Anatomy of Shadow AI: Unsanctioned Models vs. Governance Bottlenecks

Every CIO and CISO today knows their people are using unsanctioned AI tools. The data risk is obvious: proprietary code pasted into consumer LLMs, confidential projections uploaded for quick summarization, controlled information fed into unvetted generators. The exposure is not theoretical, and it is not small.

When security teams discover these workflows, the default reflex is to enforce. Block the domain endpoints at the egress proxy, issue a stern policy update, mandate refresher training. Three weeks later, usage numbers have not dropped. They have shifted to personal hotspots, locally hosted open-source models, and unmonitored API wrappers.

This is where standard enterprise security fails. It treats shadow AI as a behavioral compliance problem when it is almost always a system architecture problem. Before leadership spends another dollar on blocking, it needs to run one diagnostic: are you dealing with an enforcement gap or a friction gap?

The Enforcement Gap: Reckless Behavior in a Governed Environment

An enforcement gap exists when legitimate, enterprise-grade AI tools have been provided, but people bypass them out of convenience, ignorance, or a desire to skirt operational guardrails.

  • Redundant tooling: Staff use public chat interfaces to write code even though the organization has provisioned dedicated, privacy-compliant enterprise seats.
  • Ignorance of data sensitivity: Users treat external AI interfaces like search engines, unaware that prompt inputs may be retained or used for model training.
  • Bypassing access controls: People actively seek workarounds to move data out of restricted environments and into unauthorized tools in order to skip approval queues.

Enforcement gaps stem from poor visibility, vague policy, and no real-time feedback at the endpoint. When policy lives in a static twenty-page PDF on an intranet share rather than surfacing inside the workflow at the moment of decision, violations become inevitable. This is the same failure pattern we described in measuring the wrong things: the control exists on paper, but nothing in the operational environment tells anyone it is there.

The Friction Gap: When Governance Becomes the Bottleneck

A friction gap occurs when people use unsanctioned tools not because they want to break rules, but because the official channel is so slow, restrictive, or inadequate that compliance makes the daily job impossible.

  • The procurement black hole: A developer requests access to a specialized vision model for document processing, and the security review ticket sits unresolved for four months.
  • Sterilized utility: The official AI portal is so heavily locked down, token-throttled, or context-handicapped that it produces generic, unusable output.
  • Fragmented tooling: Teams are forced onto piecemeal internal tools that lack basic modern capability, such as document upload, retrieval over their own corpus, or code execution.

Friction gaps are created by legacy governance models trying to manage high-velocity capability with low-velocity approval processes. When security acts solely as a gatekeeper rather than an enabler, governance itself becomes the single largest driver of shadow IT.

Federal and defense organizations feel this acutely, and the policy landscape reflects it. OMB Memorandum M-25-21 pushed civilian agencies toward faster adoption, directing them to stand up AI governance boards, name chief AI officers, and issue generative AI policy on a fixed clock. It also states plainly that national security systems are governed under separate authority. That carve-out matters: defense components do not inherit the civilian timeline, so the friction gap inside a national security environment is shaped by different rules and often runs longer. The exposure does not go away because the deadline does.

The Diagnostic Matrix: Identifying Your Real Exposure

Before another round of firewall rules or security memos, place your organization on two axes: how much enforcement capability you actually have, and how much friction your governance process imposes. Four positions emerge.

  • Critical danger zone (high friction, low enforcement): heavy risk. Users bypass slow systems to deliver work, and you have no visibility into where the data went.
  • Active rebellion (high friction, high enforcement): users build rogue stacks specifically to maintain velocity against the controls you deployed.
  • Informal adaptation (low friction, low enforcement): low awareness rather than defiance. Correctable with basic tooling and better in-workflow guidance.
  • Sanctioned velocity (low friction, high enforcement): secure, frictionless, fully governed adoption. This is the target state.

Most organizations that describe themselves as having a shadow AI problem are sitting in active rebellion and treating it as informal adaptation. The remedy they reach for, more training, is calibrated to a quadrant they are not in.

Closing the Enforcement Gap

Two moves matter more than the rest.

Implement dynamic egress monitoring. Deploy API gateway controls and browser-level inspection that evaluate prompt payloads for sensitive patterns, including credentials, proprietary code, and controlled data, at the point of origin, before the request leaves organizational control. As TLS 1.3 and encrypted client hello make traditional network-perimeter inspection less reliable, governance has to follow the data itself rather than the infrastructure it happens to traverse. The joint AI data security guidance from NSA, CISA, and the FBI makes the same argument from the defensive side: provenance and integrity controls belong on the data, and they are explicitly aimed at defense industrial base and national security system owners.

Provide context at the point of friction. Replace the generic browser error screen with a landing page that explains why the destination is blocked and offers a one-click path to the approved alternative. A block that ends in a dead end teaches people to route around you. A block that ends in a working tool teaches them where the tool is.

Closing the Friction Gap

Establish a fast-track governance tier. Standard vendor risk assessment takes months. Create a lightweight sandbox clearance path, measured in days rather than quarters, for low-risk utilities that do not ingest sensitive or controlled data. Not every tool needs the full review, and treating them as though they do is what created the backlog.

Build an internal AI gateway. Provide a centralized, secure wrapper that grants access to capable foundation models behind enterprise privacy terms, zero-retention agreements, and unified identity and access management. The joint guidance on deploying AI systems securely is built around exactly this posture: govern the deployment boundary of externally developed models rather than pretending you can keep them out.

Neither track works alone. Fix only enforcement and you drive usage further underground. Fix only friction and you build a fast lane with no telemetry. The risk mutates rather than resolving, which is the same dynamic we mapped in data gaps and visualization gaps.

The VeriTech Takeaway

Unsanctioned AI usage is rarely a sign of bad employees. It is a symptom of an organization whose internal velocity has outpaced its governance architecture.

If your team is playing an endless game of whack-a-mole with unauthorized tools, stop measuring employee compliance and start measuring governance latency. How many days from request to decision? How many approved tools actually do the job? Until the secure path is also the fastest path, shadow AI stays the default mode of operation.

This is the problem SKY Operations was built for: putting policy, identity, and data authority in a control plane that executes at runtime rather than living in a document, an approach grounded in the Sky Computing model and the same architectural logic behind zero trust needs digital twins. For organizations that need to know whether their existing controls actually see what they claim to see, ARB1T3R benchmarks that visibility against ground truth. To work through where your organization sits on the matrix, talk with our team.

VeriTech Consulting is a Service-Disabled Veteran-Owned Small Business. References to government organizations, policies, and published guidance are for analytical context only and do not imply endorsement by any federal department or agency.

VeriTech Services

True Tech Advisors – Simple solutions to complex problems. Helping businesses identify and use new and emerging technologies.

Greg Bew

CEO

CEO | Data Architecture & AI Strategy Leader | Cyber Operations & Decision Advantage Expert

Greg Bew is a technology and transformation leader with deep expertise in data architecture, cyber operations, and large-scale enterprise modernization. With over two decades of experience spanning military service and industry, Greg has led the design and implementation of mission-critical data platforms, advanced analytics capabilities, and AI-driven decision systems supporting national security and defense operations.

A retired U.S. Army Lieutenant Colonel, Greg served in key leadership roles across cyber and intelligence organizations, culminating as a Senior Advisor to the Commander of DoD Cyber Defense Command and the Director of DISA for Data, Analytics, and AI. In these roles, he helped shape the Joint Cyber Warfighting Architecture (JCWA), driving the transition toward data-centric operations and enabling decision advantage across distributed, contested environments.

As the Founder & CEO of Veritech Consulting, Greg applies this experience to help government and enterprise organizations design and operationalize modern data architectures. His work focuses on integrating cloud, AI/ML, and distributed data systems into cohesive, mission-aligned platforms that prioritize governance, scalability, and real-world operational impact.

Key Expertise & Accomplishments:

Data Architecture & Platform Engineering – Designed and led enterprise-scale data platforms enabling distributed analytics, AI integration, and real-time decision support across multi-domain environments.

Cyber Operations & Intelligence Integration – Extensive experience aligning data, analytics, and operational workflows to support cyber defense, intelligence fusion, and mission execution.

AI & Advanced Analytics Enablement – Spearheaded initiatives to operationalize AI/ML within secure environments, integrating model deployment, governance, and data pipelines at scale.

Strategic Leadership & Advisory – Served as a senior advisor to three-star leadership, shaping enterprise data strategy, governance models, and cross-organizational integration efforts.

Cloud & Distributed Systems Modernization – Led transitions from legacy architectures to cloud-native and federated data environments, emphasizing resilience, sovereignty, and performance.

Career Highlights:

🔹 Senior Advisor, DoD Cyber Defense Command & DISA – Guided enterprise data and AI strategy supporting the Joint Cyber Warfighting Architecture and global cyber operations.

🔹 Senior Principal Data Platform Engineer, Leidos – Delivered advanced data solutions and modernization strategies across defense and federal customers.

🔹 U.S. Army Lieutenant Colonel (Retired) – Led cyber, intelligence, and data-focused units, driving innovation in operational analytics and mission systems.

Thought Leadership & Innovation:

📘 Author of Sky Computing: The Architecture of Data Sovereignty, introducing a new model for governing data, authority, and computation in distributed environments.

🚀 Creator of frameworks and platforms focused on data sovereignty, federated control, and AI-enabled decision advantage.

📊 Advocate for data-centric operations, emphasizing the alignment of technology, governance, and mission outcomes.


Greg Bew continues to lead Veritech Consulting with a focus on delivering practical, high-impact solutions that help organizations navigate complex technology landscapes and achieve decisive advantage through data.

Liana Pannell

Director of Operations

Liana is a process-driven operations leader with nine years of experience in project management, technology program management, and business operations. She specializes in developing, scaling, and codifying workflows that drive efficiency, improve collaboration, and support long-term growth. Her expertise spans edtech, digital marketing solutions, and technology-driven initiatives, where she has played a key role in optimizing organizational processes and ensuring seamless execution.

With a keen eye for scalability and documentation, Liana has led initiatives that transform complex workflows into structured, repeatable, and efficient systems. She is passionate about creating well-documented frameworks that empower teams to work smarter, not harder—ensuring that operations run smoothly, even in fast-evolving environments.

Liana holds a Master of Science in Organizational Leadership with concentrations in Technology Management and Project Management from the University of Denver, as well as a Bachelor of Science from the United States Military Academy. Her strategic mindset and ability to bridge technology, operations, and leadership make her a driving force in operational excellence at VeriTech Consulting.

Keri Fischer

COO & Founder

Founder & COO | Cybersecurity & Data Analytics Expert | SIGINT & OSINT Specialist

Keri Fischer is a highly accomplished cybersecurity, data science, and intelligence expert with over 20 years of experience in Signals Intelligence (SIGINT), Open Source Intelligence (OSINT), and cyberspace operations. A proven leader and strategist, Keri has played a pivotal role in advancing big data analytics, cyber defense, and intelligence integration within the U.S. Army Cyber Command (ARCYBER) and beyond.

As the Founder & COO of VeriTech Consulting, Keri leverages extensive expertise in cloud computing, data analytics, DevOps, and secure cyber solutions to provide mission-critical guidance to government and defense organizations. She is also the Co-Founder of Code of Entry, a company dedicated to innovation in cybersecurity and intelligence.

Key Expertise & Accomplishments:

Cyber & Intelligence Leadership – Served as a Senior Technician at ARCYBER’s Technical Warfare Center, providing SME support on big data, OSINT, and SIGINT policies and TTPs, shaping future Army cyber operations.
Big Data & Advanced Analytics – Spearheaded ARCYBER’s Big Data Platform, enhancing cyber operations and intelligence fusion through cutting-edge data analytics.
Cybersecurity & Risk Mitigation – Excelled in identifying, assessing, and mitigating security vulnerabilities, ensuring mission-critical systems remain secure, scalable, and resilient.
Strategic Operations & Decision Support – Provided key intelligence support to Joint Force Headquarters-Cyber (JFHQ-C), Army Cyber Operations and Integration Center, and Theater Cyber Centers.
Education & Innovation – The first-ever 170A to graduate from George Mason University’s Data Analytics Engineering Master’s program, setting a new standard for data-driven military cyber operations.

Career Highlights:

🔹 Senior Data Scientist – Led groundbreaking all domain efforts in analytics, machine learning, and data-driven operational solutions.
🔹 Senior Technician, U.S. Army Cyber Command (ARCYBER) – Recognized as the #1 warrant officer in the command, driving big data analytics and cyber intelligence strategies.
🔹 Division Chief, G2 Single Source Element, ARCYBER – Directed 20+ analysts in SIGINT, OSINT, and cyber intelligence, influencing Army cyber policies and operational training.
🔹 Senior Intelligence Analyst, ARCYBER – Built the Army’s first OSINT training program, improving intelligence support for cyberspace operations.

Recognition & Leadership:

🛡️ Lauded as “the foremost expert in data analytics in the Army” by senior leadership.
📌 Key advisor to the ARCYBER Commanding General on all data science matters.
🚀 Led the development of ARCYBER’s first-ever OSINT program and cyber intelligence initiatives.

Keri Fischer is a visionary in cybersecurity, intelligence, and data science, continuously pushing the boundaries of technological innovation in defense and national security. Through her leadership at VeriTech Consulting, she remains dedicated to helping organizations navigate the complexities of emerging technologies and drive mission success in an evolving cyber landscape.

Education:

National Intelligence University Graphic

National Intelligence University

Master of Science – MS Strategic Intelligence

 – 

George Mason University Graphic

George Mason University

Master of Science – MS Data Analytics

 –