AI proliferation: the shadow IT of 2026

If you've been watching your colleagues over the past few months, you may have noticed it yourself: AI tools are popping up everywhere. ChatGPT on the financial analyst's laptop, a self-built agent that links to internal systems that IT barely knows exist, and a free AI assistant that processes sensitive employee data without anyone knowing where it goes. As Data & Analytics Business Lead at Xylos, I see this pattern every day in the organizations we assist.

What exactly goes wrong when AI adoption goes unchecked, and how do you build an environment that employees enjoy using but is also safe and manageable for IT?

Artificial IntelligenceData & AnalyticsManaged Services

By now the pattern is recognizable, but it looks different than you might think.

Yes, there has been a task force. An enthusiastic team, an Azure OpenAI instance, a chatbot answering questions about internal documents. Three months later, maybe even a demo for management. And then?

Because meanwhile, your financial analyst has built a proprietary GPT running on exported Excel files from last quarter. Your marketing team is working with three different AI tools, not the same two. A developer has built a vibe-coded agent that links to a SharePoint library that hasn’t been synced for six months. And your HR manager requests sensitive employee information from a free chatbot that no one knows where the data goes.

The pilot did not fail. The pilot has multiplied, but unsupervised, ungoverned, on data that no one has validated.

This is not a story about organizations lagging behind on AI. This is a story about organizations that already have AI deep in their daily work, without anyone making a decision. The staff didn’t wait for a strategy. They just started. And now the proliferation is a reality: dozens of local integrations, as many data pollution points, and zero central visibility on what’s actually happening.

 

What specifically goes wrong, and why it escalates

The problems with uncontrolled AI adoption are not hypothetical. They are already visible in organizations that just two years ago thought they wanted to keep their finger on the pulse, did some isolated pilots but still haven’t developed a clear vision. Here is what is happening in practice:

  • Data fragmentation

    Each employee feeds his AI tool with the data he can find himself: exports, screenshots, copywork. The output is based on sources that may not be correct (anymore), not current, and above all not traceable.

  • Shadow IT at scale

    Vibe-coded agents, local automations and browser extensions are built without any IT involvement. They work … until they stop working, and no one knows why or how to fix them.

  • Compliance blind spots

    Sensitive data such as customer data, personnel files, legal documents are shared with external AI services without a processor agreement, let alone a data classification policy.

  • Inconsistent output as the new norm

    Two employees asking the same question to two different tools get two different answers. No one knows which one is correct. Slowly, uncertainty creeps into decision-making because what was once factual is now substantiated by different tools with different outcomes.

  • Irreconcilable technical debt

    Any local integration built now outside the central platform will soon be a legacy problem. The organization that wants to scale to enterprise AI in two years will pay double.

The question is no longer, “When do we start AI?” The question is, “Who is responsible for what is already running?”.

 

The solution is not a policy, it is a platform

The intuitive response to proliferation is regulation: create an AI policy, ban unapproved tools, install a governance committee. That doesn’t work. Employees accustomed to the productivity gains of AI don’t quit because HR sends a memo.

The only effective approach is to provide a better alternative. A platform that is at least as accessible as the separate tools people use now but built on reliable data, within the governance of the organization, and manageable by IT.

Exactly that is what Xylos enables, with Microsoft Fabric and Copilot Studio at its core. Not as a replacement for what people are already doing, but as the controlled environment within which they may continue to do it.

The logic is simple: if employees are going to build agents anyway, give them Copilot Studio. If they are going to query data anyway, give them access to a Fabric dataset that is correct. You shift sprawl to a walled garden AND gain quality, security and scalability at the same time.

 

 

Microsoft Fabric: reliable data as the foundation

The fundamental problem behind all the proliferation is the same: everyone is working with their own version of the truth. Microsoft Fabric solves that by bringing together all the data sources within your Microsoft tenant into a unified platform. With OneLake as the central data layer shared by all other services.

What that means in practice: a Copilot agent built on top of Fabric always pulls from the same certified, current data source. No outdated Excel exports. No SharePoint libraries that are six months behind. One version of the truth, for everyone, at all times.

At the same time, Fabric integrates seamlessly with Microsoft Purview for data governance and compliance, allowing you to see exactly what data is being used for what, by whom, and whether it’s within applicable regulations.

 

Copilot Studio: the controlled environment for what employees do anyway

Copilot Studio allows organizations to build (or have employees build) custom AI agents within the secure environment of their own Microsoft tenant. The agents link to Fabric data, SharePoint libraries, Dynamics 365 and external systems via certified connectors.

The difference between this and what happens in the wild now is crucial: everything built in Copilot Studio is visible to IT, auditable through Purview, and subject to Entra ID’s identity and access management. The employee who wants to build an agent for his team can do so, but not out of sight of the organization.

That is the shift from proliferation to controlled innovation. Not by banning, but by providing a better alternative that people actually want to use.

 

This requires more than technology

Setting up a Fabric environment and rolling out Copilot Studio won’t solve sprawl on its own. What it requires is a combination that many organizations now lack: data engineers who build and manage the Fabric architecture, AI architects who design agents that connect to real business processes, and adoption facilitators who help employees transition from their familiar loose tool to the centralized platform.

Organizations with a strong M365 foundation have an advantage here that they rarely exploit. The governance structures are in place. Identity management is in place. Users know the Microsoft environment. What’s missing is the connection layer, the expertise to enrich that existing infrastructure with data engineering and AI architecture that actually scales.

In the following article, we show how Power Apps acts as a concrete gateway: the technology that your existing team already knows about, and can bridge the gap to integrated AI that really lands in the organization faster than imagined.

 

Do you recognize the proliferation in your organization? Then now is the time to lay the architecture that turns chaos into a competitive advantage. Contact us for a free consultation on what controlled AI integration means for your Microsoft environment.

 

About the author

Peter Verrykt is Data & Analytics Business Lead at Xylos and guides organizations in turning data into concrete business value. He helps companies look beyond technical implementations and use data as a foundation for better decisions, greater agility and sustainable growth.

Share this story

Let's talk about your next project.

Team Xylos is ready to meet you!

Other interesting stories