Arti Raman is the founder and CEO of Portal26. She is an expert on managing and mitigating risk for enterprise GenAI and data.getty​Would it surprise you to learn that the average enterprise is already running something like 14 different AI tools? Would it also be surprising to discover that IT teams are typically unaware of most of them?​That’s a significant observability gap, with potentially serious governance and security implications. Many organizations currently operate on the basis that AI, like many other software tools, will be centrally managed. To an extent, that’s true; if a business uses Microsoft Copilot, ChatGPT Enterprise, Claude Enterprise or another mainstream AI service, it will be a formal, controlled arrangement.​What this fails to account for is how much AI is already embedded across SaaS platforms, productivity tools and business applications that organizations rely on every day. These systems are operationally important, yet the teams responsible for data protection and compliance often have no visibility into how AI is being used, let alone how to monitor or control it. On top of that, employees will inevitably bring their own preferred tools and use them too. When AI adoption accelerates faster than governance, risk becomes both decentralized and invisible.​That’s a bit like how we may assume that we know about every streaming service our family subscribes to, only to discover there are quite a few more quietly being paid for through app stores or that started as free trials. For businesses, of course, the stakes are much higher.​Lurking In The Shadows​"Shadow IT" has been a serious management and security headache for years, with businesses everywhere still trying to regain control over what technology is adopted and by whom. However, AI has fundamentally changed both the scale of the problem and the speed at which it develops. Sounds familiar, doesn’t it?​AI is quietly becoming part of almost every software platform we use, with trusted applications continuously introducing new capabilities through routine updates. As an employee, I can hardly be called out for using them; it’s not as if I’ve bought and downloaded an entirely new tool from an unknown startup. But that happens all the time too.​So where does that leave those who carry the can for security and governance? Like so many other areas of contemporary technology implementation, traditional software asset management and procurement processes have been disrupted by AI.​Without visibility, organizations can’t hope to understand the true scale of AI adoption, whether there might be duplicate spending, whether licenses are being properly utilized and, increasingly, whether AI investments are actually delivering the business value leaders are betting the farm on.​You Can’t Manage What You Can’t Measure​In any other area of business, this would be wholly unacceptable. Yes, many organizations spend inefficiently, but few would accept operating with so little visibility into where their investments are actually going.​This is not to say that all leaders are oblivious to the problem. There are many organizations that have very tight restrictions or even outright bans on AI. But there’s a strong argument that this approach doesn’t work either, as it encourages employees to find work-arounds, which further reduces visibility.​This is a telemetry issue, which means we must be able to capture real-world AI activity as it happens. Organizations need to understand which AI services are being used and who is using them. Then they can work out whether each tool and the data being shared with it aligns with policy.​This should apply to everything AI touches, whether organizations know it's there or not. In this context, governance is evidence-led, even as AI usage inevitably (and sometimes extremely rapidly) changes over time. Indeed, governance should not be a stumbling block at all; business leaders should have the oversight and authority to apply good governance to AI the same way they do for just about every other enterprise technology investment.​According to findings from Gartner, "69% of organizations suspect or have evidence that employees are using prohibited public GenAI," and "by 2030 more than 40% of enterprises may experience security or compliance incidents linked to unauthorized shadow AI.​"The path forward requires CIOs to establish organization-wide AI usage policies, build routine auditing practices around shadow AI and weave GenAI risk assessment into how they evaluate SaaS tools. All of this, however, depends on getting a handle on observability first.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?