Teams moved first. Policy is still catching up.
Employees discovered ChatGPT, Claude, Gemini, and a long tail of other tools the same way they discover any useful website — by opening a tab. That convenience arrived faster than most organizations could invent approved paths, training, and enforceable rules. The result is Shadow AI: productive use mixed with unmanaged risk, often invisible until something sensitive has already been pasted.
Waiting for perfect governance before acknowledging GenAI use is no longer realistic. The practical question is how to put a gate in front of access now — so verified tools can stay useful and unapproved ones stop being a silent exit path for data.