AppSec · 109 days ago
The control failure is not a rogue model. It is employees giving personal AI tools access to internal messages, HR data, and confidential documents while leaders think the policy is clear. Once that access is granted by the user, sensitive data can leave through a trusted-looking workflow instead of a malware event.
Okta’s survey found that more than half of employees use unapproved AI tools, and 58% of executives said their organization had an AI-related incident or close call last year. It also found a gap between leadership and staff: executives believe the rules are clear, while more than half of employees say the policies are unclear, hard to find, or missing.
That gap keeps shadow AI inside the business even when tools are banned. The risk is quiet exfiltration through productivity workflows that normal blocking and DLP assumptions do not see.
4 sources covering this story
Shadow AI: The Hidden Risk Expanding Across the Enterprise
Learn about the shadow AI attack surface, how it is expanding, and how you can protect and govern it from threats.
Enterprise data is creeping its way into shadow AI tools
Executives and employees are clashing over usage policies as AI security concerns rise, an Okta report found.
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
Shadow AI adoption grows as 69% of organizations detect unauthorized AI tools, increasing unseen corporate data exposure risks.
Turns out the C-suite loves shadow AI - Help Net Security
Workplace shadow AI use is rising as senior leaders bypass approved tools despite security and privacy concerns.
Part of the PlainSec briefing for 2026-05-29