​David Matalon is the founder and CEO of Venn.

Companies have dealt with shadow IT for years, with employees, contractors and other workers using unsanctioned software to get their jobs done. When organizations imposed unrealistic restrictions to protect company systems and data, users found workarounds. We are now seeing the sequel to this in shadow AI, only the stakes are even higher.

Many companies are approaching AI from a defensive crouch. They are blocking tools, drafting acceptable-use policies and treating AI primarily as a security risk to contain. The problem is that the business and its users want AI too badly. The benefits are too significant to ignore, and the time savings are too compelling for employees not to find a workaround.

AI adoption is already happening. The decision has effectively been made by employees and business teams. The question for IT ​leaders now is how they can gain visibility into AI usage, control where sensitive data flows and build governance that follows the work.

Shadow AI Is The Sequel To Shadow IT

Shadow IT emerged because employees needed tools the company did not provide. Blanket restrictions did not eliminate demand; they forced people to work around company controls. We are seeing the same pattern with AI.

If companies overdo the restrictions, people are going to find ways around them. AI can make work significantly faster and easier. Once employees experience that benefit, asking them to abandon the technology is not realistic.

Saying no may only push AI adoption into personal accounts, unauthorized applications and invisible workflows, leaving compliance, security and governance teams unable to protect activity they cannot see.​

This is the security workaround paradox: When organizations make useful technology too difficult to access, employees may adopt less secure ways of using it.

The Risks Are Real

Companies are not wrong to be concerned about AI. The security risks are significant, particularly for organizations operating in regulated industries.

Organizations handle protected health information, financial records, customer data, intellectual property and contracts. Every AI interaction has the potential to expose that information.

Employees may paste sensitive text, customer records or protected files into an AI platform. Once this data enters a model, IT no longer controls where it lives, how long it persists or who else can see it.

The challenge grows with contractors, offshore workers, remote teams and unmanaged devices. In a highly distributed, heterogeneous workforce, traditional device-based controls may not be enough.

But the existence of risk does not make a blanket ban an effective strategy. In many cases, blocking AI without providing a sanctioned alternative simply moves the risk somewhere less visible.

The Decision Has Already Been Made

AI adoption is already outpacing organizations’ ability to restrict and control it. Companies therefore need to change the questions they are asking.

Instead of asking, “How do we stop employees from using AI?” leaders should ask, “How do we say ‘yes’ to AI securely?”​

Instead of building governance around a particular device or application, they should ask, “How can we protect company data and AI workflows on any device, for any user?”

Companies need controls that reflect how people actually work across applications, devices and employment arrangements.

The goal should not be to slow AI down; it should be to enable people to use it responsibly.

Create A Path For Sanctioned AI

The balanced approach is sanctioned AI.​​

Decide which AI tools the company will support and provision company accounts for them. Separating business AI usage from personal AI usage is crucial to ensure that company data stays within sight. Employees can use approved tools within a business context, but personal AI accounts should not be used for company work. This creates a clear boundary without denying employees access to the technology altogether.

This is freedom within enforceable boundaries, not unrestricted AI experimentation.

That is a much stronger security position than assuming a written prohibition will prevent employees from opening a personal account.

Freedom Without Compromise

Compliance and security teams may instinctively default to no because the risks are incredibly high. For regulated companies in particular, moving too quickly without the right protections can create serious consequences.

But defaulting to no is not the same as managing risk.

AI’s benefits are too significant to ignore, and excessive restrictions create the workarounds security teams are trying to prevent. The better approach is to make saying “yes” possible through sanctioned tools, visibility into usage, and consistent policy enforcement.

Companies that succeed in this will be the ones that enable their people to adopt AI quickly and safely.

The real competitive advantage is freedom without compromise: giving employees permission to use transformative technology without losing control of company data.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version