Superhero businesswoman surrounded by energy in an office

The Shadow Function, Part II: AI Didn’t Blur the Line, It Removed the Toll

Written by:

Learning to write a decent SQL query used to be a toll booth. It cost months of frustration, and only the people who genuinely needed the road paid it. Conversational AI with data access, and the new generation of tools that let anyone build software by describing what they want, took the toll booth down. The road is free now. Which means the toll booth was doing more work than anyone gave it credit for — it wasn’t just annoying, it was the thing quietly keeping “data professional” a legible category.

The scale of what’s now walking through is already measurable. Nokod Security’s survey of 200 enterprise CISOs, published April 2026, found that for every professional developer in the average enterprise, there are now four business users building applications — and in some organisations, ten. Security teams admit they can see only 44% of the AI tools and agents actually handling sensitive company data; 80% say they’ve lost full visibility into what business users are building. Over half of those CISOs agree the applications in question aren’t toys — they support business-critical processes. This is the population from Part I of this piece, the finance analyst and the supply chain planner, except they’re no longer building spreadsheets. They’re building software.

That would be tolerable if the accountability had scaled with the capability. It hasn’t. IBM’s 2025 Cost of a Data Breach Report found that 63% of organisations have no AI governance policy in place at all — nothing to manage AI use or stop the shadow versions of it. Among the organisations that had already suffered an AI-related security incident, 97% said they’d lacked proper AI access controls beforehand. Shadow AI usage, where it ran high, added an average of $670,000 to the cost of a breach. None of this is a story about malicious employees. It’s a story about capability outrunning the plumbing meant to contain it, by design, because the tool never asked whether anyone was ready to own what it produced.

Even the sanctioned, budgeted, board-approved version of this isn’t landing cleanly. Gartner predicted in June 2025 that more than 40% of agentic AI projects will be cancelled by the end of 2027 — not for lack of ambition, but for escalating costs, unclear business value, and inadequate risk controls once the project moved past a proof of concept. A January 2025 Gartner poll of over 3,400 attendees found only 19% had made what they’d call a significant investment in agentic AI; a third were still watching from the sidelines. Officially sponsored AI initiatives are struggling with the same question the shadow ones never got asked in the first place: who is actually responsible for what this thing does once it’s running.

I’ve watched this pattern before, just at a slower speed. Every wave of self-service tooling I’ve rolled out over the years produced the same two reactions in the same order: delight that people could finally get what they needed, then a slow-dawning discovery, months later, of exactly how many of those people had built something nobody else understood well enough to fix when it broke. AI hasn’t introduced a new failure mode. It has just made that gap between “look what I built” and “who’s on the hook for it” open up in weeks instead of years.

Which is why Part I’s test survives this intact, and arguably matters more now. The old, unreliable heuristic — can this person’s skills transfer, does their output look reusable — is now nearly useless, because AI can make almost anyone’s output look reusable on a Tuesday afternoon. What AI cannot do is make someone accountable for a system they don’t understand. It can generate the pipeline; it cannot generate the judgment to know when the pipeline is quietly wrong, or the standing to be the person the business turns to when it is. That’s still authored by understanding, not by a prompt. A data professional is the person who can be handed the failure, not just the output. Everyone else is now capable of producing the artifact. Almost no one has inherited the liability that used to come bundled with it.

Removing the toll booth didn’t create more data professionals. It just made it much harder to tell, at a glance, who was ever going to pay for what breaks.

Sources: Nokod Security, “The Invisible Enterprise AI Jungle” survey (April 2026); IBM, “Cost of a Data Breach Report 2025” (July 2025); Gartner, “Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027” (June 2025).


Suggested category: Data and Artificial Intelligence (secondary: Entropy Management)

Mode: Argument Essay — direct follow-up to “The Shadow Function.” Reuses that piece’s accountability/authorship distinction rather than restating the reusability test from scratch, so it reads best published after it (or with a one-line pointer back to it if it stands alone).

Leave a Reply

Discover more from DATA ENTROPY (Notes to fight the drift, by Sergio Rozalen)

Subscribe now to keep reading and get access to the full archive.

Continue reading