Your people are already using AI. The question is whether they understand why it matters

Shadow AI is the governance problem many risk and compliance leaders are now grappling with. Not because the technology is dangerous in itself, but because it is being adopted faster than the frameworks meant to govern it.

Staff drafting board papers with a chatbot. Client data pasted into an AI tool to summarise a report, with no thought given to where that data goes next. A recruitment manager running CVs through an AI screener they found online. A finance analyst modelling scenarios with commercially sensitive figures in a consumer tool.

None of these people think they are doing something wrong. Most are trying to do their jobs better. That instinct is not the problem. The problem is that we have failed to tell them why they should think twice.

A New Zealand case in point

This is not theoretical. In March 2026, RNZ reported that Health NZ staff in mental health services had been using free AI tools to help write clinical notes. A memo to staff in one district reminded them that this was prohibited, and warned that it could lead to formal disciplinary action.

The detail that matters most is this: the prohibition extended even to information staff had anonymised before entering it, and to notes drafted in an AI tool and then transcribed by hand. The anonymising is the tell. Stripping out identifying details before pasting the text in is what someone does when they have grasped that raw patient data does not belong in a consumer tool, but not why anonymising does not fix the problem. The behaviour points to people working to comply, not people ignoring the rule. What it does not show is an understanding of why anonymising was not enough.

The reason is that when clinical information enters a free consumer AI tool, even anonymised, it leaves the organisation’s systems. There is no contractual safeguard, no visibility over where the data goes, no ability to retrieve it, and no accountability framework around it. And this is mental health information, among the most sensitive that exists.

Notice too that the memo was a reminder, not a new rule. The prohibition was already in place. Staff had already been told what they could not do, and what the approved process was. They did it anyway. Not out of malice, but because no one had made the reason real enough to change behaviour at the point of decision.

It is worth being clear about what this is not. It is not an anti-AI story. Health NZ is actively deploying an approved AI scribe across hospitals. The issue was never AI itself. It was unsanctioned AI, used without governance, in a setting where the risks were poorly understood. That distinction matters for how any organisation frames its governance.

One more point, because it complicates the easy reading. If staff knew the policy, knew the process, and knew that disciplinary action was possible, and did it anyway, is that not an enforcement problem rather than a communication one? It is a fair challenge. But look at what the behaviour actually shows. These were not staff flouting a rule they understood and rejected. They were improvising a workaround, anonymising, transcribing by hand, to thread the needle between a governance constraint and a workload reality. That is not how people behave when they understand a risk and have chosen to accept it. It is more consistent with understanding the rule but not the principle underneath it. The distinction matters, because enforcement addresses the first and not the second.

There is a second challenge, and it is the stronger one. When this episode was reported, the Public Service Association argued the real issue was not communication at all but pressure: staff were turning to free tools because they were overloaded and had no approved alternative to hand. That is fair, and it is not in competition with the point here. A workforce under pressure, with no sanctioned tool and no clear understanding of why the unsanctioned ones are dangerous, faces two failures at once. Closing the communication gap does not remove the resourcing gap. But of the two, communication is the one most organisations can act on immediately, at the lowest cost, and it is the one most often left undone. Naming the why does not excuse failing to provide a usable how. It is the part that is too often skipped even when the resources exist.

The three layers of governance communication

In my work with boards, I have found it useful to think of governance communication as operating on three levels. Most frameworks address only two.

The what. The rule, control, or expectation. “Do not enter personal, client, or commercially sensitive information into any AI tool that has not been approved.” Clear and specific. Health NZ had this.

The how. How someone complies. The approved tools, the process for requesting approval, who to contact. This is where most organisations put their effort: policies, training modules, intranet pages. It is necessary, and not sufficient. Health NZ had this too.

The why. Why the control exists. What the actual risk is. What the legal, ethical, and reputational consequences of getting it wrong are. This is where nearly every organisation falls short, and it is the layer that decides whether governance changes behaviour. The anonymising behaviour said exactly this. It showed the what had landed and the how was being worked around. What was missing was a why concrete enough to make someone stop.

The omission is not minor. It is why shadow AI persists even in organisations with mature policies. People who understand only the what and the how follow the rule when it is convenient and find ways around it when it is not. People who understand the why internalise the principle, and apply it even in situations the policy never anticipated.

Guardrails, not prison walls

There is a useful way to picture the difference. Governance built mainly on the what and the how produces prison walls: prescriptive controls that people resent, work around, or comply with superficially, and that offer no guidance the moment a tool appears the policy did not anticipate. Governance built on the why produces guardrails: people who understand the principle under the rule, exercise judgment in novel situations, and raise questions rather than making quiet workarounds.

This matters more in AI than almost any other domain, because the technology is moving faster than policy can track. An organisation whose people understand why caution is warranted will navigate that uncertainty far better than one whose people only know which tools are on today’s approved list.

Four ways to embed the why

Lead with consequence, not the rule. Before the control, name what could go wrong and point to where it already has. A real, current, local example lands harder than a policy clause. An anonymised clinical note entered into a consumer tool in a New Zealand mental health service is more persuasive than any preamble.

Put the why inside the how. Do not separate the rationale from the guidance. Place it immediately before the instruction, in the same document, at the point of use: here is why this control exists, in two sentences, and here is how to comply. A rationale buried in a preamble no one reads is functionally absent.

Connect individual action to organisational consequence. The most effective explanations link what one person does at their desk to what it means for the organisation, its clients, and its legal obligations. People respond to stakes they can see. Abstract risk registers do not change behaviour at the point of decision; concrete, personal consequences do.

Make it a board and executive conversation. When governance is framed at leadership level as a cultural priority rather than an IT checkbox, that tone cascades. Boards that understand why AI governance matters, not just that it is required, ask better questions and set clearer expectations. The why has to be present at the top before it is credible anywhere else.

The bottom line

Shadow AI is not primarily a technology governance failure. It is a communication failure: the sustained failure to answer why.

Organisations that take seriously the work of building understanding, not just procedural compliance, will be better placed to manage AI risk as the technology keeps evolving. Not because their policies are more comprehensive, but because their people are better equipped to exercise judgment when the policies run out. In an environment where AI is advancing faster than any policy framework can track, that judgment is the most important governance asset you have.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top