Quick Overview

  • A survey released by Okta on Wednesday shows that nearly all executives believe employees are using AI responsibly, butshadow AIis quietly infiltrating enterprises. The security platform provider, in partnership with market research firm Apprize360, surveyed nearly 300 technology executives and 500 knowledge workers, finding that more than half of employees reported using personal AI tools without approval.
  • Employees use unapproved AI tools for efficiency and allow these tools to access internal messages, HR-related information, and confidential company documents. The report shows that this practice exacerbates security risks, with 58% of executives stating their organizations experienced an AI-related security incident or near miss last year.
  • Harish Peri, Okta's Senior Vice President and General Manager of AI Security, said in an email that a lack of clarity in AI usage policies or outright bans on personal AI tools may actually increase shadow AI usage. "By taking a more collaborative approach, leaders can provide employees with approved, enterprise-grade alternatives to the unapproved tools teams are using."

Deep Insights

Executives strongly believe their AI usage policies are clear and consistent, but the Okta report shows employees do not feel the same. More than half of employees say their organization's policies are unclear, difficult to find, or nonexistent.

U.S. employees are especially inclined to use unapproved tools to fill productivity gaps. The report found that two-thirds of U.S. employees use unapproved AI, with nearly a quarter using it regularly.

Peri said shadow AI usage is often not malicious but stems from employees wanting to try new tools and agents to meet deadlines or solve specific problems. Employees often do not understand what data AI tools might access or how long data is retained.

"The risk doesn't necessarily come from intent, but from employees experimenting without considering visibility, governance, or consistent security controls," he said.

Organizations should collaborate with employees to understand their productivity needs and what they feel is missing from the company's AI offerings. Based on that, they can establishgovernance frameworks, providing secure sandboxes for employees to safely try AI tools.

"There's an old saying in cybersecurity: you can't protect what you can't see," Peri said. "If you don't know what agents exist in your environment or where they are, you can't reliably enforce access policies."

Peri said many technology leaders have an illusion of control over their AI governance, but most policies require frequent updates and security checks. He encourages business leaders to regularly ask themselves: Which agents have access? What are they allowed to do?

"If you can't answer these questions, you're flying blind," Peri said. "That's the baseline for securely operating an agentic enterprise today."