There's a name for this now: Shadow AI. And I think it's the most honest problem in project management today.
Alex Rodov · PMO Leadership, PMP, Microsoft MVP Alumni
Ask most PMO leaders whether their team uses AI, and you'll get a fairly confident answer.
Usually, you'll hear the name of an approved tool. Maybe there's a rollout plan. A training schedule. A policy.
Then ask a more specific question:
Where exactly is AI being used? On which decisions? And using whose data?
The confidence tends to fade.
That gap has a name now: Shadow AI.
In a recent conversation on the Online PM Courses platform, project management commentators Yoshi Soornack and James Garner used the term to describe AI tools employees are already using informally, outside the tools a PMO has approved or even knows about, to help make decisions on real projects.
I don't think this is a scandal.
I think it's what happens when a technology becomes useful faster than an organization can build a policy around it.
This Isn't a Compliance Footnote
A project coordinator pastes budget numbers into a chatbot to get a second opinion on a forecast.
A scheduler asks an AI tool to sanity-check a resourcing plan.
A project manager uses an AI assistant to summarize risks before a stakeholder meeting.
Nobody is necessarily trying to break a rule.
They're trying to do their job a little faster with a tool that happens to be extremely good at sounding confident.
And that confidence is exactly the part that worries me.
AI is very good at producing an answer that reads as authoritative whether or not it actually is.
Soornack and Garner, in that same conversation, called this the "illusion of intelligence."
I think that phrase is doing real work.
The danger isn't simply that AI gives wrong answers.
It's that wrong answers and right answers arrive dressed identically.
The risk was never that AI would refuse to answer a question it shouldn't. It's that it always answers, with the same calm certainty either way.
What Is Shadow AI in Project Management?
Shadow AI is not necessarily a collection of rogue employees doing something malicious.
It can be much more ordinary.
It can look like:
- Using a public AI chatbot to analyze project data
- Generating a risk summary outside approved systems
- Asking AI to review a project forecast
- Using AI to create stakeholder communications
- Summarizing confidential project information
- Getting AI-generated recommendations about resources or schedules
The important question isn't simply whether AI is being used.
It's what the AI is being used to influence.
That's where project management governance becomes critical.
What I Think This Actually Calls For
Not a ban.
I don't think that works, and I don't think it's the right instinct anyway.
The people reaching for these tools are usually just trying to do good work faster.
What it calls for is bringing the behavior into the light instead of pretending it isn't happening.
Salman Amir, a commenter writing from the PCI AI perspective on a project management blog, put it better than I could when this topic came up recently:
AI capability in project management should be assessed at the decision level, not merely by whether someone can operate a tool.
I think that reframing is the whole answer in one sentence.
Don't just ask whether someone is allowed to use a chatbot.
Ask what decision it's touching.
Is it influencing:
- A budget line?
- A contractual date?
- A risk rating?
- A resource allocation?
- A project forecast?
- A baseline?
- A contractual commitment?
Then match your scrutiny to the stakes.
AI Governance Should Follow the Decision
This is where AI governance becomes practical.
Not every AI-assisted task carries the same level of risk.
Using AI to brainstorm a meeting agenda isn't the same as using AI to recommend whether a project should be re-baselined.
Summarizing publicly available information isn't the same as uploading confidential financial data.
Generating a first draft isn't the same as approving a contractual commitment.
The governance model should reflect that difference.
Amir's own list is worth highlighting:
- Source-data controls
- Documented human review
- Accountability for approved outputs
- A clear escalation path when generated analysis conflicts with the baseline
The PMO can establish those governance standards.
But a qualified professional still has to remain accountable for any decision touching forecasts, resources, cost, or contractual commitments.
The model doesn't get to hold that responsibility, no matter how confident it sounds.
The Numbers Say the Stakes Are Real
This isn't a theoretical concern.
Gartner's Predicts 2026 report on program and portfolio management puts a hard number on the underlying problem: only 14% of IT leaders are confident their data is properly governed for AI.
For the other 86%, any AI-assisted decision, "shadow or sanctioned," is being built on a foundation they don't believe has been properly verified.
And the upside is just as real.
That's exactly why I don't think the answer is to pull back.
PMI's Pulse of the Profession data shows organizations using AI deliver 61% of projects on time, compared with 47% for those that don't, and hit their ROI targets 64% of the time versus 52% for non-adopters.
The gap runs in both directions at once:
More capability. More exposure. From the same tools.
The Real Problem Isn't AI Adoption
This is the part I think PMO leaders should pay closest attention to.
The question shouldn't be:
"How do we stop people from using AI?"
It should be:
"How do we make AI-assisted decisions visible, explainable, and accountable?"
That's a very different problem.
And it's a much more useful one.
Because Shadow AI is often a symptom of something else.
People are looking for faster ways to analyze information, communicate, identify risks, and make decisions.
If the official systems are too slow, too restrictive, or disconnected from the way people actually work, employees will naturally find alternatives.
The answer isn't necessarily tighter restrictions.
Sometimes it's building a better path.
Where I Land on This
The PMO's job isn't to have the fastest AI adoption.
It's to make sure the organization can stand behind the decisions being made in its name.
Shadow AI isn't a reason to slow down.
It's a reason to finally say out loud what was always true:
A decision made with AI still needs someone qualified to own it.
I'd rather have that conversation now, while it's still a policy discussion, than later, when it's an incident report.
Bring it into the open. Match the scrutiny to the stakes. Someone still has to own the decision.
Alex Rodov

Top comments (0)