The Nextworld co-founder argues that companies cannot govern artificial intelligence effectively while their operational data, workflows, and accountability remain scattered across disconnected systems.
For years, companies have quietly operated two technology environments. One is the official system of record. The other consists of spreadsheets, inboxes, departmental applications, and manual workarounds that keep daily operations moving when formal systems cannot.
Nextworld calls that second environment Shadow ERP. According to co-founder and CEO Kylee McVaney, the current concern over Shadow AI reflects the same underlying governance failure, now moving at machine speed.
“Shadow IT isn’t the problem. It’s the symptom. It happens when rigid enterprise software forces the business into operational debt,” McVaney said. “Critical data ends up scattered across spreadsheets, inboxes, and custom tools that IT can’t see, and leadership can’t govern. Yet that’s the fragmented foundation many companies are trying to build AI on today, and AI can only be as intelligent as the operational truth it’s built on.”
AI Inherits the Systems Beneath It
The problem becomes clear when an organization introduces AI without first resolving fragmented workflows, permissions, and data ownership. An agent may produce useful work, but it still depends on the information and processes surrounding it.
That makes enterprise AI governance inseparable from the architecture beneath the technology. If operational truth is divided across disconnected tools, AI can automate those inconsistencies without correcting them.
Recent research suggests many companies are already confronting that gap. EY’s March 2026 Technology Pulse Poll found that 52% of department-level AI initiatives were operating without formal approval or oversight. It also found that 78% of technology leaders believed adoption was outpacing their organizations’ ability to manage it.
Panorama Consulting’s 2026 ERP Report points to the same structural problem in conventional enterprise systems. As SaaS ERP adoption grows, unclear governance ownership after implementation can lead to shadow reports and ad hoc access requests. Those unofficial processes emerge for the same reason employee-built AI applications do: workers need a faster way around systems that no longer match operational reality.
McVaney sees that pattern repeating now.
“The same dynamic that created shadow ERP is already playing out with AI. Employees are using general-purpose AI tools to build their own custom applications, addressing the same gaps that drove spreadsheet workarounds historically, and on the surface, it looks like productivity. In practice, those apps are ungoverned, invisible to IT, unscalable, and impossible to maintain when the person who built them leaves. Slowing workers down isn’t the answer. Giving them a platform where AI agents, the data they act on, and the workflows they trigger all live inside a single governed environment is. The goal is to channel that energy productively.”
Governance and Security Are Separate Problems
An effective AI governance framework must establish who approved an agent, who remains accountable for its decisions, and how its actions can be reviewed. Security answers a different question: what is that agent permitted to access, change, or trigger?
The distinction matters. A company may have clear governance procedures while still carrying an agentic AI security gap if agents can act beyond the permissions of the employees they represent.
That risk may already exist inside tools companies use every day. Some organizations are discovering that AI features delivered through routine vendor updates have been running against production data before leadership formally evaluated them. Businesses therefore need to audit which AI capabilities current vendors have activated, rather than focusing only on new tools under consideration.
The governance gap also appears in broader deployment data. Smarsh and FTI Consulting reported in July 2026 that 55% of enterprises were actively deploying AI, while only 26% said governance was fully aligned with that pace. Just 30% said they could comprehensively detect and manage unauthorized AI use.
Architecture Sets the Rules Early
McVaney argues that enterprise architecture AI decisions should establish accountability before applications and agents reach production. Oversight added later may expose problems, but it cannot fully repair a fragmented foundation.
Nextworld designed its platform so that every application, agent, and integration automatically inherits role-based access controls, audit trails, and a gated promotion process. Governance is built into the platform from day one rather than added afterward, making AI accountability part of the operating environment.
That approach also informs Nextworld’s view of ERP modernization. The company does not argue that businesses should discard every existing system. Its stated position is to preserve what works while building governed applications to address the remaining operational gaps.
The question will become more urgent as agent adoption expands. Gartner forecasts that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from fewer than 5% at the start of the year. Gartner also predicts that more than 40% of agentic AI projects will be canceled by 2027 because of escalating costs, unclear business value, and inadequate risk controls.
Nextworld applies the same warning to the adoption of the Model Context Protocol. As the company has written, “dozens of ungoverned agents calling hundreds of unmanaged tools is Shadow ERP with a new protocol underneath it.” The protocol itself is not the central risk. The risk is allowing the same pattern of ungoverned adoption to recur through agents.
Governance as an Enabler of Speed
For McVaney, a governed AI platform should not stop employees from solving problems. It should provide an environment in which applications can be secured, maintained, audited, and extended beyond the person or department that created them.
Founded in 2016, Nextworld has grown to roughly 450 employees and over 600 customers across 50 countries. In early 2026, it appeared on the Constellation ShortList for Enterprise Application Platforms from non-ERP Vendors for the third consecutive year.
Those figures offer context, but McVaney’s larger point concerns the AI deployment risk facing enterprises of every size. Blocking employee-built tools does not address why they appeared in the first place. A more durable answer begins with architecture that keeps data, permissions, decisions, and responsibility visible from the start.



