You Can’t Monitor Your Way Out of an Incentive Problem
Why monitoring and office mandates miss the shadow AI that matters.
Part two of three
Last week we described a researcher who keeps her real thinking in a personal ChatGPT account, because handing it over makes her easier to replace.
The standard response is to make that harder to do. Log the usage, flag the anomalies, get her back where the screens are visible. Lock down her laptop, though, and she’s on her own account at lunch. All you’ve bought is friction on the work you’re paying her for, and less sight of the thing you wanted to see.
That’s what happens when you treat an incentive problem as a security problem. Some shadow AI is a workaround for broken systems, and most people would hand that over tomorrow if it were safe to do so. Some is judgement capital, the instinct and reasoning someone was hired for, and nobody gives that away for nothing.
Why monitoring and office mandates fail
Firms mostly reach for two fixes. The first is tighter monitoring, the way you’d track a leak. It catches usage on the tools you can see, which leaves out the second tab on a personal phone and the years-old habit that never touched a company laptop to begin with.
The second is getting people back in the office, usually framed as culture and cohesion, but also a way for firms to keep more screens and devices in view during the day. And it does work for some roles, trading floors and call centres and anything else bounded and process-driven enough that the output is the job, and the output can be watched.
It falls apart in roles where the value lies in judgement rather than throughput, regardless of seniority. You can watch her desk without seeing the account she thinks in.
Both fixes make the behaviour harder without changing the calculation behind it. You can’t monitor your way out of that. You have to change the incentive.
The mechanism
Those two kinds of shadow AI need different responses.
For the workarounds caused by broken systems, the answer is fairly simple: make it safe to admit the workaround, then fix the system. Done right, that admission hands the firm free diagnostics. Nobody’s confessing to anything. But people will only speak up if they trust it won’t be held against them later, and if coming clean sounds like owning up to two years of doing it wrong, they’ll say nothing.
Judgement capital is harder because the person has something to lose. It’s the specialist’s read on the work: an analyst catching bad numbers before the model does, an ops lead sensing a delivery’s about to slip before the status report shows it. It only moves if something is traded for it. Asking alone won’t get it.
Someone might agree to spell out one particular judgement and let the firm test it against what happens next, without handing over the account it came from or the wider body of experience behind it.
None of the current tools make that easy to do cleanly yet. That’s a separate problem from whether it’s worth doing.
Verification is where it gets hard. Checking whether someone’s usage history looks sophisticated is gameable, and people already know how to perform expertise for an audience. Give the check a specific signal to aim for and what you get back is chat histories engineered to pass it, which tells you nothing honest about how someone actually thinks.
Payment has the same problem. Pay for a claim with no verification and you’re rewarding whoever bluffs best. Pay once for something that keeps making the person easier to replace and the exchange only runs one way. If the firm keeps benefiting, the payment has to keep running too. That makes it closer to a royalty than a signing bonus. It still needs checking, just later, against what happens next: did the disclosed judgement help teams spot a slipping delivery earlier, or did the same failure keep recurring?
None of it works out of sequence. The workarounds have to come first. They give the firm a lower-stakes way to prove disclosure is safe, and without that, nobody hands over judgement capital.
The payoff for the firm
A firm does this for what it gets back: three things across both kinds of disclosure.
Fixed plumbing comes first, close to guaranteed: broken handoffs between systems, manual patches nobody had previously admitted to. Hiring gets better too, since right now firms are mostly guessing at fit from weak stand-ins, a CV, a few hours of interview performance, a plausible answer to a hypothetical question.
A disclosed, verified pattern of how someone handles ambiguity beats all of those, especially once it’s tested against real outcomes rather than a polished interview answer. It only works, though, if it’s handed over voluntarily, on the same terms as any judgement capital exchange.
It doesn’t prove expertise on its own, but it’s a better starting point for figuring out whether someone’s instincts fill a gap the firm has. The aim should be to widen the pool of instincts a firm hires against. The risk with hiring on patterns of thought is that it pulls toward people who already think like the existing best performers.
Then there’s the payoff most firms aren’t set up to see at all.
Say the disclosed judgement capital across best performers clusters around one type of problem, while another repeatedly catches the firm out. That suggests a gap in the firm’s collective thinking, visible before it costs a pitch or a client. Most firms only find this out after the fact: a stalled expansion, a lost account, a post-mortem nobody wants to own.
Fixed plumbing is what a firm gets in the first year. The rest is why it’s worth building properly.
Part three traces that blind-spot payoff through a specific failure, and what it shows.