Case Study: Mapping Shadow AI Without Driving It Underground
A conglomerate's official AI adoption was 12%. The real number was closer to 60% — running through personal accounts. The amnesty that surfaced it changed the whole roadmap.

Every organisation has two AI adoption numbers: the official one, and the real one1. The distance between them is where your risk lives — and, less obviously, where your best working practices live too.1A composite case, anonymised and simplified from several Fellow engagements. Numbers are representative of the pattern, not one client's audited figures.
The situation
A Thai conglomerate's transformation office reported 12% AI adoption, based on licence activations. Their readiness answers told a different story: heavy weekly usage alongside almost no visibility into which tools were involved. When we ran structured conversations across three business units, actual usage — counting personal ChatGPT accounts, free-tier tools, and browser extensions — was closer to 60%◦.By the numbers12% → ~60%official adoption versus what a three-week mapping actually found
Nobody had lied. The official number counted what the organisation had bought; people were using what worked, on their own accounts, including for material work: contract summaries, customer correspondence, financial commentary.
Why people hide usage
Shadow usage is not rebellion — it is a rational response to incentives◦. The approved tools were worse than the free ones. Asking for permission took weeks. And admitting AI use invited two fears at once: being told to stop, and quietly suggesting your job could be automated. Given those incentives, hiding is what a sensible person does.DefinitionShadow AI AI use running through personal accounts and unapproved tools, invisible to the organisation that carries its risk
That framing matters, because the standard corporate response — a usage survey, a stern reminder of policy — reads as a threat and drives the practice deeper underground. You cannot audit your way to visibility here.
The amnesty
We ran the mapping as a show-and-tell, with three explicit rules announced by the business-unit heads themselves: nothing disclosed would be punished; anything disclosed that worked would get proper tooling; and the goal was to find practices worth keeping, not people to correct.
The sessions surfaced 40+ distinct workflows in three weeks. The best of them — a contract-clause summariser built by a junior legal analyst — became the template for the unit's first officially supported AI workflow◦.Figure
The most valuable workflow in the company was invisible until it was safe to show
What changed
The roadmap inverted. Instead of rolling out training for hypothetical use cases, the programme promoted proven underground workflows into supported, governed ones — tooling, data rules, and an owner per workflow. Within a quarter, the official and real adoption numbers converged, which meant risk was finally being carried where it could be seen◦.By the numbers40+real workflows surfaced by three weeks of amnesty mapping — each one a governance blind spot the day before
What to steal
- Assume the real number is a multiple of the official one. Budget your governance effort for the real one.
- Run the mapping as an amnesty, announced by line leaders — not by compliance. The messenger is the message.
- Reward disclosure visibly and fast: the first disclosed workflow that gets upgraded to proper tooling does more for visibility than any policy email.
- Promote, don't punish: the shadow practices are your adoption roadmap, pre-validated by the fact that people use them without being told.
If your readiness report flagged low tool visibility against real usage, this is the playbook — and the first mapping conversation is one we can help you run◦.RelatedWhat to do once usage is visible: closing the governance gap
ทุกองค์กรมีตัวเลขการใช้ AI สองชุดเสมอ: ตัวเลขทางการ กับตัวเลขจริง1 ช่องว่างระหว่างสองตัวเลขนั้นคือที่อยู่ของความเสี่ยง — และที่หลายคนไม่ทันสังเกต มันคือที่อยู่ของแนวปฏิบัติที่ดีที่สุดของคุณด้วย1กรณีศึกษานี้เป็นการประกอบขึ้นจากหลายงานที่ Fellow ทำจริง ปรับข้อมูลให้ไม่ระบุตัวตน ตัวเลขสะท้อนรูปแบบที่พบซ้ำ ๆ ไม่ใช่ผลตรวจสอบของลูกค้ารายเดียว
สถานการณ์
สำนักงาน transformation ของเครือองค์กรไทยแห่งหนึ่งรายงานการใช้ AI ที่ 12% โดยนับจากการเปิดใช้งานลิขสิทธิ์ แต่คำตอบในแบบประเมินความพร้อมเล่าคนละเรื่อง: การใช้งานรายสัปดาห์หนาแน่น คู่กับการมองไม่เห็นว่าใช้ผ่านเครื่องมืออะไรบ้าง เมื่อเราพูดคุยเชิงโครงสร้างกับสามหน่วยธุรกิจ การใช้งานจริง — นับบัญชี ChatGPT ส่วนตัว เครื่องมือฟรี และส่วนขยายเบราว์เซอร์ — อยู่ที่ราว 60%◦ตัวเลข12% → ~60%ตัวเลขทางการ เทียบกับสิ่งที่การสำรวจสามสัปดาห์พบจริง
ไม่มีใครโกหก ตัวเลขทางการนับสิ่งที่องค์กรซื้อ ส่วนพนักงานใช้สิ่งที่ได้ผล บนบัญชีของตัวเอง รวมถึงงานสำคัญอย่างสรุปสัญญา จดหมายลูกค้า และบทวิเคราะห์ทางการเงิน
ทำไมคนถึงซ่อนการใช้งาน
Shadow usage ไม่ใช่การกบฏ แต่เป็นการตอบสนองอย่างมีเหตุผลต่อแรงจูงใจที่องค์กรสร้างขึ้นเอง◦ เครื่องมือที่อนุมัติด้อยกว่าของฟรี การขออนุญาตใช้เวลาเป็นสัปดาห์ และการยอมรับว่าใช้ AI เปิดความกลัวสองอย่างพร้อมกัน: ถูกสั่งห้าม และการส่งสัญญาณกลาย ๆ ว่างานของตัวเองอาจถูกแทนที่ ภายใต้แรงจูงใจแบบนี้ การซ่อนคือสิ่งที่คนมีเหตุผลทำนิยามShadow AI การใช้ AI ผ่านบัญชีส่วนตัวและเครื่องมือที่ไม่ได้รับอนุมัติ ซึ่งองค์กรมองไม่เห็นแต่ต้องแบกรับความเสี่ยง
กรอบคิดนี้สำคัญ เพราะปฏิกิริยาองค์กรแบบมาตรฐาน — ส่งแบบสอบถาม หรือเตือนนโยบายด้วยน้ำเสียงเข้ม — จะถูกอ่านเป็นคำขู่ และผลักการใช้งานลงใต้ดินลึกกว่าเดิม คุณไม่สามารถ audit เพื่อให้ได้มาซึ่งความโปร่งใส
การเปิดเผยแบบไม่เอาผิด (Amnesty)
เราจัดการสำรวจในรูปแบบ show-and-tell พร้อมกติกาสามข้อที่ประกาศโดยหัวหน้าหน่วยธุรกิจเอง: สิ่งที่เปิดเผยจะไม่ถูกลงโทษ สิ่งที่เปิดเผยแล้วใช้ได้ผลจะได้เครื่องมือที่ถูกต้องรองรับ และเป้าหมายคือหาแนวปฏิบัติที่ควรเก็บไว้ ไม่ใช่หาคนผิด
สามสัปดาห์ของ session เหล่านี้เผยเวิร์กโฟลว์จริงกว่า 40 รายการ ที่ดีที่สุด — ตัวสรุปเงื่อนไขสัญญาที่นักวิเคราะห์กฎหมายรุ่นน้องสร้างเอง — กลายเป็นต้นแบบของเวิร์กโฟลว์ AI ตัวแรกที่องค์กรรองรับอย่างเป็นทางการ◦ภาพประกอบ
เวิร์กโฟลว์ที่มีค่าที่สุดในบริษัท มองไม่เห็นจนกว่าจะปลอดภัยพอที่จะโชว์
สิ่งที่เปลี่ยนไป
โรดแมปกลับหัวกลับหาง จากเดิมที่จะอบรมเพื่อ use case สมมติ โปรแกรมเปลี่ยนมายกระดับเวิร์กโฟลว์ใต้ดินที่พิสูจน์แล้วว่าใช้ได้ผล ให้กลายเป็นเวิร์กโฟลว์ที่องค์กรสนับสนุน พร้อมเครื่องมือ กฎข้อมูล และเจ้าของต่อเวิร์กโฟลว์ ภายในหนึ่งไตรมาส ตัวเลขทางการกับตัวเลขจริงเข้าใกล้กัน ซึ่งแปลว่าความเสี่ยงถูกนำมาอยู่ในที่ที่มองเห็นได้เสียที◦ตัวเลข40+เวิร์กโฟลว์จริงที่โผล่จากการสำรวจสามสัปดาห์ — แต่ละตัวคือจุดบอดการกำกับดูแลเมื่อวานนี้
สิ่งที่นำไปใช้ได้เลย
- สมมติไว้ก่อนว่าตัวเลขจริงเป็นหลายเท่าของตัวเลขทางการ แล้ววางแผนการกำกับดูแลบนตัวเลขจริง
- ทำ mapping แบบ amnesty โดยให้ผู้นำสายงานเป็นคนประกาศ ไม่ใช่ฝ่าย compliance — ผู้ส่งสารคือตัวสารเอง
- ให้รางวัลการเปิดเผยอย่างเห็นได้และรวดเร็ว: เวิร์กโฟลว์แรกที่ถูกอัปเกรดเป็นเครื่องมือจริง มีพลังกว่าอีเมลนโยบายทุกฉบับ
- เลื่อนขั้น ไม่ใช่ลงโทษ: แนวปฏิบัติใต้ดินคือโรดแมปการนำไปใช้ของคุณ ที่ผ่านการพิสูจน์มาแล้วโดยที่ไม่มีใครสั่ง
ถ้ารายงานความพร้อมของคุณชี้ว่าการใช้งานจริงสูงแต่ความโปร่งใสของเครื่องมือต่ำ นี่คือ playbook — และการพูดคุย mapping ครั้งแรกคือสิ่งที่เราช่วยคุณเริ่มได้◦บทความที่เกี่ยวข้องเมื่อมองเห็นการใช้งานแล้ว ต้องปิดช่องว่างการกำกับดูแลอย่างไร
Keep reading

Case Study: Turning Individual AI Wins Into Shared Capability
A capable, well-trained team where nothing compounded: every AI win stayed private. Five harvested workflows and one co-built assistant later, the median user caught up with the best.

Case Study: Putting a Defensible Number on AI Adoption
An AI programme everyone liked nearly lost its budget because nobody could prove it worked. Two baselined workflows later, it survived the cut — and earned an expansion.