A threefold rise in a single year is fast enough that any policy written before it is describing a different organization.

The number is best read as a measurement of governance lag rather than of employee behavior. Shadow AI is defined against what the employer has sanctioned, so the figure rises both when staff adopt something new and when the organization has simply not gotten around to classifying a tool that is already in use. Both are governance gaps and both are closed the same way, which is by producing an inventory.

That is why every AI governance framework, from NIST AI RMF to ISO 42001 to the EU AI Act, starts in the same place. Each assumes you can enumerate the AI systems in use and say what each one does with what data. An organization that writes an acceptable-use policy before it can produce that list has governed a population it cannot see.