What is shadow AI?
Shadow AI is people using AI tools for work without the organization's knowledge, approval or guardrails. With coding agents it is concrete: a developer runs Claude Code or Cursor that can execute shell commands, edit files and push to git — with no policy and no record. The risk is not the tool; it is the absence of guardrails. The practical response is to sanction the tools, add a fail-closed checkpoint, and keep a signed record — making the governed path the easy path.
Why it happens
AI coding tools are useful and easy to install, so developers adopt them faster than policy can react. Banning them drives usage underground; the better move is to sanction them with guardrails.
A practical response
- Name the tools you sanction, so people don't reach for unmanaged ones.
- Add a fail-closed checkpoint that blocks destructive actions and secret reads before they run —
npx @scopebond/hook@latest init, then turn each rule on withrules enforce(until then it records). - Keep a tamper-evident, verifiable record so you can see what agents actually did.
- Make the governed setup the default (a one-command install per machine), so the safe path is the easy path.
On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.
What this does not do
Guardrails reduce risk; they do not eliminate it or replace judgement. Scopebond governs what an agent routes through it and records it — it does not discover every tool in use or make a compliance ruling. Pair it with a clear, sanctioned tool list.
Alternatives
- An outright ban — tends to push usage into the shadows; sanction-with-guardrails usually works better.
- Network/endpoint monitoring — sees traffic, not agent intent; a checkpoint decides on the action itself and records it.
FAQ
Isn't the answer to just block AI tools?
Bans tend to create more shadow AI. Sanctioning the tools with a fail-closed checkpoint and a record governs the real usage instead of hiding it.
How do we even see what agents are doing?
Put a checkpoint in front of the agent; every action becomes a signed, verifiable record — the visibility shadow AI lacks.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/cli.test.mjs).