Shadow AI

Shadow AI, From the User's Side

9/9/2026

"Shadow AI" usually gets described as a governance problem: employees pasting sensitive data into public chatbots, teams standing up unsanctioned tools, IT departments finding out about AI usage after the fact instead of before it. That's the enterprise view — from the top down, looking for exposure, and it's the view the last piece in this series was written from.

Flip the vantage point and it looks different. From the user's side, none of this is rebellion. It's just what happens when knowledge, which has always been personal, meets a tool that finally keeps up with how personal and productive it actually is.

Knowledge was always a personal bookcase

Before it's shared, scrutinized, or organized into a wiki, knowledge lives somewhere much smaller: a personal bookcase. Two people can own the same books and shelve them completely differently — by subject, by mood, by how recently something was read — because the organizing principle was never the content. It was the person. That organization shifts over time too; what a bookcase looks like at twenty and at sixty is rarely the same, the way memory itself gets more selective, and more forgetful, with age.

That same shelf holds two different modes at once — leisure and work, a passing curiosity and a year-long research thread — without needing to be split into separate systems. It's one shelf because it's one person's mind.

And personal knowledge doesn't stay personal by choice. It moves through a loop where people push it outward: creatively, by extending or reimagining an idea; pragmatically, by adapting it to a local context; or argumentatively, by proposing an alternative and defending it against pushback. That's the informal version of peer review — debate until something like consensus forms — and a human is the one turning that wheel at every step, not the knowledge itself. Eventually it goes back to the commons: shared through libraries, wikis, and communities, and critiqued there the way a draft gets reviewed before it becomes a book.

Where the personal bookcase actually gets filled

None of this happens in a vacuum. Before knowledge ever reaches a chat window, it's usually been gathered from a scattered set of everyday sources: Facebook groups, Reddit threads, personal and company websites, message boards, X or Substack posts, YouTube videos, a plain internet search, and increasingly, a direct back-and-forth with an AI chatbot itself. These are the consumption mechanisms — the equivalent of walking into different rooms of a library, except each room has its own tone, bias, and level of scrutiny attached.

That mix is exactly why the resulting personal knowledge is so uneven in quality, and exactly why it's so valuable: it's synthesized across sources nobody else combined in that order, filtered through one person's judgment about what to trust, and shaped into something that only makes sense shelved the way they shelved it. The AI chatbot doesn't replace these other sources so much as sit at the end of the chain, becoming the place where a person increasingly does the sorting, the questioning, and the note-taking that used to happen across a dozen open tabs.

The chatbot is the new bookcase

This is where Shadow AI actually comes from. A chat history with an AI assistant is a bookcase now — arguably a more intimate one than any actual shelf, because it captures not just what someone read but what they asked, in their own words, at 11pm about a work problem and at 11:05 about something completely unrelated. It's organized by nothing but the order a person thought of things, which is exactly how personal knowledge has always worked.

That personal-ness is precisely what makes it valuable to the user and awkward for an organization. A few distinctions matter here:

  • Short-term vs. long-term memory. A single session's context — what's been said in this conversation — behaves like working memory: useful right now, gone once the session ends unless something is deliberately carried forward. Long-term memory is the deliberate exception: facts, preferences, and context a person (or a system on their behalf) chooses to persist across sessions, the way a note gets moved from a scrap of paper onto a permanent shelf.
  • Audit logs, and where they actually sit. Every one of those exchanges is a record somewhere — on a personal device, in a vendor's cloud, in an enterprise's own systems, or split across all three. From the user's side, that log is just their thinking made visible. From the organization's side, it's the one part of "shadow" AI usage that actually matters: if the record doesn't sit somewhere the organization can see, govern, or retrieve, the knowledge that was generated on its behalf effectively never happened, as far as the organization is concerned.

That gap — a chat history that's genuinely useful to the person who created it, and genuinely invisible to the organization they work for — is the real shape of Shadow AI. It isn't people trying to hide something. It's personal knowledge doing what personal knowledge has always done, running into a system that hasn't caught up to the fact that the bookcase moved onto a server nobody's looking at.

The point isn't to eliminate the shadow

Trying to stamp out personal AI use is roughly as effective as trying to stop people from keeping personal notes — it doesn't work, and it throws away the creative and pragmatic value that personal knowledge generates in the first place. The more useful question is the one this series keeps circling back to: how do you let that personal loop keep running — creativity, localization, argument, the human turning the wheel — while giving the resulting knowledge somewhere legitimate to go? Somewhere it can be surfaced, reviewed, and folded back into the shared, structured knowledge the rest of this series has been arguing should be commodity-priced and commonly held.

That's the actual design problem. The next piece looks at what a framework built to solve it might look like.