Endeavors AI Podcast

Shadow AI: The Risk Hiding Inside Your Company

Compliance attorney Michael Volkov on AI governance, hidden risk, and deploying AI the right way.

Guest: Michael Volkov — compliance attorney and AI-governance expert, founder of Volkov Law. He advises Fortune 500 compliance teams, major law firms, and Berkshire Hathaway subsidiaries, and publishes the long-running "Corruption, Crime and Compliance" blog and podcast (plus Volkov Law TV on YouTube).

Watch on YouTube

Episode summary

Michael Volkov sits across the table from Fortune 500 compliance teams and finds that the people running governance committees often have no idea what's actually happening three floors down. In this episode he unpacks "shadow AI" — unsanctioned use that creates real liability — why the business is racing ahead of compliance, where the genuine risks live (algorithmic decisions, hallucinations, third-party vendors), and how to put lightweight, human-in-the-loop controls in place without standing in the way of innovation.

Key takeaways

  • The pattern Volkov keeps seeing: the business wants AI and doesn't care about the risks, while compliance runs behind like "the boy who cried wolf" — and the two sides aren't talking to each other.
  • "Shadow AI": employees using tools like ChatGPT or Claude at work without integrating them into the company's control structure — he found a Fortune 100 finance team using AI for transaction monitoring while the official line was "we haven't deployed any."
  • The real risk tiers: algorithmic decisions (hiring, credit) are high-risk and demand heavy controls against discrimination; incidental internal uses (marketing, etc.) are lower-risk but must be distinguished from customer-/market-facing uses.
  • AI's most dangerous trait is that it makes mistakes authoritatively — it hallucinates confidently, which is why a human quality-control check is essential, and companies will be liable for mistakes they rely on.
  • Third-party/vendor exposure: ask AI vendors how they use AI and what decisions it drives, then mitigate with contractual reps & warranties, an AI use policy they must sign, and audit rights — and document everything.
  • Most companies still lack an AI acceptable-use policy; the fear is that a policy will "cabin" benefits, but a good compliance function exists to let the business succeed, with controls behind it.
  • Humans are indispensable: AI properly deployed makes people (including HR) more effective, not obsolete — "you won't be replaced by AI, you'll be replaced by people who know how to use it well."
  • Enforcement is coming: the EU AI Act applies to foreign companies operating in Europe, big media-vs-AI lawsuits are underway, and litigation risk argues for cyber/AI insurance.
  • For small and midsize businesses: don't "boil the ocean" — a basic acceptable-use policy, awareness, light training, and a CEO statement are enough. Use smart sampling to spot-check AI outputs and minimize the verification burden.
  • The opportunity he's most excited about: education on effective prompting across an organization — garbage in, garbage out.

Full transcript

Collin McKee

Every company thinks they've got a handle on AI, and most don't. Today's guest has sat across the table from Fortune 500 compliance teams, major law firms, and Berkshire Hathaway subsidiaries — and what he finds is that the people running governance and compliance committees have no idea what's actually happening three floors down. Michael Volkov is a compliance attorney, an AI-governance expert, and someone genuinely concerned about what happens when this technology runs without guardrails. I'm Collin McKee, and this is the Endeavors AI Podcast. Michael, welcome.

Michael Volkov

Hey Collin — thank you so much. That's an intro like an Alfred Hitchcock movie, meant to scare. But people who know my work in compliance and ethics and governance know I'm trying to raise awareness and bring practical solutions to problems. Let me take a step back, because I'm seeing more and more of something concerning. Right now the business wants AI and they don't care — they just want it. A company I know: the CEO sent a message to every department head saying, "Tell me how you're going to use AI and how many people you can reduce your workforce by." Talk about a stupid way to approach AI. The business is demanding this and being hellbent about it, and nobody is saying, "Wait — what are the risks? How are we going to deploy this? What's the use case? What controls are in place to prevent a series of catastrophes that could happen?" Responsible risk management requires some consideration and analysis. You're the type of people companies need to bring on board to have the rational discussion and deploy this technology the right way. What I'm not seeing is the two parts of the company talking to each other — compliance is running behind like the boy who cried wolf, and the business just doesn't care. You're on the front line too — what attitude are you seeing? Am I exaggerating, or is this really something to be concerned about?

Collin McKee

We're in different pools — you're in a larger one. The people I speak with are smaller and more nimble, and for the most part they're being cautious. But I've heard many stories like yours: "just get it out there, don't be left behind, we need it now and who knows what it'll do." But you told me one story in our first conversation that hits hard — you were doing a risk assessment for a major company with all the governance boxes checked, and then you talked to the finance team.

Michael Volkov

Right. I'm doing an ethics-and-compliance risk assessment, and one of the questions is, "Are you using AI?" And the answer is, "No — we have an AI governance committee, all uses go through there, we haven't deployed any." Then I go talk to the finance team — this is a Fortune 100 company traded on the New York Stock Exchange — and they say, "Yeah, we're using AI for transaction monitoring." Do I think that's a high-risk use? No. But it underscores the problem I call shadow use: people using AI that the company doesn't know about. Depending on how they use it, they can create serious liabilities. We all have access to ChatGPT or Claude, and there are people using it at work without integrating it into their control structure. This is an example of the business getting far out in front of ethics and compliance, with no AI governance. So let's talk about shadow use, and then about what we actually mean by "AI governance." Shadow use is occurring — I gave you that example of a major company. That's not a high-risk situation, but it could be. And where are the risks? Let me not exaggerate them. The real risk is where you're engaged in algorithmic functions — making decisions based on AI: hiring decisions, credit decisions. That's a narrow but high-risk band, and I see high risk in HR functions. Then there's the incidental — using it internally for things like marketing — but those have to be distinguished from customer-facing, market-facing uses. With algorithmic, you need governance and controls "out the wazoo" to make sure AI isn't discriminating on a prohibited characteristic in important decisions. You cannot have AI making your HR decisions or quality cuts. What's really troublesome is that AI makes mistakes — and it makes them authoritatively. It hallucinates: it calls out cases that are made up. If it's doing that in the legal field, where is it hallucinating in your business? That begs for a control — a human set of eyes to double-check. That's a huge risk right now, and it's making more mistakes than we know. Companies will be held liable if they rely on those mistakes and provide services and products based on them.

Collin McKee

Take the HR side. If you hire a vendor with a tool that sifts through applicants and there's a bias, you can be on the hook — you could get sued, even though you didn't know. So what do they need to ask the vendor before they sign? What's the due-diligence checklist?

Michael Volkov

Great question — you've highlighted yet another risk: your third parties. People are hiring AI vendors. The questions you have to answer from the third party: How are you using AI? What functions? What exactly are they doing? Based on those answers, my job is to mitigate the risks — I put in contractual provisions requiring representations and warranties of compliance. If I have a use policy, which I should, I give it to them and require them to comply and sign on. I also need audit rights to look at how they're using AI, what decisions they're making, and what controls ensure accuracy. Nobody is putting in contractual provisions right now. I hate to say it, but there's one real use for lawyers — in these technical areas we can protect you with provisions in your contract and by documenting the due-diligence questions and answers. Keep a file of everything, because when the government or litigation comes in and you say "well, they told me this," nobody will believe you unless it's documented.

Collin McKee

A hundred percent. And a lot of people don't even have AI acceptable-use policies yet — it's brand new.

Michael Volkov

Companies know how to write policies; we've done it for years. So what's the hesitation? What's hard to overcome?

Collin McKee

I think they don't want to limit themselves. There are more unknowns than knowns in AI right now, and they don't want to pigeonhole themselves or break their own policies. They want to play with the fancy new toy and not do the homework.

Michael Volkov

I think it's also that they fear it'll restrict potential benefits. I'm not so sure it does, because my job as a compliance person is to make sure the business can function and succeed, and then I'm behind them with controls to protect them and the company. I'm not trying to shut your business down — you tell me you want to do something with AI, and I say, "Okay, here's what we need to do to get it done." The third-party situation is a classic. And there's real fear in HR functions right now about being replaced as obsolete. I don't think that's true. We need your judgment and expertise. I'm not ready to hand my HR function over to Claude. Claude's a nice guy, but he won't do what Collin can do. If AI is properly deployed, you'll be a more effective, more efficient HR officer. The most beneficial thing I've seen so far is distilling lots of information — that's fantastic, and I use it for that — but it will not make legal judgments for me, because my schooling and experience are more valuable than anything in a language model based on a snapshot of the internet. On the other hand, I'm seeing incredible positive uses: in that financial case, AI is fantastic at sifting through transactions and identifying patterns and red flags; auditing international trade, imports and exports, on a monthly basis is fantastic. But I double-check it — I do sampling to confirm it's doing it right.

Collin McKee

One challenge to getting people to double-check is that in their mind they're unraveling the time they just got back. How do you un-teach that?

Michael Volkov

Good question — we're also used to putting a search into Google and living with the algorithmic results without checking. Here, because it's so efficient and powerful, every case cite it gives me, I go read the case. I should be doing that anyway, but I have to, because ethical lawyers are being prosecuted by ethics committees for submitting briefs with AI-generated hallucinated cites. It does require coming back and looking. When I say "sample," I mean build a sampling technique that's minimally burdensome: if I have 10,000 transactions, I take a small percentage and look at those. Don't boil the ocean — do smart sampling, minimize your burden, and move on. And document every step. The bigger enforcement picture: in the U.S. we don't have much government enforcement yet, but in the EU there's an AI law effective for foreign-enforcement purposes that companies operating in Europe must get ready for. If Congress ever gets its act together with an AI bill, we'll have issues here too. There are big lawsuits going on, and litigation risk from a customer or vendor who gets burned could be significant — companies need cyber and AI insurance. It'll be costly, but the lawsuits will be more costly.

Collin McKee

Making an example of the first ones to do it wrong.

Michael Volkov

And Collin — if you're seeing in small businesses that they won't slow down to get insurance because they're running and gunning, they've got to be mindful of this. I don't want to see a "boil the ocean" compliance policy in a small startup or mid-sized company. I want to see the basics: an acceptable-use policy that people are aware of, some training, and maybe a statement from the CEO — "we love this, but we've got to be careful how we do it." Small and mid-sized businesses can't slow themselves down — it might be a matter of survival — but they need the controls in place. That's where your operation can protect people from those risks.

Collin McKee

And they're doing it in small ways. I don't see heavy engagement on a full AI use policy yet — hopefully soon — but little things like "company-wide, you can't use your own personal free version, you've got to use the company's version," especially in law.

Michael Volkov

Exactly. And I'm sure there are people sitting at their desk using their phone to check something, and then it gets plugged into the business system — that could be a problem. But I don't want to stand in the way of this innovation. I want to embrace it, in the smartest way possible. Nobody accomplishes anything by being a negative force in the marketplace saying "you're all going to jail." What works is saying, "Let's do it this way — it's the least burdensome and it protects you." You have to make it in their interest. I don't want to be a key witness in a case going through my emails asking "what did I know and when did I know it." Once you get the business to pay attention, they find the solutions aren't as hard as they think. Years ago, companies built elaborate anti-corruption compliance programs. We don't need that for this — we need awareness, intelligence, and sensitivity. Ultimately, humans are indispensable: the human judgment, the human eyes that say "that doesn't seem right to me." My mission is to bring the human to the AI function — just merge those two.

Collin McKee

You said something on our first call I can't agree with more: people aren't going to be replaced by AI, they're going to be replaced by people who know how to use it well. Still your view?

Michael Volkov

Absolutely. There's a level of near-hysteria that's taken over the dialogue. When the internet first started, everybody worried about losing their job to it. I don't see that with AI. HR is indispensable; their discretion and expertise are indispensable. I think it'll make all of us more effective. Anecdotally, people say, "I have more time, and all I do is use it to do more work, and they expect more from me." But used properly, you'll become more efficient and a better performer, and you'll be compensated for it. The stupidity of that CEO's announcement is that it's the exact example of how not to deploy AI. Imagine devoting 20 years to a company and being told to "figure out a way to make yourself useless." I'm a strong advocate for technology — I've seen it revolutionize the compliance function itself. We used to deal with paper and questionnaires; now technology makes effective compliance so much easier.

Collin McKee

And "people who know how to use AI" doesn't mean who can type anything into it — it's using it properly, with guidance. Garbage in, garbage out. Your CEO story is short-sighted: keep the business flat and cut HR costs. The opposite view is, how can I make my people more productive and happier and do more? Use it as a force multiplier.

Michael Volkov

You said it perfectly — as a force multiplier. This will exponentially increase productivity. The one area with so much need is education and training: what are effective prompt strategies? Imagine how helpful that would be across an organization — to even know what to put in. Let's maximize the use of this, understand its limitations, and develop the key to get the most out of it. You're preaching to the choir, but I learn so much talking to you — your perspective is really important right now.

Collin McKee

I have conversations like this to thank for it. Michael, as we wrap up, how do people find you — podcasts, blogs, consulting?

Michael Volkov

We have a blog, Corruption, Crime and Compliance, that's been around forever; we're redoing our website. I have a podcast under the same name, and Volkov Law TV, a YouTube channel with a lot of AI topics. I run a law firm — the bulk of my work is legal work — but I love getting out there. Someone said, "Mike, you're the oldest person I know who uses social media." I'm not sure if that's a cut or a compliment. Please get in touch: volkov@volkovlaw.com, and I'm on LinkedIn. I'm here to help — I don't operate like a normal lawyer who says "my time is so valuable, you've got to pay me." I work as a partner with people, and when we get into a real project, that's when I charge. Before that, I'm here to help, because I'm on a mission — I feel passionate about ethics and compliance, and even more passionate about the benefits and productivity of AI.

Collin McKee

That's Michael Volkov — compliance attorney and the person making sure the machines don't run the show. The links will be in the show notes. If this hit home and your company needs help with implementation, automations, workflows, the AI infrastructure — that's what we do here at Endeavors AI. Reach out. Thanks for listening, and we'll see you on the next one.

Explore our services

Get Started

Ready to put AI to work in your firm?