Latest News & Blogs - cubesys

Shadow AI signed a contract

Written by Paul Heaton | Oct 8, 2026, 1:46:05 AM

 

An IT lead told me last week that four AI agents are being built for his organisation right now. He cannot tell me what they do, what they cost, or which cloud they run in. He is the IT lead.

They were commissioned by an executive, outside IT, from a different provider. They are being built on a model his organisation has not approved, inside that provider's own cloud account, not his tenant. His description of the scope was exact: they are paying for four agents "to do who knows what with business process". On the data question he was equally honest — none has moved yet, and when it does, he will find out then what they need.

Here is the short version. Shadow AI has grown up. It is no longer just a staff member pasting into a chatbot. It is a signed contract, with a supplier, a cloud and an invoice — and it is invisible to the person accountable for the data.

 

Why this matters now

Every control the market is selling looks inward. Approved-tool lists, data loss prevention, tenant-level agent registers: all of them answer the question "what are my people doing in my environment". None of them can see a build contract signed by a director with a third party.

This organisation is not careless. It is a not-for-profit in health and disability services with the most sensitive data category there is. It has tooling in place to see and block public AI tools. Its IT lead is deliberately holding Copilot back from general staff until the data loss controls are configured, because he would rather govern first and open up second. His own summary of where they are: effectively level one, and they need to tighten things up.

So the organisation most careful about the tool was wide open on the supplier. And the exposure is not hypothetical — it is written into a scope of work nobody in IT has read, with data access as a scheduled future step.

I saw two more versions of the same shape in the same week. A manufacturer with heavy intellectual property, deliberately restrictive — sanctioned applications only, and an agentic solution deployed against publicly available data so that nothing internal is at risk. That agent came through one of several partners, not through its Microsoft partner. And a travel operator, by its own description a Microsoft shop, whose development team brought in a different frontier model "in the last few weeks" and now uses it to write, validate and commit changes.

Three organisations. In every one, the real AI build was happening somewhere the incumbent provider could not see it.

 

What organisations get wrong

First, they govern tools when the purchase has moved to suppliers. A policy that names approved applications is answering last year's question. The thing to inventory now is not software; it is every third party contracted to build something against your business processes.

Second, they read "no data has moved yet" as "no exposure yet". It is the opposite. Before data moves is the only moment you still have leverage — over scope, over hosting, over what gets read and retained. After it moves you are negotiating about something that has already happened.

Third, they treat it as a discipline problem, and it isn't. The executive went outside because the inside could not answer. Where IT is holding the line, the business buys around it — and increasingly it buys build, not tools. That is a much harder thing to retrofit governance onto.

 

And if you are a provider, as I am

When a client buys a build from somebody else, the comfortable question is how we win it back. The uncomfortable one is whether we ever gave them a way to say yes to us. If the answer an executive gets to an urgent process problem is a readiness assessment and a policy workshop, they will go and find the person who offers to build the thing.

It also exposes what our reporting is for. A monthly report that covers patching, endpoints and tenant health says nothing at all about the four agents being built in a supplier's cloud. The unit of AI risk has moved from the device to the supplier, and a provider still reporting on devices is managing your infrastructure while somebody else builds your intelligence. That is the whole distance between a managed service provider and a managed intelligence provider, and it is not a marketing distinction.

 

Three questions, and only one of them is for IT

Ask your finance team — not your IT team — which suppliers are being paid for anything AI-shaped. Search the ledger, not the tenant. The ledger is where this is visible, and almost nobody looks there.

For each one, get the scope of work and find the sentence describing what data it will read. If there isn't one, that is your answer, and you still have time to write it.

Then ask three things nobody has written down: which model, which cloud, whose tenant. "Theirs" is a decision, not a detail — and somebody in your business should be able to tell you who made it.