Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 11 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

65% of Organisations Still Detect Unauthorised Shadow AI Despite Visibility Optimism

New research from CultureAI revealed that overconfidence around AI governance and visibility persists within enterprises

by Guru Writer
March 11, 2026
in Editor's News, Featured, Features
65% of Organisations Still Detect Unauthorised Shadow AI Despite Visibility Optimism
Share on FacebookShare on Twitter

New research from CultureAI has revealed a growing gap between how AI is used in practice and how organisations believe it’s being controlled. Worryingly, the report revealed that while 72% of organisations believe they have full visibility into AI usage, 65% still report detecting unauthorised shadow AI, revealing a structural gap between perceived control and operational reality. 

The research, titled The State of Enterprise AI Usage: The Illusion of Control, was conducted by Censuswide, features insights from 300 senior technology, security, and risk leaders from across North America and Europe. 

Unsurprisingly, AI is widely used across teams, with 67% of security leaders reporting wide use across the organisation and 27% use in specific functions. Currently, AI use is most notably focused on core functions like data analysis and RevOps (72%), software development and engineering (59%), and customer support (43%). Yet, the vast majority of respondents (91%) expect AI usage to grow across their entire organisation over the next 12 months, with 41% expecting significant growth. However, risk scales with usage. As exposure grows faster than controls, an organisation often has little time to prepare. 

Nearly three-quarters (72%) of respondents report full visibility into AI usage, while 28% report only partial or no visibility. However, nearly two-thirds (65%) of respondents reported detection of unauthorised AI usage (shadow AI). This means that many tools, personal accounts, and embedded AI features remain invisible to traditional controls.

Most organisations express strong confidence in their visibility and governance posture, with formal frameworks, policies, and oversight committees now being common. However, unauthorised AI usage, limited detection and inconsistent enforcement capabilities remain widespread, creating an illusion of control: governance exists, but behaviour frequently escapes it.

Leaders consistently identify high-impact concerns such as compliance exposure (56%), data leakage via prompts and uploads (52%), credential compromise (40%), and intellectual property loss (39%).  Despite this, nearly half (46%) of respondents rate AI risk as moderate or lower. Whilst organisations acknowledge AI risk, these risks are rarely escalated. This apparent contradiction reveals that leaders are not dismissing AI risk, but they are struggling to accurately quantify it in an environment where damage often occurs without an obvious breach, alert, or outage.

Most organisations have policies, committees, and training in place, but lack mechanisms that operate in real time at the point where AI risk is actually created: prompts, uploads, and embedded AI features inside SaaS tools. Nearly two-thirds (62%) of organisations report they have already implemented a formal AI governance framework, while a further third are actively developing one. Similarly, over two-thirds (67%) say they have established an AI or risk committee with explicit oversight responsibilities. However, this confidence sits alongside clear operational gaps, with 20% of respondents acknowledging that their policies are not actively enforced and more than a third lacking dedicated AI detection capabilities altogether. 

Oliver Simonnet, Lead Cybersecurity Researcher at CultureAI, said: “Generative AI is now embedded across everyday workflows, often beyond traditional IT oversight. While many organisations believe they have governance frameworks in place, our research reveals a widening gap between perceived control and operational reality. The most significant AI risks in 2026 aren’t theoretical; they’re practical, high-probability risks tied to everyday use. Policies set intent, but without real-time enforcement at the point of use, risk is created quietly and at scale. To adopt AI at scale responsibly, businesses must move beyond policy and implement real-time, enforceable controls where risk is actually created.”

ShareTweet
Previous Post

KnowBe4 launches AI agent to tailor security awareness assessments

Next Post

Top AI SOC Analyst Platforms in 2026

Recent News

Q&A: Graham Cluley warns that AI has made scams harder to spot

Q&A: Graham Cluley warns that AI has made scams harder to spot

June 10, 2026
Agentic Compliance Without Control Risks Scaling the Problems it Aims to Solve

Agentic Compliance Without Control Risks Scaling the Problems it Aims to Solve

June 10, 2026
AI

Nine in Ten Dev Teams Hit by AI Code Bottlenecks as Governance Lags Behind Adoption

June 10, 2026

Check Point Brings Industry Cyber Curriculum to Manchester Students in Latest UK Academic Push

June 10, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol