Security1 publisher3 min readPublished
AWS report ties shadow AI to review queues that outlast the experiments
AWS's Reimagine 2026 report, built on 154 executive interviews, says review processes sized for six-month IT programs are driving AI use underground. AWS's answer is governance built into the systems themselves, with humans kept accountable for outcomes.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- In the report's example, a two-week AI experiment that waits a month for approval leads some teams to stop asking for permission at all.
- One unnamed leader interviewed for the report said CIOs who spent years on shadow IT now face shadow AI at ten times the scale.
- Boston University CIO Chris Sedore estimates 40 to 50 percent of people at the university use AI at least weekly, some of it outside systems the university provides.
- A Strand Partners survey commissioned by AWS found 24% of European businesses have a documented approach to responsible AI use and 10% have a data governance strategy.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Every experiment that skips review adds a third-party AI tool holding company or customer data that the security team cannot see and cannot respond to when it leaks.
- decision Security teams have to choose between triaging AI work by risk at intake, as Bradesco does, and keeping one slow queue that low-risk experiments will route around.
- constraint Rules written into an AI agent cannot be treated as the security boundary, so enforcement has to live in the platform or network the agent runs on.
In the report's example, a two-week experiment waits a month for approval. That makes the approval queue roughly twice as long as the work it covers [16]. The authors write that policy in that position is "pushing it underground" [4]. For a security team, underground means the data goes where its controls do not reach. The report says organizations fear proprietary data, customer personal information and confidential business intelligence will escape through AI systems, sometimes invisibly and often through third-party tools employees use without oversight [6].
The evidence comes from interviews. AWS built the report on confidential sessions of 45 to 60 minutes with executives at 128 organizations in 23 industries, run over nine months [2]. Its survey figures come from Strand Partners work that AWS commissioned [7]. The ten-times comparison with shadow IT came from a single interviewee, and the coverage does not name that person [5]. The published summary does not include incident or breach counts. The most direct first-hand account comes from Chris Sedore, CIO at Boston University, on where his users' AI runs. "Some of it in models and systems we provide, some of it going rogue," he said [9].
AWS proposes putting the rules into intake. Rafael Cavalcanti, chief data officer at Bradesco, built a classification tree with three questions: does the use case involve personal data, does it run live or in batches, and must a human stay in the loop [10]. Each combination of answers maps to a risk level and a set of controls [10]. A batch job with no personal data and a live system handling customer records get different controls from the start, without one review sized for the riskier case.
For agents, the authors advise starting with human approval and widening autonomy only after the agent proves reliable, while keeping the option to narrow it again [11]. "Treat it like probation for a new hire," they write [11]. Security limits should sit outside the agent, they say, since agents "can misinterpret or work around embedded rules" [12]. A rule embedded in the agent holds only if the agent reads it correctly. A limit set outside the agent holds either way [12].
The privacy controls work the same way. Where salary data, HR decisions or personal communications were involved, organizations redacted them before processing so that "AI receives the signal without the identity" [13]. At Houston Methodist, staff needed a year with the system before they trusted that it surfaced organizational patterns and left personal content alone [15].
Usage counts do not show whether anyone is governing anything. One organization looked 88 percent "adopted" early on, yet produced better work in fewer than one in 5,000 sessions [14].
What to watch
- Whether AWS publishes the full Reimagine 2026 methodology and the Strand Partners sample size and survey base behind the 24% and 10% figures.
- Whether any interviewed organization discloses an incident traced to an unsanctioned AI tool, which would put a count on leakage the report describes only as a fear.