Analysis · curated 15 Sep 2026

Shadow AI in the Enterprise: A Governance Framework for Transitioning from Uncontrolled Experimentation to Secure, Accountable AI Adoption | International Journal of Computer Information Systems and Industrial Management Applications

Coverage timeline

15 Sep 2026cspub-ijcisim.org

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Shadow AI represents an ungoverned enterprise risk surface where unsanctioned copilots and autonomous agents can drive higher data-breach costs, and defenders need governance and agent-identity controls to gain visibility and reduce exposure.

An academic paper by Abhipray Mirke and Sushmita Dey Banik proposes a governance framework for managing "Shadow AI" — the unsanctioned enterprise use of generative AI tools, APIs, browser extensions, copilots, and autonomous agents without security review or oversight. Using qualitative document analysis of seventeen sources, it argues prohibition-based strategies are ineffective and presents a ten-principle governance model, risk-tiering structure, agent-identity control baseline, and four-phase roadmap.