Skip to Main Content

AI Governance and Mitigating Shadow AI

AI Governance and Mitigating Shadow AI

 

 

 

 

 

 

 

 

 

 

See the article in Texas School Business, September/October 2026.
by Steve Barnwell, Director of Technology, Schertz-Cibolo Universal City ISD

Educational organizations, from small schools to expansive districts, have reached the point in LLM tool adoption where mature, repeatable processes can now take place. While much attention has been placed on instructional guardrails for AI, it is important to recognize that students and teachers are not the only users seeking innovative tools to manage their workloads. The emergence of "shadow AI," much like shadow IT before it, is a symptom of the growing gap between the rapidly expanding number of tools available and the absence of comprehensive, detailed processes for approving or restricting the usage of said tools. Given the unique nature of LLMs, operational procedures must extend beyond traditional software adoption to include guidelines for responsible and appropriate use. As a result, even organizations with robust software approval processes may inadvertently enable shadow AI through staff misuse of officially sanctioned products.

When staff members resort to unsanctioned AI tools, it is rarely due to carelessness or recklessness. Rather, this behavior stems from a lack of clarity, the need for faster solutions, or misalignment between available tools and the demands of their work. District leaders are acutely aware of the high expectations placed on their staff, who in turn are driven to innovate under mounting workloads by seeking more efficient methods. Organizations must acknowledge this reality and commit to communicating available tools, usage processes, and procedures for expanding offerings in a way that is clear and accessible, making workarounds increasingly unnecessary.

The initial impulse to solve shadow AI may be to ban or block access. This approach, however, often pushes activity to personal devices beyond organizational oversight, increasing risk and stifling the innovative problem-solving that moves organizations forward. Rather than prohibiting use, organizations should focus on establishing clear governance that enables responsible innovation through proper channels.

Practical Steps for AI Governance

1. Clear Communication

The foundation of effective AI governance is transparent communication. At its simplest, this can be achieved with a single document or spreadsheet listing approved AI tools and their capabilities. Integrating these resources into a single sign-on platform or web application launcher further streamlines access. However, passive communication alone is insufficient. Mature software approval processes should include notifications to requestors and ongoing training on available resources. Organizations with established software approval processes should adapt them to include AI tools, ensuring clear instructions on appropriate use. For those lacking such processes, the creation of a visible, user-facing approval workflow is the best starting point.

2. Tool Categorization and Human Review

The next step is categorizing and reviewing AI tools to ensure compliance with organizational goals and regulatory requirements. It is essential to evaluate how each LLM offering might expose sensitive data or influence decisions and communications. A critical safeguard, and a legal requirement in Texas through HB 149 and SB 1964, is the implementation of human review. AI must not make significant decisions autonomously, echoing the Manage function of the NIST AI Risk Management Framework. In practice, this means every AI-assisted output, such as student discipline referrals, writing scores, or IEP drafts, must receive explicit human approval and documentation before it becomes a final decision.

3. Maintaining an Organized Governance Process

The categorization process should be as concrete as initial communication efforts. Maintaining a shared list detailing each tool's level of student data access and influence on decision-making helps keep governance organized.

This is also where organizations can note whether tools, paid or free, offer data privacy agreements or refrain from using user prompts for future training. Enterprise and educational deployments may involve contractual safeguards such as tenant isolation, data retention controls, and exclusion of user data from training datasets. Policies and user expectations can be relaxed for tools with higher data security standards, allowing for a tiered approach that reduces the cognitive burden on staff seeking efficient workflows.

Districts that successfully mitigate shadow AI risks will not necessarily have the most extensive policy documents. Effective leadership in AI policy is demonstrated by organizations that make the responsible path to AI adoption easier and more attractive than unapproved alternatives. Human judgment must remain at the core of all AI-influenced decisions. Technology departments should lead this effort by continuously refining communication and categorization processes and adapting as AI technology evolves.

The challenge of shadow AI is not unique to educational organizations, but it is especially critical given the sensitivity of student data and the need for responsible innovation. By focusing on clear communication, thoughtful categorization, and human oversight, districts can foster an environment where staff are empowered to use AI tools efficiently and responsibly, minimizing risk and maximizing the positive impact of technology on teaching and learning.