By the time a security team sits down to write its shadow AI policy, the problem is already months old. Dozens of unsanctioned AI tools are usually in use across the organization, and most of them are invisible to IT. The people using them aren’t being reckless.