Financial institutions trying to stamp out shadow AI by blocking unapproved tools may be making the problem harder to see, according to John Denham of Napier AI.
Denham argues that restriction treats a demand problem as a technology problem. In financial services, he says, that demand is here to stay.
Shadow AI is the use of unapproved artificial intelligence tools by employees. Denham says the sector is especially exposed because it combines constant productivity pressure with tightly regulated data. Staff are turning to AI to speed up reporting, compliance tasks, analysis and client communications, and they are often moving faster than governance can follow.
The research he cites shows how wide the gap is. More than 80% of workers use AI tools their employer has not sanctioned, and nearly 90% of security professionals do the same. The teams tasked with controlling the behaviour are taking part in it too.
Denham notes that the motive is usually benign. Employees reach for public tools when approved ones are missing or awkward to use. The consequence is still that sensitive client, proprietary or transaction data can end up in unmanaged systems. Because financial firms face strict audit, compliance and operational resilience obligations, this becomes a regulatory exposure rather than an IT nuisance.
The Napier AI executive draws a distinction between shadow AI and the older problem of shadow IT. Shadow AI adds uncontrolled data leakage through prompts and outputs that can be inaccurate, biased or hallucinated. Auditability also suffers, because there is no record of what was asked, what came back or what shaped a decision. In a regulated customer communication, a hallucination becomes a legal and reputational liability.
Blocking fails, Denham argues, because it ignores why people use these tools in the first place. Workers simply move to personal devices or other applications. Restriction without provision, he warns, turns a visible problem into an invisible one.
He believes the better path is managed adoption. That means providing secure enterprise tools, writing usage policies people can realistically follow, and training staff on safe prompting. It also means defining clearly which data can and cannot be used with AI. Monitoring should avoid fostering a culture of fear, and human oversight should remain in place for high-risk decisions. Encouraging staff to flag mistakes early matters because a risk raised early costs far less than one uncovered during an audit.
Napier AI recommends folding AI governance into existing security, compliance and operational risk frameworks instead of creating a separate discipline. Denham highlights the NIST AI Risk Management Framework, which is built around four ongoing functions: govern, map, measure and manage. He also points to the Cyber Risk Institute’s financial services adaptation, developed with more than 100 institutions.
Looking ahead, he expects shadow AI to become harder to detect as AI is embedded into everyday software, autonomous agents and multimodal tools. As regulators push for explainability and resilience, Denham says the goal is transparent, governed adoption that matches each firm’s risk appetite rather than a ban on AI use.
For more insights, read the full report here.
Copyright © 2026 RegTech Analsyt
Copyright © 2026 RegTech Analyst





