Back to perspectives
/Intellicon FDE Team

Shadow AI: Are You Building AI Assets, or Just Paying Subscription Fees?

Companies often fail to retain the effective methods employees develop through personal accounts—and may also expose themselves to data leakage risks. This article examines the two costs of shadow AI and explains how organizations can turn ways of working into maintainable, transferable AI assets.

AI導入

Consider a common workplace scenario. A procurement specialist spends months repeatedly refining a prompt until the AI can accurately identify discrepancies between quotations and specification sheets. His daily work becomes faster, and the results grow increasingly consistent. The problem is that the prompt remains in his personal AI account. One day, he leaves the company and the account is deactivated, forcing his successor to start from scratch.

A quality assurance engineer may face the same situation. He has fine-tuned the logic for reviewing technical drawings, knows which standards must accompany each type of drawing, and understands which cases cannot be handled by AI and must be escalated for human review. Yet all of these judgments remain buried in his personal conversation history. No one else can see them, and the company cannot take them over.

To determine whether a company is truly building AI capabilities, it is not enough to look at how many people are using AI, how many conversations they are having, or whether one or two departments have produced successful use cases. The real questions are: What prompts have employees revised? What data have they used? How have they taught AI what they know? If no one else has visibility into these activities, then even when the company pays the subscription fees, the resulting knowledge still resides solely with individual employees.

Everyone Is Using AI, but the Company Cannot Retain the Know-How

A 2025 study by MIT NANDA found that only 40% of surveyed companies had purchased official language model subscriptions—that is, enterprise plans procured and managed centrally by the company. Yet at more than 90% of the companies surveyed, employees regularly used personal AI tools for work.

Microsoft and LinkedIn’s 2024 Work Trend Index surveyed 31,000 people across 31 countries. Among those who used AI at work, 78% brought their own tools into the workplace, while 52% were reluctant to admit using AI for their most important tasks. In other words, AI has already become part of everyday work, but much of this usage remains outside the company’s management oversight.

Taiwanese companies face a similar gap. The “2026 Taiwan Industry AI Adoption Survey,” conducted by the Artificial Intelligence Foundation in partnership with Qualcomm, found that 61.8% of AI usage within companies occurs outside their organizations’ control.

Employees find their own tools to get work done, while their companies do not know what they are using, what data they are uploading, or how the outputs are being applied. This unregistered and unmanaged use is known as shadow AI.

The Two Costs of Shadow AI

The first cost is the loss of organizational know-how.

MIT’s research includes the example of an in-house legal professional whose organization spent US$50,000 on a specialized contract analysis tool. She nevertheless continued to use ChatGPT to draft documents because she could refine the output repeatedly until it met her needs. From an individual perspective, this approach makes sense: the readily available tool is effective and improves immediate productivity. But the prompts, decision-making methods, and practical experience developed through repeated revisions are never retained by the company.

The second cost is the risk of data leakage.

IBM’s 2025 Cost of a Data Breach Report found that organizations with high levels of shadow AI incurred an average of US$670,000 more per data breach than organizations with little or no shadow AI. Cybersecurity company Cyberhaven reported in 2025 that 34.8% of the data companies shared with AI tools was sensitive, while 83.8% flowed to platforms rated as high or critical risk. Its 2026 report further found that 32.3% of ChatGPT usage occurred through personal accounts and that 39.7% of the data entered into AI tools involved sensitive information.

When faced with these risks, some companies respond first by imposing an outright ban. In April 2023, Samsung engineers pasted internal source code into ChatGPT, prompting Samsung to announce restrictions on employees’ use of generative AI. A ban can certainly reduce the likelihood of data leakage, but it cannot retain the prompts, judgments, and exception-handling experience that employees have already developed. The tool may be blocked, but the loss of organizational knowledge remains unresolved.

What Can Actually Be Retained?

Companies need to retain three things: tasks, skills, and validation records.

A task documents how a recurring activity receives inputs and what outputs it should produce. A skill captures common rules used across multiple tasks, such as report formats, review standards, and translation terminology. Validation records document which cases have failed and how they were subsequently corrected. Together, these elements represent the company’s operational experience—and one of its most important AI assets.

However, simply saving prompts in a shared folder does not constitute a complete AI asset. For these assets to remain usable over time, three conditions must be met: they must be version-controlled, have designated maintainers, and define a clear scope of application. They must also remain usable when the underlying language model is replaced.

In practice, whenever a task is revised, its maintainer must determine whether the change applies only to a single case or whether the shared rules should be updated. When a standard is revised, the system must also notify the affected tasks so they can be rerun and revalidated. Otherwise, the company is merely moving content scattered across personal accounts into another location that no one maintains.

When methods are not retained within the company, those who follow must repeatedly learn through trial and error—and that cost is often higher than expected. In 2018, Panopto and YouGov surveyed 1,001 U.S. knowledge workers. Respondents reported wasting an average of 5.3 hours per week waiting for colleagues to provide critical information or recreating knowledge that already existed within the company.

Manufacturers Cannot Afford to Wait

For Taiwan’s manufacturing sector, knowledge retention affects not only operational efficiency but also workforce resilience.

According to data from the Ministry of Labor, Taiwan’s manufacturing sector employs 1.322 million people aged 45 or older, accounting for 44.2% of the industry’s workforce. At the same time, the sector has 85,000 job vacancies, and it takes an average of 3.2 months to fill a full-time position. As experienced employees gradually leave the workplace and new hires become harder to recruit, knowledge transfer can no longer depend on verbal instruction passed from mentors to apprentices. The experience of senior employees must be captured before it is too late.

Organize the Knowledge First, Then Connect It to the Model

To begin organizing organizational knowledge, companies can first divide their ways of working into two categories.

Recurring work should be documented as tasks—for example, consolidating monthly shipping reports, comparing BOMs with technical drawings, or producing customs declaration documents. Rules that must be followed while performing the work should be documented as skills, such as report formats, review standards, and translation terminology. Each execution of a task produces a result, while a skill can be referenced by multiple tasks at the same time.

Turning knowledge into an organizational asset means assigning people to maintain these ways of working, making them discoverable to those who need them, and ensuring that the company can continue using them after changing tools. The sequence matters: companies should organize and validate their knowledge before connecting it to a model. Even with a model already in place, organizational knowledge that has not been properly structured remains difficult to put into practice.

Morgan Stanley first organized, classified, and validated approximately 100,000 internal documents. Financial advisors and prompt engineers then rated the AI’s responses, increasing advisors’ use of internal documents from 20% to 80%. Hsin Cheng Industrial, a wire-processing manufacturer in Taichung, similarly began by using AI to turn the tacit knowledge of experienced technicians into training materials and comprehensive SOPs.

The two companies differ dramatically in scale, but they followed the same sequence: first organize the knowledge scattered across employees, documents, and the workplace, then enable AI to use it. This way, the company is not merely paying monthly subscription fees—it is building maintainable, transferable, and reusable AI assets.


This article is excerpted from Intellicon Solutions’ “Agent-Ready: AI Application White Paper for Taiwan’s Manufacturing Industry.” The full white paper explains the differences between tasks and skills, the approval criteria for AI governance, and includes a 12-question self-assessment.

References

Enterprise trials are opening in stages

Want every employee to have their own AI teammate?

Places are limited. Our team will be in touch after you register.