July 9, 2026Eran Vaisfailr, Chief Executive Officer

Shadow AI and Shadow Learning: IT's Playbook for L&D

IT already fought the losing battle against unsanctioned tools - here's the three-part playbook it built afterward, and what L&D can borrow before repeating the same mistakes.

Illustration of shadow AI and shadow learning: employees using unsanctioned AI tools and video sources to learn outside the corporate LMS

Key Takeaways

  • Shadow AI and shadow learning are the same behavior, reported to two different departments. An employee who asks ChatGPT how to structure a QBR is triggering a security alert and submitting a curriculum request at the same time.

  • Blocking never worked for IT, and it will not work for L&D. You cannot ban YouTube, ChatGPT, or Slack DMs any more than IT could ban Dropbox in 2013 or shadow AI tools in 2024. The workaround always wins against a policy.

  • The sanctioned path has to win on speed, not on approval. IT's mature answer wasn't a stricter acceptable-use policy - it was providing an approved tool that was faster than the workaround. For L&D, that means delivering learning inside Slack and Microsoft Teams, not behind a portal login.

  • Visibility should mean aggregate demand, never individual surveillance. The goal isn't a log of who searched what. It's a map of which topics, teams, and gaps are generating demand - the same shift IT made from monitoring devices to monitoring patterns.

IT has already run this experiment

Every L&D leader watching "shadow AI" climb the search charts is looking at a rerun. IT lived through the unsanctioned-tool problem twice: first as shadow IT (personal Dropbox accounts, unapproved SaaS, USB drives), then as shadow AI (employees pasting client data into whatever chatbot was fastest). Both times, the instinct was the same - block it - and both times, blocking failed for the same structural reason: the tool wasn't the problem. The tool was solving a real problem faster than the sanctioned alternative could.

Microsoft and LinkedIn's 2024 Work Trend Index found that 78% of AI users bring their own AI tools to work, often without telling IT. That number didn't shrink because policies got written. It shrank in the organizations that gave employees an approved tool that was actually better than the workaround.

Shadow learning is the L&D-side version of the same behavior: the learning employees already do outside sanctioned systems - searching YouTube, asking ChatGPT, messaging a colleague in Slack - the moment a work problem appears. It's unrecorded, so L&D can't see it, credit it, or build on it. In most organizations it's the majority of all workplace learning, and it exists for the identical reason shadow AI exists: the sanctioned option is too slow for the moment the need shows up in.

One distinction is worth keeping straight before going further: shadow learning is not job shadowing. Job shadowing is scheduled and observed - you follow a colleague to learn their role, and someone signed off on it. Shadow learning is the opposite: unscheduled, unrecorded, and invisible to everyone except the employee who needed the answer.

Lesson one: you cannot ban the workaround

IT's first move against shadow IT was almost always a block list. It didn't work, because banning a tool doesn't remove the need the tool was meeting - it just moves the workaround somewhere less visible. Employees switched to personal devices, personal email, personal logins. The governance gap got worse, not better, because now IT couldn't see it at all.

L&D is one step behind on the same move. You cannot block YouTube on a corporate network without blocking half of legitimate work research along with it. You cannot stop someone from opening ChatGPT in another tab. Every attempt to restrict the workaround just pushes the learning further from anything L&D can measure - exactly what happened when IT tried the same thing.

Lesson two: the sanctioned path has to win on speed, not policy

The turning point for IT wasn't a better memo. It was recognizing that employees don't choose unsanctioned tools out of rebellion - they choose them because the sanctioned tool is slower than the problem they're solving. An approval workflow that takes three days loses to a chatbot that answers in three seconds, regardless of how good the policy is.

The fix was to make the sanctioned path competitive on the only dimension that mattered: how fast it got someone from question to answer. That's why flow-of-work delivery, not a new portal, is the lever. An employee will not remember to open a learning platform in the middle of building a dashboard. They will use whatever is already open.

This is the same logic behind delivering learning inside Slack and Microsoft Teams instead of a standalone destination. If the sanctioned path requires leaving the tool where the work is happening, it has already lost to the workaround - no matter how good the content is on the other side of that portal.

Lesson three: visibility should be aggregate demand, not surveillance

IT's early instrumentation efforts often reached for the wrong kind of visibility: device monitoring, browsing logs, DLP tools that flagged individual employees. It bred exactly the mistrust that pushed shadow AI further underground. The lesson that stuck was to instrument the signal, not the person - watch which categories of tools were spiking in demand, then build or license a sanctioned equivalent before the workaround became entrenched.

L&D should take the same turn before it repeats IT's early mistake. The goal isn't a record of which employee searched which topic on YouTube - that's surveillance, and it drives the behavior further out of sight, the same lesson IT learned the hard way. The useful signal is aggregate: which topics are generating repeat questions, which teams are hitting the same skill gap, where demand is showing up faster than any training calendar can plan for. That's a curriculum map, built from real behavior instead of a quarterly survey.

We wrote about the mechanics of an LMS's blind spot in our LMS alternative guide: a scheduled course calendar cannot see or serve a need that arrives with a deadline attached. The same blind spot is what pushes learning into the shadows in the first place.

What it looks like when L&D gets this right

The pattern from IT is consistent enough to state as a sequence: stop trying to block the workaround, build a sanctioned path that's faster than it, and measure demand instead of people. Applied to learning, that means the moment an employee has a work problem, they can get a structured learning path in the tool they're already using - in minutes, not after finding time to browse a catalog - while L&D sees the topic-level pattern without ever seeing an individual's search history.

That's the approach behind Plynn: an employee asks a question in Slack or Teams, and a personalized course from vetted YouTube and internal recordings is ready in under two minutes, with L&D seeing aggregate topic and team-level demand rather than individual records. In one enterprise pilot, 60% of employees adopted it with no mandate from L&D and 90% came back to build a second course - the same signal IT looks for when a sanctioned tool has actually beaten the workaround. Full methodology is on the pilot results page.

Frequently Asked Questions

Is shadow AI the same thing as shadow learning?

They're the same underlying behavior, viewed from two different departments. Shadow AI is IT's term for employees using unapproved AI tools; shadow learning is what that behavior looks like from L&D's side, when the AI tool (or YouTube, or a colleague in Slack) is being used to answer a work question the sanctioned learning system doesn't cover. An employee doing one is very often doing the other in the same conversation.

Why did blocking unsanctioned tools fail for IT, and why would it fail for L&D too?

Blocking removes the tool, not the need. Employees who lose access to a fast workaround don't stop needing the answer - they find a less visible way to get it, on a personal device or a personal account, which makes the behavior harder to see, not less common. The same dynamic applies to learning: restricting YouTube or an AI assistant doesn't create demand for the LMS, it just pushes the learning further outside L&D's view.

What does "visibility without surveillance" actually mean for a learning platform?

It means the system reports on topics, teams, and gaps - not on individual employees. IT's mature shadow-AI programs monitor which categories of tools are spiking in demand across the organization, not which employee opened which chatbot. Applied to learning, that's a map of what the workforce is trying to learn and where, built from aggregate usage rather than a per-person activity log.

Where should L&D start if it wants to apply this playbook?

Start with the signal, not the policy. Look at where work problems currently generate unrecorded learning - new task assignments, recurring support tickets, onboarding gaps - and test whether a sanctioned path can answer those moments faster than the workaround does. If it can't beat the workaround on speed, no amount of policy will bring the behavior back into view.

Ready to transform your L&D?

See how Plynn can help your team learn faster and smarter.

Book a Demo