I've been reading a new report from LexisNexis, published in June, about how people in PR, media and communication are using generative AI.
There are plenty of numbers in it worth paying attention to. One finding in particular stood out for me – a lot of people are using AI at work without approval.
That's hardly news in itself. We've been talking about "shadow AI" for some time – employees using ChatGPT and other AI tools for work without their organisation necessarily knowing about or approving them.
I wrote about this in July 2024, describing the rise of shadow AI as a double-edged sword for corporate innovation. My argument then was that organisations couldn't simply clamp down on unauthorised AI use. Employees were discovering useful tools and experimenting with them, while employers were understandably concerned about security, privacy, intellectual property and other risks. The challenge was to guide that experimentation rather than stifle it.
Shel Holtz and I returned to the issue in April this year in For Immediate Release #510, Should Companies Embrace Shadow AI? There, we looked at an organisation taking a different approach from the usual policy reminders and crackdowns, and considered what communicators could learn from it.
We returned to shadow AI again in the June long-form episode, FIR #520, AI's PR Meltdown, as evidence continued to emerge of its growing use inside organisations.
Two years after that first post, the new LexisNexis research makes me think we need to take the argument a step further.
The issue isn't only how organisations manage the risks created by shadow AI. It's what the existence of shadow AI is telling them.
People know there's a risk
LexisNexis finds that communication professionals are less confident about using generative AI than the cross-industry average, while their concern about misinformation is considerably higher.

The report describes PR, media and communication as having the lowest technical confidence, the weakest foundational understanding and the highest misinformation anxiety of the industries it studied.
If you work in communication, an AI error doesn't necessarily stay inside the organisation. It can appear in a news release, a report, a social post or something supplied to a journalist. It can be published, shared and attributed to you.
Credibility is part of the job. Yet large numbers of these same professionals are using AI without approval.
And here's a finding that really interests me: among unauthorised users, 62% say they're doing it because deadlines won't wait.
What is shadow AI telling us?
When I wrote about shadow AI in 2024, I saw the central tension as innovation versus control.
Employees wanted to experiment. Organisations needed to manage the risks. The goal was to find a way to accommodate both.
I still think that's true. But the LexisNexis findings point to something else.
Widespread shadow AI isn't simply evidence that employees aren't following the rules. It's evidence of a gap between the way people are expected to work and the governance their organisations have put around that work.
Think about the communication professional facing a deadline. They know an AI tool can help them research something faster, analyse a pile of information or get a first draft moving. They also know the technology can hallucinate and get things wrong.
Their organisation hasn't provided an approved tool. Or the policy is unclear. Or getting permission takes longer than the deadline allows. The deadline hasn't changed, so they use the tool.
That doesn't make the unauthorised use of AI acceptable. There are good reasons for controls around confidential information, data protection, accuracy, intellectual property and security.
But another reminder to "follow the AI policy" doesn't address why people are working around it. That's why I see shadow AI increasingly as a leadership signal, not simply an employee compliance problem.
Training isn't competence
There's another tension in the LexisNexis findings.
Across its wider research, 82% of professionals now receive some form of AI training. Yet 28% say their organisation has no AI policy, and the report identifies significant gaps between what it calls confidence, competence and control.
Training clearly matters. But what are we training people to do? Learning how to prompt an AI tool, generate a draft or summarise a document is useful. It isn't the same as learning how to question an output, verify its sources, recognise uncertainty or know when AI shouldn't be used at all.
For communicators, these are becoming core professional skills.
I'd add a fourth to LexisNexis' three: accountability. Who is accountable when AI contributes to something that goes wrong?
"Human in the loop" has become a comforting phrase in discussions about responsible AI. But it means little if that human doesn't know what they're responsible for, lacks the competence to exercise meaningful judgement or doesn't have the authority to challenge the machine.
Communication belongs in this conversation
This is also where I think communicators have a role beyond managing AI in their own function.
Effective AI governance depends on people understanding what's expected of them, why guardrails exist, where responsibility lies and what to do when a policy doesn't provide an obvious answer.
That puts communication right in the middle of the issue.
It also strengthens the case for communication leaders being involved when organisations shape their approach to AI – not simply when a finished AI policy needs communicating.
Silvia Cambié and I have discussed this in the IABC AI Leadership & Communication SIG and in our private LinkedIn group on AI leadership. The technology matters, of course. But many of the hardest questions around organisational AI adoption concern trust, behaviour, transparency, responsibility and judgement.
They're leadership questions. And they're communication questions.
From capability to credibility
LexisNexis describes the change taking place as a shift from AI capability to AI credibility.
I think that's exactly where we are. The first phase of generative AI at work was dominated by a question: What can this thing do? We're now confronting harder ones.
Can I trust what it gives me? How do I know? Should I use it for this? What am I responsible for? What happens when it gets something wrong?
Look at the work. Look at the pressures. Look at the tools people have been given and the decisions they're being asked to make.
Shadow AI isn't just telling you that people are ignoring your governance. It's telling you something about the governance itself.
Reference:
- AI in PR & Communications: 2026 Industry Report on GenAI, Risk & Governance (LexisNexis, June 2026)
AI-generated "desire path" image at top created by ChatGPT.