First the rule, then the exception for yourself
Picture a typical scenario. A company rolls out an AI policy. The lawyers approve it, IT publishes it on the intranet, HR adds it to onboarding. The document says clearly: use only approved tools, company data doesn't belong in public AI services.
And then, the evening before a board meeting, the CEO opens ChatGPT to quickly put together some materials. Because, of course, they know what they're doing. And everyone else does exactly the same thing.
Numbers you wouldn't expect
Research by Cybernews among more than 1,000 US employees found that 59% of employees use shadow AI — unapproved AI tools. The number itself isn't surprising if you've read our previous article on this topic.
What is surprising is the breakdown by hierarchy.
Unexpectedly, the people at the top aren't the most disciplined. Quite the opposite: 93% of executives and senior managers admit to using shadow AI at work — the highest share of any employee group. A BlackFog survey adds another layer: 69% of presidents and C-suite members know about this problem and consciously tolerate this behavior, on the grounds that speed and efficiency simply outweigh security concerns.
In other words: people at the top of the organization are both the biggest group breaking the rules, and the ones quietly signing off on everyone else breaking them too.
And then we wonder why AI policies don't work.
Why executives do this, and why they stay silent about it
It would be easy to dismiss the whole situation as hypocrisy. But the reality is more complicated, and more interesting.
At the top of an organization, the pressure for results is highest. A CEO doesn't have time to wait for the IT department to approve a new tool — they might have only a few hours before a board presentation. A CFO needs to put together an analysis quickly before a strategy meeting. A sales director wants to make an impression in a meeting with a key client. And AI makes all of this possible: fast, simple, no bureaucracy.
On top of that comes the specific psychology of the position: people at the top have a strong sense that they can judge their own risks. Research by UpGuard even revealed a paradoxical correlation: the more employees claim to understand AI security requirements, the more regularly they use unapproved tools. Competence turns into a license for exceptions.
And then there's one more factor, highlighted by CIO research: senior executives are reluctant to admit how they actually work. They're trying to demonstrate their value, and admitting that half their output went through an unapproved AI tool doesn't fit that image. The result is a quiet, unshared practice. Everyone does it, nobody talks about it.
What happens when the rest of the company sees it
Employees aren't blind. They see which tools their managers use. They hear comments in meetings. They notice when a presentation from leadership looks like it came straight out of ChatGPT. And they draw a perfectly logical conclusion from it: if the boss does it, it probably can't be that bad.
That's how shadow AI turns from an individual decision into a cultural norm — except an unwritten, unofficial, suppressed one. And unofficial norms are, by their nature, more dangerous than official ones — they can't be measured, managed, or corrected.
The result is a situation flagged by BCG and Columbia Business School research: 76% of executives think their employees are enthusiastic about AI adoption. The reality is different: only 31% of frontline workers actually feel that enthusiasm. Leadership and the rest of the company aren't living in the same reality. And that gap keeps widening, driven exactly by this practice, and by what doesn't get said out loud.
The hidden cost of the double standard
The security risks of shadow AI are well documented. IBM's research calculated that the average cost of a data incident caused by shadow AI is $670,000 higher than incidents caused by approved tools. Roughly one in five organizations that experienced a data breach identified shadow AI as a contributing factor.
But these numbers are only part of the story. Less visible, and more serious from an organizational culture standpoint, is the erosion of trust in rules themselves.
Every corporate policy rests on an implicit assumption: the rules apply to everyone. The moment employees see that these rules clearly don't apply to leadership, the whole governance system starts to collapse. It's not a statement like “our boss is a hypocrite.” It's something subtler: “around here, the rules are more for show than for actual function.” And from that point, it's a very short road to systematically bypassing other rules too.
Research by Resume Now confirms this from the other side: 57% of employees admit they probably use AI in ways that violate company policy, and half of them don't even consider that policy clear enough. Unclear rules, visibly not followed by leadership on top of that: that's the exact recipe for a culture where compliance becomes paperwork, not a genuine norm.
So what do you do about it? Three concrete steps for leadership
1. Name your own practice out loud. The most effective thing an executive can do is stop hiding how they actually work. Not to brag, or to confess wrongdoing, but to open up space for an honest conversation about where the real boundaries are, and where the rules date back to a time before AI was a given. One sentence in a meeting — “I prepared this analysis with AI's help. Here's how I do it, and here's how I check it” — does more than three compliance training sessions.
2. Distinguish what the rules are actually protecting. A large share of AI policies were created preventively, without a clear idea of what exactly is a risk and what isn't. There's a fundamental difference between “don't share clients' personal data with a public AI service” and “don't use AI without IT approval.” The first rule protects something concrete. The second mostly protects a feeling of control. Leadership should go through its own policy and separate the rules that have real impact from the ones that exist simply because they seemed reasonable to write down.
3. Lead by behavior, not by directive. Shopify CEO Tobi Lütke stated internally that AI is now a “baseline expectation” at his company, and made that message public so the commitment would be visible. Amazon CEO Andy Jassy, by contrast, chose to use the threat of layoffs as motivation for AI adoption. The results of these two approaches differ. Culture isn't built through policies — it's built through what leadership does when it thinks no one is watching. Except in an organization, someone is always watching.
Conclusion: your company's biggest AI risk sits in the boardroom
Shadow AI isn't primarily a security problem. It's a symptom of how a company handles rules, trust, and accountability.
As long as 93% of top executives keep breaking policies they themselves approved, and as long as that stays a quiet secret everyone knows about, any attempt at meaningful AI governance will just be a game of hide-and-seek. Rules without example are just text in a document.
The question isn't: “How do we stop employees from using unapproved AI tools?”
The question is: “Are we, as leadership, willing to be the standard we demand of everyone else?”

