Bypassing the approved tool to get the job done
Leo is an industrial HVAC contractor who spends most of his Tuesdays looking at “as-built” diagrams that bear only a passing resemblance to the actual network of copper and galvanized steel vibrating behind the drywall. (An as-built diagram is a revised set of drawings submitted by a contractor upon completion of a project to reflect all changes made during construction).
Last week, Leo was installing a high-pressure relief valve in a dairy processing plant-a shiny, brass component that satisfied the local fire marshal’s checklist but sat entirely downstream of a manual bypass the floor workers used to keep the pressure from ever hitting the sensor.
$1,422
The price of a shiny brass component that remained pristine and untouched, optimized out by the line workers.
The valve was a monument to a theoretical system that the people actually working the line had long ago optimized out of existence. It cost the dairy $1,422 to install a piece of equipment that would remain pristine and untouched until the building was eventually demolished.
In the Wednesday project call, Elena says the summary was pulled together from the transcript, and she leaves the sentence hanging there like a loose thread no one wants to pull. (A transcript, in this context, is the raw, often incoherent text dump of forty minutes of human stuttering and “can you hear me” interruptions).
Everyone on the call knows there is only one way she produced eight pages of structured, insightful notes overnight while also managing three other accounts. They know she didn’t use the “Enterprise-Safe Assistant” the firm pays for. That tool-a sluggish, neutered LLM that requires a three-factor authentication and times out if you sneeze-has been opened by precisely since the launch in , and by exactly zero people twice.
The Silent Migration to Shadow IT
This is the great unspoken reality of the modern office: the approved tool is a theatrical performance, while the unapproved tool is the engine. Procurement departments optimize for defensibility (the ability to prove you followed the rules if everything goes south) rather than usefulness. They choose the vendor who can fill out a 418-page security questionnaire, even if the resulting software has the cognitive processing power of a mid-90s graphing calculator.
The result is a widening gap between what is “compliant” and what is “effective.” When a tool is so restricted that it becomes a friction point, users do not simply work slower; they move their work into the shadows. (Shadow IT refers to the use of information technology systems, devices, software, applications, and services without explicit IT department approval).
The gap between the “Approved” map and the organizational reality.
I once gave a tourist directions to the local library, only to realize three blocks later I’d sent them toward the municipal impound lot. I felt a surge of authority when I spoke, a certainty that I knew the grid of this city, but my memory had prioritized the logic of where the library should be over the reality of where it actually sat.
Compliance officers do this every day. They point the organization toward the “Approved” tool because the map says it’s there, ignoring the fact that the actual library moved across town .
Mason T., a fire cause investigator, spends his life looking at the charred remains of buildings to find where the heat started. (A fire cause investigator is essentially a detective who specializes in the physics of combustion). He knows that most fires don’t start in the stove; they start in the “clipping”-an unauthorized modification made to a circuit to keep a breaker from tripping.
🔥
“If the breaker trips every time you use the toaster, you don’t stop using the toaster; you jam a penny in the fuse box.”
In corporate tech, a bad “approved” tool is a breaker that trips too often. The “penny” is the employee’s personal ChatGPT account, used on a personal phone to summarize a confidential strategy deck because the internal tool told them the file was 4 kilobytes too large.
The most dangerous tool in any company is not the one that got rejected by the IT committee. It is the excellent, high-performing one that nobody can say out loud in a meeting. This creates a relocation of risk. Instead of the risk being managed by the company’s security protocols, it is moved into an unlit part of the organization where there is zero visibility.
The Physics of Corporate Combustion
Latency-the frustrating delay between clicking a button and seeing something happen-is often the primary driver of this migration. If the approved AI takes 45 seconds to generate a response and the unapproved one takes three, the user will choose the three-second option every single time, regardless of the “Data Privacy Awareness” sticker on their laptop.
Latency Breakdown
Approved “Enterprise” Tool
45 Seconds
The “Shadow” Unapproved Tool
3 Seconds
The irony is that the “Approved” status is often a shield for the person giving the approval, not a benefit for the person using the software. If Tool B is mediocre but has a massive legal department and a SOC2 Type II report (a document that confirms a company’s internal controls are set up to protect client data), it is the “safe” choice for the Procurement Lead.
If Tool B fails to help the company grow, no one gets fired. But if Tool A-the brilliant, transformative tool-is used and a single minor data leak occurs, the person who signed the contract is on the hook.
This creates the “Questionnaire Victory.” A vendor wins the contract because they checked the most boxes, not because they solved the most problems. This leads to a scenario where compliance departments spend an average of 1,180 hours a year on paperwork for tools that are eventually bypassed by the very people they were meant to protect.
The gap between the sanctioned world and the real world becomes a chasm. To bridge this, we have to look at architectural protection rather than just contractual protection. You cannot legislate away the human desire for efficiency.
Building Bridges: From Compliance to Architecture
If you want people to stop using unapproved AI, you have to give them a tool that is as good as the one they are sneaking. This means providing an anonymous gateway to the top-tier models they actually rely on-the ones that can actually write code, summarize transcripts, and analyze complex data without the “lobotomy” that corporate filters often impose.
When you use something like tunnel AI, you are essentially creating a secure airlock. (An airlock, in engineering terms, is a chamber that allows the passage of people and objects between environments of different pressures).
It allows the high-performance model to do the work while the identity of the user and the sensitivity of the data are stripped away before they ever hit the vendor’s servers. It’s a way to acknowledge the reality of the “Shadow IT” and bring it back into the light by making the safe option the fastest option.
The goal should be zero-knowledge encryption-a system where even the person holding the data can’t see what’s inside it. This removes the “confidentiality trade-off” that currently forces professionals to choose between their duty to protect information and their need to be productive.
Ephemeral storage-data that disappears as soon as you close the tab, like a ghost that forgets to haunt you-should be the standard, not a premium feature.
If the “Approved” tool is a brass valve that never sees pressure, it isn’t a safety feature; it’s a $1,422 tax on honesty. We have reached a point where the most productive employees are often the ones most likely to be in violation of a corporate IT policy. They aren’t doing it to be malicious; they are doing it because they have a job to do, and the tools provided to them feel like they were designed by people who have never had to meet a deadline.
Involve Human Error
Most “human error” is just code for an employee trying to find a workaround for a broken process. When the process is the problem, the workaround is the only way to survive.
The solution isn’t more training or more “rhythmic” insolence from the compliance department; it’s a better class of tools that respect the user’s time as much as the auditor’s checklist.
“The pristine transcript is the only evidence of a meeting that happened inside a tool no one is allowed to name.”
We need to move past the era of the Questionnaire Victory. We need to stop pretending that a tool is “safe” just because a lawyer said so, and start realizing that a tool is only safe if it is good enough to be used in the light of day.
If the people on your Wednesday call are all secretly using a personal login to get their work done, your security policy isn’t a wall-it’s a suggestion. It’s a shiny brass valve on a dairy line that everyone has already bypassed.
True security is architectural. It doesn’t rely on the “discipline” of an overworked analyst who just wants to go home at . It relies on a system that makes the right way to work the easiest way to work.
When the encrypted, anonymous, and high-performing path is also the most convenient one, the “shadow” disappears because there is no longer any reason to hide. Until then, Elena will keep producing her eight pages of notes, and everyone will keep nodding, and the “Approved” assistant will continue its lonely reign over a kingdom of exactly zero users.
-
Tagged business