Gradient blur
Blog
Artificial Intelligence
Data & Analytics
Managed Services
Back to overview

AI sprawl: the shadow IT of 2026

If you've watched your colleagues over the past few months, you may have already noticed it yourself: AI tools are popping up everywhere. ChatGPT on the financial analyst's laptop, a self-built agent connecting to internal systems that IT barely knows exist, and a free AI assistant processing sensitive HR data without anyone knowing where it's going.
09 - 04 - 2026

As Data & Analytics Business Lead at Xylos, I see this pattern daily in the organizations we work with.

What exactly goes wrong when AI adoption runs unchecked, and how do you build an environment that employees are happy to use but that is also safe and manageable for IT?

The pattern is recognizable by now, but it looks different than you might think.

Yes, there was a taskforce. An enthusiastic team, an Azure OpenAI instance, a chatbot that answers questions about internal documents. Three months later, maybe even a demo for management. And then?

Because meanwhile, your financial analyst has built their own GPT running on exported Excel files from last quarter. Your marketing team is working with three different AI tools, no two alike. A developer has built a vibe-coded agent connecting to a SharePoint library that hasn't been synced in six months. And your HR manager is asking sensitive personnel information from a free chatbot that no one knows where the data is going.

The pilot didn't fail. The pilot has multiplied, but unmanaged, ungoverned, on data that no one has validated.

This isn't a story about organizations falling behind on AI. This is a story about organizations that already have AI deeply embedded in their daily work, without anyone having made a decision about it. Employees didn't wait for a strategy. They simply started. And now the sprawl is a fact: dozens of local integrations, just as many points of data contamination, and zero central visibility into what's actually happening.

What's actually going wrong, and why it's escalating

The problems with uncontrolled AI adoption aren't hypothetical. They're already visible in organizations that, two years ago, thought they wanted to keep a finger on the pulse, ran some isolated pilots, but still haven't developed a clear vision. This is what happens in practice:

-

Data fragmentation

Every employee feeds their AI tool with whatever data they can find themselves: exports, screenshots, copy-pasting. The output is based on sources that may no longer be correct, aren't current, and above all aren't traceable.

-

Shadow IT at scale

Vibe-coded agents, local automations, and browser extensions get built without any involvement from IT. They work … until they don't, and no one knows why or how to fix them.

-

Compliance blind spots

Sensitive data such as customer information, personnel files, and legal documents get shared with external AI services without a data processing agreement in place, let alone a data classification policy.

-

Inconsistent output as the new norm

Two employees asking the same question to two different tools get two different answers. No one knows which one is correct. Uncertainty slowly creeps into decision-making, because what was once factual is now backed up by different tools with different outcomes.

-

Unbridgeable technical debt

Every local integration built today outside the central platform will become a legacy problem later. The organization that wants to scale up to enterprise AI in two years will end up paying twice.

The question is no longer: "When do we start with AI?" The question is: "Who's responsible for what's already running?"

The solution isn't a policy, it's a platform

The intuitive response to sprawl is regulation: drawing up an AI policy, banning unapproved tools, setting up a governance committee. That doesn't work. Employees who are used to the productivity gains of AI don't stop just because HR sends a memo.

The only effective approach is to offer a better alternative. A platform that's at least as accessible as the standalone tools people use now, but built on reliable data, within the organization's governance, and manageable by IT.

That's exactly what Xylos makes possible, with Microsoft Fabric and Copilot Studio at its core. Not as a replacement for what people already do, but as the controlled environment within which they can keep doing it.

The logic is simple: if employees are going to build agents anyway, give them Copilot Studio. If they're going to query data anyway, give them access to a Fabric dataset that's correct. You shift the sprawl into a walled garden while simultaneously gaining quality, security, and scalability.

Microsoft Fabric: reliable data as the foundation

The fundamental problem behind all this sprawl is the same: everyone works with their own version of the truth. Microsoft Fabric solves that by bringing together all data sources within your Microsoft tenant into a unified platform, with OneLake as the central data layer shared by all other services.

What that means in practice: a Copilot agent built on top of Fabric always draws from the same certified, up-to-date data source. No outdated Excel exports. No SharePoint libraries that are six months behind. One version of the truth, for everyone, at any time.

At the same time, Fabric integrates seamlessly with Microsoft Purview for data governance and compliance, so you can see exactly which data is used for what, by whom, and whether that falls within the applicable rules.

Copilot Studio: the controlled environment for what employees are already doing

Copilot Studio gives organizations the ability to build custom AI agents (or have employees build them) within the secure environment of their own Microsoft tenant. The agents connect to Fabric data, SharePoint libraries, Dynamics 365, and external systems through certified connectors.

The difference with what's happening in the wild right now is crucial: everything built in Copilot Studio is visible to IT, auditable through Purview, and falls under the identity and access management of Entra ID. An employee who wants to build an agent for their team can do so, but not outside the organization's view.

That's the shift from sprawl to controlled innovation. Not by banning things, but by offering a better alternative that people genuinely want to use.

This requires more than technology

Setting up a Fabric environment and rolling out Copilot Studio doesn't automatically solve the sprawl. What it requires is a combination that many organizations currently lack: data engineers who build and manage the Fabric architecture, AI architects who design agents that align with real business processes, and adoption coaches who help employees make the switch from their trusted standalone tool to the central platform.

Organizations with a strong M365 foundation have a head start here that they rarely use. The governance structures are in place. Identity management is set up. Users know the Microsoft environment. What's missing is the connecting layer: the expertise to enrich that existing infrastructure with data engineering and AI architecture that actually scales.

In the next article, we'll show how Power Apps serves as a concrete gateway: the technology your existing team already knows, and one that can bridge the gap to integrated AI faster than expected, AI that really lands within the organization.

Do you recognize this sprawl in your own organization? Then now is the moment to lay the architecture that turns chaos into a competitive advantage. Contact us for a no-obligation conversation about what controlled AI integration means for your Microsoft environment.

About the author

Peter Verrykt is Data & Analytics Business Lead at Xylos and guides organizations in turning data into concrete business value. He helps companies look beyond technical implementations and use data as a foundation for better decisions, greater agility, and sustainable growth.