OS-level control plane for Mac that discovers which AI tools are actually in use on a device, enforces policy on them, and produces audit-ready reports — with immediate support for Claude Code, Claude Desktop, and OpenAI Codex. It’s not alone: Microsoft Purview surfaces shadow AI across Microsoft 365, and Zscaler does it at the network layer. Gartner puts AI-governance spending at $492 million this year, past a billion by 2030. The measurement problem became a product category.
So now you can see it. The interesting question is the one that arrives the moment the dashboard lights up: now what?
For the rest of us: what these tools actually do
Shadow AI is the AI people use at work without IT’s blessing — a personal chatbot subscription, a coding agent installed off a website, a browser extension that pipes company text to a model nobody vetted. It’s invisible to the org precisely because it routes around the org.
The new tooling makes it visible at the endpoint — on the laptop itself, not just the corporate network — which matters because a coding agent running locally never touches the web proxies older tools watched. It answers three questions IT couldn’t reliably answer before: which AI tools are running, on whose machines, and doing what. Discover, enforce, report. That’s genuinely new capability, and it’s genuinely useful.
One dashboard, two exits
You can finally see your shadow AI.
The same dashboard has two exits.
- read usage as demand
- fix the sanctioned path
- usage comes into the light
- read usage as violation
- surveil and punish
- usage goes dark again
Shadow AI was a verdict on your culture when you could not see it. Now that you can, the verdict just comes with receipts.
Here’s the thing the product demos don’t dwell on: the dashboard is neutral, and the same data supports two opposite responses. Which one you choose has nothing to do with the tool and everything to do with the culture the first article was about.
Exit one — the roadmap. You look at the usage data and read it as demand. People are using a particular coding agent? That’s a signal your sanctioned toolchain is missing something. You use the visibility to fix the sanctioned path — approve the good tools fast, provide a safe equivalent for the risky ones, close the gap that sent people around you in the first place. Usage comes into the light because the light is where the good tools now are.
Exit two — the panopticon. You look at the same data and read it as violation. You surveil, you flag, you discipline. And you get exactly what surveillance always gets: people don’t stop, they get better at hiding. The coding agent moves to a personal laptop, the chatbot to a phone, the whole activity one step further from anything you can see. You’ve spent real money to make your shadow AI darker.
Same dashboard. Opposite outcomes. The variable isn’t the software.
The tool is neutral; the verdict isn’t
This is why the culture argument survives the arrival of the tooling instead of being resolved by it. Measurement doesn’t tell you what to do — it just removes your excuse for not knowing. An organisation that already treats employee demand as a signal to serve will use AI Governance to build a better roadmap. An organisation that treats it as behaviour to punish will build a better panopticon. The dashboard amplifies whichever posture you already hold; it doesn’t choose one for you.
Which means buying the tool is the easy 20% of the decision. The hard 80% is deciding, before the reports start landing on someone’s desk, what your organisation is going to do with a number it couldn’t see before. That decision is a governance-culture decision, and it’s worth making on purpose — because the first time a manager uses a usage report to reprimand someone instead of to fix a gap, your whole workforce learns which exit you took, and the shadow gets deeper from that day.
What this means
Buy the visibility. It’s real, it’s overdue, and “we can’t see it” was never a good place to govern from. Jamf’s endpoint approach, Purview’s Microsoft-estate coverage, Zscaler’s network view — pick what fits your fleet. Measurement is a prerequisite for any serious AI governance, and the tooling has finally caught up to the problem.
But decide the posture first, because the tool will make you more of what you already are. If your instinct on seeing unsanctioned usage is “who do we stop,” the dashboard will make you efficient at driving AI underground. If it’s “what are we missing,” the same dashboard becomes the best product-roadmap input your IT organisation has ever had. Shadow AI was a verdict on your culture when you couldn’t see it. Now that you can, the verdict just comes with receipts.
References
- Jamf, “Jamf launches AI Governance, a first-of-its-kind native AI control plane for Mac” (2 July 2026) — discover / enforce / report; Claude Code, Claude Desktop, OpenAI Codex support; Gartner AI-governance spend ($492M in 2026, >$1B by 2030).
- Microsoft Purview and Zscaler — shadow-AI discovery for the Microsoft estate and the network layer respectively, establishing this as a category rather than a single product.
- keller-ai — the companion argument this builds on: Shadow AI Is a Verdict on Your Culture, Not Your Security.