Employees discover ChatGPT and similar tools and immediately gain speed on drafts, summaries, and brainstorming. Leadership sees the demos and asks why the company needs anything else. Simultaneously, security sees pastes of customer data, source code, and contracts into consumer endpoints. Both observations are true — and they collide.
The confusion is category error. A general assistant optimised for open-ended conversation is not the same product as an invoice extractor wired to ERP, a KYC workbench with audit trails, or an HR assistant grounded only in approved policy. Buying “seats of chat” does not create routing rules, role-based access, evaluation harnesses, or model change management.
Shadow AI grows in the gap. Teams solve real pain with personal accounts because official IT has no sanctioned alternative. When a regulated incident occurs, nobody can reconstruct prompts, sources, or approvals. Boards then swing from enthusiasm to prohibition — killing productivity without solving the original workflow problems.
CISO and risk own data-handling boundaries; IT owns sanctioned tool catalogues; business owners own workflow requirements; legal owns policy language. Anti-patterns include equating “we bought enterprise seats” with governed workflows, measuring success only by seat adoption, and delaying sanctioned alternatives so long that shadow AI becomes cultural default.
The decision framework is simple to state and hard to operationalise: allow consumer-class tools for low-risk personal productivity under clear rules; require enterprise-controlled systems for processes that need retrieval grounding, integration, human-in-the-loop, logging, and vendor accountability. Arcloops exists for the second class — and for the consulting work that draws the line.