AI & Emerging Tech
Kyndryl's Jim Freeman on why shadow AI is a people problem, not a tech one

Kyndryl’s Jim Freeman explains why Shadow AI is a people and workplace challenge, urging firms to reduce friction and rethink AI governance, skills and jobs.
Artificial intelligence has moved from experimentation into everyday work at remarkable speed. Alongside that shift, a new workplace challenge has emerged: employees using AI tools their organisations may not know about, have not approved, or cannot properly govern. This is Shadow AI, and according to Jim Freeman, CTO at Kyndryl ANZ, it shouldn't be treated as employees simply bypassing the rules.
In conversation with People Matters, Freeman said, "If the path to use it, the mechanism to use it in an enterprise, is so full of friction that it's just not worth it, employees will find another route.”
In other words, Shadow AI isn't really an IT problem.
It's a design problem.
One about how organisations structure work, prepare managers, equip employees and build governance around a technology that's already in daily use.
A technology that needed no translator
Unlike previous waves of enterprise technology, generative AI didn't require employees to learn a new programming language before they could start using it.
"The programming language isn't Pascal or COBOL or Java. It's Hindi. It's Spanish. It's natural language," Freeman said.
That accessibility is precisely what allowed AI to leap from consumer devices into workplaces almost overnight. Employees simply carried over what they were already doing with AI at home, applying it to emails, research, writing and other everyday tasks.
Freeman calls this initial wave a "flash fire". The task now facing organisations is turning that early burst of enthusiasm into genuine business value, without compromising security along the way.
Larger Australian enterprises are already well into that transition, deploying AI across application development, marketing, sales and customer service.
Smaller and mid sized organisations tend to move more cautiously, often because they lack the resources to weigh up the risks and benefits at the same scale.
Why employees go looking elsewhere
Shadow AI refers to the unauthorised or unknown use of AI tools within a business. Left unchecked, it can create real risks around data exfiltration, privacy, security, bias and compliance.
But Freeman is clear that employees rarely turn to unapproved tools out of a desire to break the rules. More often, the sanctioned route is simply too hard to use.
"The real challenge that we have is how can we remove that friction," he said.
That reframes the question entirely. Rather than asking how to stop unauthorised AI use, organisations need to understand why staff are looking outside the approved environment in the first place. Common reasons include:
- No clear, approved pathway for using AI
- Excessive or slow approval processes
- Limited access to enterprise grade AI tools
- Low awareness of safe AI practices
- A gap between what employees need to be productive and what the organisation actually provides
Freeman also pushes back on the assumption that data leakage is deliberate.
"Employees don't want to be nefarious. The number one reason for exfiltration of data is accidental leakage by employees, not intentional," he said.
That distinction matters.
A governance strategy built purely around policing staff risks missing the real problem entirely.
Governance is everyone's job, not just IT's
One of the clearest themes to come out of the conversation is that AI governance cannot sit with the technology function alone.
Freeman splits organisational responsibility across three areas:
- Technology and security. CIOs, CTOs and CISOs must ensure the AI environment is safe and that sensitive information stays protected.
- Business leaders. Line managers need to understand how AI can be woven into specific functions and workflows.
- HR and finance. HR helps managers lead staff through changing roles and skills, while finance assesses whether the promised productivity and financial returns are actually materialising.
"HR plays the role in enabling the managers to lead the organisational change that has to happen," Freeman said.
Seen this way, AI adoption is as much a workforce issue as it is a technology one.
The job might not vanish, it might just be taken apart
Perhaps the most striking idea for HR professionals is what Freeman calls "task atomisation".
Instead of asking whether an entire job could be replaced by AI, organisations can break a role down into its component tasks and assess which of those can be augmented or automated.
Freeman points to his own role as an example. Some of his work could plausibly be supported by AI, while other parts, particularly those built around conversations, relationships and human interaction, remain firmly dependent on people.
"It's not a technology problem. It's an organisation skill readiness governance," Freeman said. "That's pacing absorption."
For many employees, this could mean that parts of their existing role are automated while their contribution shifts towards higher value work.
Bring employees into the redesign, don't impose it on them
This is where HR's role becomes especially important. If AI is changing what a job actually involves, employees need to understand what's changing, why it's changing, and what skills they'll need next.
Freeman believes managers need a practical framework for having these conversations without stoking unnecessary fear. The starting point is straightforward:
- Understand what an employee actually does today
- Break that role down into its individual tasks
- Identify where AI can genuinely contribute
- Build a roadmap for how the employee's responsibilities will evolve
"You don't want to do it to them. You want to do it with them," Freeman said.
It's a subtle shift, but an important one. AI adoption isn't simply about rolling out a new tool and measuring productivity gains. It's about redesigning work, with employees included in that process rather than informed of it after the fact.
Build governance into the platform, not onto the individual
The other half of the equation is making responsible AI use genuinely easy. Freeman states organisations shouldn't place the full burden of compliance onto individual employees. Instead, safeguards should be built directly into the technology people are already using.
"Put it into the platform. Don't put the onus on the individual," he said.
That might include controls around personal information, rules about which models can be used for particular types of query, and organisational policies and ethical requirements baked into the system itself.
The aim is an environment where employees can use AI productively without wading through a maze of approvals every time they want to try something new.
Fail to do that, and organisations simply recreate the conditions that drive staff towards Shadow AI in the first place.
From discovery to governance
Rather than rushing to block every unauthorised tool in sight, Freeman suggests organisations start by understanding how employees are actually using AI. He outlines three broad stages:
- Discover. Understand which AI tools employees are using, and what for.
- Rationalise. Identify overlapping tools or agents and work out where they can be consolidated.
- Govern. Put in place the policies, controls and lifecycle processes needed to manage AI responsibly.
This approach accepts a simple reality: AI use is already widespread across the workforce, whether or not every use case has been through a formal approval process.
Elimination won't solve, restructuring could
The conversation ultimately moves beyond Shadow AI itself. For Freeman, the question is no longer whether organisations will adopt AI, that decision has effectively already been made. The bigger challenge is whether businesses can build the organisational structures needed to absorb it safely and meaningfully.
Everyone wants something slightly different from this shift. Businesses want productivity gains.
Employees want tools that genuinely make their work easier. Technology leaders want security. HR needs to prepare people for changing roles. Finance needs to see the return.
All of those interests converge on the same underlying question: how do organisations make AI easy enough to use, safe enough to trust, and meaningful enough to actually change the way work gets done?
The answer may not be to build more walls around AI. It may be to take down the unnecessary ones already in place.
As Freeman puts it, the goal isn't simply to automate work. It's to give employees "higher bandwidth" for the parts of their jobs where human judgement, relationships and conversation matter most.
Author
Loading...
Loading...





