Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

PagerDuty found 66% of office workers use AI tools they believe violate company policy. This isn't malicious, but a result of consumer AI tools often being far more capable than sanctioned enterprise software, creating a significant "shadow AI" governance problem for corporations.

Related Insights

Similar to "Shadow IT," employees are using powerful, unmanaged AI agent tools without corporate oversight. These "shadow agents" can gain the same system access as a powerful employee but without any identity, limits, or oversight, creating a significant and often invisible risk for CISOs and CTOs.

IT leaders are caught in a pincer movement regarding AI. They face top-down pressure from boards to adopt AI and drive efficiency, while simultaneously dealing with bottom-up pressure as employees independently purchase and use their own AI tools ("shadow AI"). This creates a chaotic environment that CIOs must navigate.

Employees often use personal AI accounts ("secret AI") because they're unsure of company policy. The most effective way to combat this is a central document detailing approved tools, data policies, and access instructions. This "golden path" removes ambiguity and empowers safe, rapid experimentation.

Instead of punishing employees for using unapproved AI tools, leaders should view it as a critical signal. It's often the highest performers who do this, not out of malice, but because the company's sanctioned tools are inadequate. They are identifying gaps and potential solutions for the organization.

Individual employees want powerful, autonomous AI agents similar to consumer products. However, the enterprise prioritizes control, safety, and governance. This creates a fundamental tension that enterprise AI products must navigate, balancing user desire for freedom with the organization's need for security and oversight.

The decentralized adoption of numerous AI tools by employees on their devices creates a new, invisible "Shadow AI" attack surface. Companies lack visibility into these tools, making them vulnerable to compromised AI packages and libraries consumed by unsuspecting users.

Research reveals a major disconnect: 53% of professionals feel advanced in their personal AI use, but only 25% believe their company is keeping pace. This disparity between individual agility and organizational lag creates internal friction and significant risk of shadow IT.

The most clear and present danger in enterprise AI is the proliferation of unauthorized "shadow agents." These tools, like coding assistants downloaded by employees, have powerful access to codebases and databases, creating a massive, uncontrolled security threat.

Large enterprises often have secure, licensed AI tools. Mid-market employees, lacking these resources, are more likely to use free consumer-grade AI, inadvertently feeding it proprietary company data and creating significant security vulnerabilities.

When companies don't provide sanctioned AI tools, employees turn to unsecured public versions like ChatGPT. This exposes proprietary data like sales playbooks, creating a significant security vulnerability and expanding the company's digital "attack surface."