Your Team's AI Skills Are Creating a Hidden Mess

TL;DR: Developers are building custom AI skills locally, creating a massive governance challenge for companies. Enterprises are left struggling to manage a growing, decentralized library of unvetted AI tools and runbooks, creating a new form of 'shadow IT'.
Key facts
- Category
- Infrastructure
- Impact
- High
- Published
- Source
- The New Stack
Full summary
As developers build custom AI skills on their laptops, enterprises are inheriting a sprawling, unmanaged 'shadow IT' problem with little oversight.
Enterprises are facing a new and subtle operational challenge as their developers embrace artificial intelligence. According to reporting from The New Stack, a growing problem stems from developers creating custom "AI skills" on their own laptops to automate tasks. These skills, which can range from deployment runbooks to code review checklists, are being built in a decentralized, ad-hoc manner. Sagar Batchu, CEO of Speakeasy, highlights the core issue: it is unrealistic for any central administrator to have context on how every single skill across a company should be performing. This bottom-up innovation, while powerful, is creating a sprawling and ungoverned library of tools that enterprises inherit, often without any formal oversight, documentation, or quality control. The result is a hidden mess that complicates governance and undermines the very efficiency AI is meant to provide.
In this context, an "AI skill" is not a human capability but a modular set of instructions that an AI agent can execute. Think of it as a small, single-purpose program or script designed to automate a specific workflow. For example, a developer might create a skill that teaches an AI agent how to analyze a pull request against the company's unique coding style guide, or another that walks the agent through a multi-step incident response checklist. These skills are often created quickly to solve an immediate, local problem. The mechanism of the problem is their origin: they are born outside of traditional software development lifecycles. They are written on a developer's machine, tested informally, and then deployed for use by an AI agent, often bypassing the rigorous code review, security scanning, and performance testing that standard applications go through. This creates a blind spot for IT and security teams.
This trend represents a new frontier for "shadow IT," where technology is adopted and used without the knowledge or approval of the central IT department. The direct impact falls on IT, security, and governance teams who are left in the dark. They cannot ensure these AI skills are secure, compliant with regulations like GDPR or SOC 2, or even efficient. A poorly written skill could inadvertently expose sensitive data, introduce a security vulnerability, or consume excessive computing resources, driving up costs. For CTOs and engineering leaders, this uncontrolled proliferation undermines efforts to build a standardized, scalable AI strategy. Instead of a cohesive ecosystem of well-managed tools, they are left with a fragmented collection of personal scripts that are difficult to maintain, update, or share effectively across the organization, leading to duplicated effort and inconsistent outcomes.
The business impact of this unmanaged growth is a silent drag on the return on investment from AI. Companies pour resources into AI platforms and agents to accelerate productivity, but these gains can be eroded by the chaos happening at the skill level. This introduces significant operational risk and accumulates a new form of technical debt that will be costly to address later. The key takeaway for business and technology leaders is the urgent need for a proactive governance strategy for AI skills. Allowing purely organic, bottom-up creation without a framework is not a sustainable path. Organizations must begin establishing clear processes for how AI skills are developed, tested, approved, and monitored. This means treating AI skills like any other critical software asset, with version control, security checks, and performance monitoring built into their lifecycle.
Looking ahead, the industry is poised to respond to this challenge with a new category of tools focused on AI skill management and governance. This emerging market will likely be a subset of AIOps or MLOps, offering platforms that act as a central registry or "app store" for an enterprise's AI skills. These solutions will provide capabilities for cataloging, versioning, securing, and monitoring the performance of these skills, bringing much-needed order to the chaos. We can expect this evolution to mirror the journey of traditional software development, which moved from individual scripts to the disciplined, automated pipelines of modern DevOps. The central question for enterprises will be whether to build these governance platforms internally or adopt third-party solutions. Either way, applying formal discipline to the creation and management of AI skills will be a critical step in maturing from AI experimentation to scalable, enterprise-grade AI implementation.
Why it matters
This trend creates a new form of "shadow IT" for artificial intelligence. Without central oversight, IT and security teams lose visibility into the tools being used, making it impossible to enforce security, compliance, or performance standards on AI agents operating within the company.
Business impact
The proliferation of unmanaged AI skills introduces significant operational risk and technical debt, undermining the potential ROI of AI investments. It leads to inconsistent performance, duplicated effort, and a lack of standardization that can slow down development and increase maintenance costs.
Tags
Related on Notifire
Related stories
Primary source: The New Stack