A finance coordinator builds a pricing model in Excel, then asks an AI assistant to turn it into a small web app so the sales team can use it without opening a spreadsheet. An operations manager strings together an AI tool and a handful of scripts to track shipments that used to live in a shared workbook. A customer service lead automates ticket triage with an AI-generated tool built over a weekend.
None of this required a developer, a project request, or a line item in the IT budget. It required an employee, a business problem, and a few hours with an AI coding assistant.
Instead of simply buying software, employees are now building software.
That shift is not the problem. The problem begins the moment one of these tools quietly becomes the system the business depends on to close the books, ship an order, or answer a customer.
Excel is not the problem. Excel is one of the most reliable tools ever built for analysis, modeling, and one-off calculations. The problem starts when a spreadsheet quietly turns into a system of record.
There is a tipping point where a workbook stops being a personal productivity tool and becomes critical infrastructure. Most leaders don't notice the shift because it happens gradually, file by file, formula by formula.
Any one of these is manageable. Several of them together mean the spreadsheet has become a business system without anyone deciding it should be one.
Shadow IT has existed for decades. Employees have always found workarounds when official systems felt too slow or too rigid for the problem in front of them.
What changed is speed and accessibility. An employee no longer needs to file a request, wait for an IT project to get prioritized, or find budget for a developer. They can describe what they need to an AI coding tool and have a working application days later.
That is a genuine opportunity. It is also a new category of risk, because the applications being created this way rarely pass through anyone who thinks about security, architecture, or long-term ownership.
Call it Shadow AI. It looks like innovation from the outside. From the inside, it is often a business-critical process running on software nobody outside one department has ever reviewed.
An AI-built application can absolutely solve the problem it was created for. That is exactly what makes it dangerous to overlook. It works well enough that no one stops to ask what is missing underneath.
None of these gaps are visible on launch day. They surface later, usually at the worst possible moment.
AI is genuinely excellent at proving an idea, automating a repetitive task, or producing a first version of something. That is not the same job as running a production business application, and treating them as interchangeable is where the risk hides.
| Dimension | AI-Generated Prototype | Production Business Application |
|---|---|---|
| Purpose | Prove an idea or automate a task quickly | Support ongoing business operations |
| Security | Minimal, often none | Authentication, access control, encryption |
| Testing | Rarely tested beyond the original use case | Structured testing before and after every change |
| Documentation | Usually none | Documented architecture and processes |
| Ownership | The employee who happened to build it | A named owner accountable within the business |
| Data handling | Ad hoc, may not follow governance rules | Defined data governance and backup strategy |
| Lifespan | Meant to validate or solve a short-term need | Built to be maintained and supported for years |
A prototype earns its value by moving fast. A production application earns its value by still working correctly a year later, after the person who built it has moved on.
Most employee-built applications fail quietly, not dramatically. They don't crash in front of leadership during a demo. They get adopted, relied on, and slowly woven into daily operations.
The risk shows up later. The employee who built the tool gets promoted, changes teams, or leaves the company. Suddenly a process the business depends on has no one who fully understands it, no documentation to fall back on, and no plan for what happens next.
By that point, the application is no longer a side project. It is infrastructure, running without an owner.
The instinct to lock everything down after seeing these risks is understandable, and it is the wrong response. Employees experimenting with AI to solve real operational problems is exactly the kind of initiative businesses should want more of, not less.
The goal is not to stop people from building. It is to know when what they built has crossed into territory that requires more than good intentions.
Encourage employees to use AI to prototype ideas, automate small tasks, and improve their own workflows. Draw a clear line, however, around anything that touches financial data, customer information, HR records, ERP transactions, or other systems where a failure would actually hurt the business. Those applications deserve a technical and security review before they become permanent.
Not every spreadsheet needs to become an application, and not every workflow needs automation. Excel remains the right choice for ad-hoc analysis, exploratory modeling, one-time calculations, and personal productivity work that never needs to scale beyond one person.
Use Excel for analysis. Use applications for operational processes.
That single distinction resolves most of the debate before it starts. The question is never "should we get rid of Excel." The question is whether a specific spreadsheet has quietly taken on a job it was never designed to do.
Not every repetitive spreadsheet process justifies building an application. If the underlying workflow is genuinely simple, automation is often the faster, cheaper, and more durable fix.
Connecting existing systems directly, eliminating manual data entry, and letting Excel handle the parts where it still adds value is frequently enough to remove the pain without adding a new piece of software to maintain.
Automation solves the busywork. It doesn't require replacing the tool people already know how to use.
Some processes have outgrown Excel entirely, and no amount of automation will fix that. These are the situations that justify building, or professionally developing, a dedicated application.
When several of these apply, continuing to patch the spreadsheet is more expensive than building the application properly.
The temptation with AI is to use it to rebuild the spreadsheet as a slightly nicer-looking application. That misses the bigger opportunity. The real value is in automating the business process the spreadsheet was only ever a workaround for.
AI applications can extract data from documents, process and route incoming emails, classify transactions, reconcile records across systems, flag anomalies before they become problems, forecast demand or cash flow, match records between disconnected systems, and handle exceptions that used to require someone manually checking a spreadsheet.
The objective is not a better-looking spreadsheet. It is fewer hours spent doing work a spreadsheet was never designed to do well.
Not every problem needs custom software, and assuming otherwise is its own kind of waste. Before building anything, it is worth asking which category the problem actually falls into.
| Situation | Recommended Path |
|---|---|
| A mature SaaS product already solves the problem well | Buy |
| The process is sound but full of manual, repetitive steps | Automate |
| The process is unique, strategic, or poorly served by existing software | Build |
| The process involves documents, unstructured data, classification, prediction, or matching | Use AI within the solution |
Most organizations end up needing all four paths at once, applied to different problems, not a single strategy applied everywhere.
Governance does not have to mean a slow-moving approval committee. A lightweight review process, applied consistently, is enough to catch the risks that matter without discouraging employees from experimenting.
Before an AI-built application is allowed to become part of daily operations, someone should be able to answer these questions:
If those questions don't have clear answers, the application isn't ready to be business-critical, no matter how well it currently works.
Consulting Group works with CEOs, CFOs, COOs, and IT leaders to bring structure around exactly this gap, without shutting down the innovation that got them here in the first place.
That starts with an honest assessment of the Excel files and employee-built AI tools already running the business today, and an inventory of the operational risk hiding inside them. Where a spreadsheet is still doing its job well, we help maintain and improve it so it keeps working without draining employee time on manual upkeep.
Where a spreadsheet or employee-built tool has become a real operational dependency, we transform it into properly engineered software, using AI as one of the tools in that process, not as the product being sold. We automate the repetitive processes underneath it, integrate the systems it should have been connected to from the start, and professionally develop the applications that have become too important to the business to leave ungoverned.
AI has made it possible for almost anyone in the business to build software. That is a genuine advantage for companies that use it well, and a genuine liability for companies that don't know it is happening.
The goal was never to eliminate Excel, and it isn't to stop employees from building with AI either.
The goal is to know the difference between something that works today and software the business can actually depend on tomorrow, and to bring the right architecture, security, and ownership to the systems that have earned that distinction.
We use cookies to improve your experience, analyze site traffic, and personalize content. You can accept all cookies, reject non-essential ones, or customize your preferences below. Privacy Policy
These cookies are required for the website to function and cannot be switched off. They are usually set in response to actions you take, such as setting your privacy preferences or logging in.
These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously, so we can improve site performance and content.
These cookies are used to deliver advertising that is more relevant to you and your interests, and to measure the effectiveness of our marketing campaigns.
Save Preferences

