Ask most CIOs where shadow AI lives in their organization and they'll point at sales, or marketing, or some overeager product team pasting customer data into a consumer chatbot. The data says otherwise.

A 2026 WitnessAI survey of 300 enterprise decision-makers found that 47% named IT and infrastructure as the single largest source of shadow AI activity — ahead of every other function in the company. The same survey found 91% of respondents worried AI agents are increasing their financial risk exposure, and 86% had investigated at least one AI-related security or operational incident in the past twelve months.

The uncomfortable part isn't the number. It's the role reversal. IT is usually the function writing the AI acceptable-use policy, running the approval workflow, and fielding the audit questions. When it's also the function most likely to be operating outside that same policy, the org chart stops matching reality.

This tracks with what we see on-site: engineers standing up their own coding assistants, ops teams wiring agentic workflows into ticketing systems over a weekend, sysadmins testing tools nobody in security has ever heard of — all in the name of moving faster. None of it is malicious. Almost none of it is documented.

Over 40% of enterprises in the same survey reported an AI-related incident costing $2 million or more in the past year. That's not a hypothetical line item for next year's budget. It's this year's.

The fix isn't a stricter policy memo — IT already writes those. It's an actual inventory: what's running, who approved it, what data it touches, and who's accountable if it breaks. Most enterprises we work with don't have one. Building it is usually the first thing we do together.