Digital Transformation and the Rise of Shadow IT: Implicationsfor Organisational Complexity and Cyber Governance
TL;DR
An integrated conceptual framework is developed that explains how digital transformation drives Shadow IT adoption, links unauthorised technology use to organisational complexity and cyber governance risks, and identifies governance mechanisms that balance innovation, security, and compliance.
Abstract
Purpose: This study examines how digital transformation contributes to the emergence of Shadow IT and Shadow AI, synthesising evidence on the factors driving unauthorised technology adoption, its implications for organisational complexity and cyber governance, and the governance strategies proposed to address these challenges. Methodology: A systematic literature review was conducted in accordance with the PRISMA guidelines, synthesising evidence from 25 peer-reviewed studies across diverse organisational and industrial contexts. The evidence was synthesised through thematic analysis to identify recurring patterns relating to the conceptualisation of Shadow IT, adoption drivers, organisational consequences, cyber governance risks, and organisational responses. The findings were interpreted using the Technology–Organisation–Environment (TOE) framework and Diffusion of Innovation (DOI) theory. Results: The review found that digital transformation, combined with restrictive governance processes, unmet operational needs, and the widespread availability of cloud computing and generative AI, encourages the adoption of unauthorised technologies. Shadow IT increases organisational complexity by creating fragmented technology infrastructures, data silos, duplicated information, and reduced accountability. These conditions weaken cyber governance through reduced visibility, data security vulnerabilities, compliance risks, and challenges associated with autonomous AI systems. Novelty and Contribution: The study develops an integrated conceptual framework that explains how digital transformation drives Shadow IT adoption, links unauthorised technology use to organisational complexity and cyber governance risks, and identifies governance mechanisms that balance innovation, security, and compliance Social and Practical Implications: The findings support the development of governance practices that improve collaboration between business units and IT departments while strengthening cybersecurity, regulatory compliance, and responsible use of digital and AI technologies in contemporary organisations.