
Two out of every three employees who’ve used AI at work have used a tool they believed their company hadn’t approved. That’s not a guess. It’s from a recent survey of people who use AI as part of their job, cited by Jamf.
Sit with that for a second. This isn’t a fringe behavior from one rogue engineer. It’s most of your team.
This isn’t the shadow IT you’re used to
Shadow IT used to mean someone signed up for Dropbox or Trello without asking. Annoying, but manageable. You could see it. A quick look at an app inventory would surface it, and you could either bless it or shut it down.
AI sprawl doesn’t work that way, and it’s coming from two directions at once.
The first is native. Gemini is already inside Google Workspace. Copilot is already inside Microsoft 365. Slack will summarize a thread for you without anyone flipping a switch. These aren’t new tools someone had to install. They’re features quietly turned on inside software you already pay for.
The second is standalone. Claude, ChatGPT, Cursor, and dozens of others are installed the same way someone would install any other app, often without asking anyone first.
Both add up to the same result: AI is already running across your environment, and almost none of it arrived with a plan.
What this actually looks like
It rarely shows up as one dramatic moment. It’s a hundred small ones. Someone pastes a section of a client contract into ChatGPT to get a plain-English summary before a call. Someone drops a spreadsheet of user data into Claude to spot trends faster. A new hire turns on Copilot’s meeting summaries in their first week because it looked helpful, not because anyone approved it. None of these people think they’re doing anything wrong. Most of them aren’t, technically. But nobody signed off on where that data went, what it’s used to train, or whether it’s still sitting somewhere outside your control.
The numbers back this up
Other research points at the same gap, from different angles:
- Roughly a quarter of employees have put confidential company data into a public AI tool, including customer records and financial information, according to Salesforce’s State of IT research.
- Source code is the single most common category of sensitive data that ends up in AI tools, per Cyberhaven’s data security research, which matters a lot if your team is technical.
- Over half of organizations have no formal policy at all governing employee use of external AI tools, per KPMG.
- Roughly four in ten organizations say they can’t even produce an inventory of which AI tools are in use across their own workforce, per Gartner.
That last one is the real story. It’s not that companies have looked at their AI usage and decided the risk is acceptable. Most haven’t looked at all.
Why this is a bigger deal than it looks
Nobody’s trying to leak your data. People are trying to get their work done faster, and AI tools are genuinely good at that. The problem isn’t intent; it’s visibility. Most companies, especially those in the 25 to 250-employee range without a dedicated IT team, have no clear picture of what’s turned on, who’s using what, or where their data actually goes once it’s typed into a prompt.
That gap matters more if you’re venture-backed. Investors and enterprise customers are starting to ask pointed questions about AI usage during diligence and vendor security reviews, not just about your SOC 2 report or your MDM setup. “We don’t really know” is not an answer anyone wants to give in that room. Global spending on AI governance tools is projected to climb past a billion dollars by 2030, largely because that question is becoming standard, not optional.
You can’t make a good decision about what to allow, restrict, or standardize on until you know what’s actually happening. Right now, most companies are guessing.
How we approach it
This is exactly the gap we built our AI audit process to close, and it works the same way we already approach identity, devices, and security: get deliberate, don’t ban things people find useful, and don’t touch anything without a green light.
Audit. We map where AI already lives across your environment: native features inside tools you’re already paying for, plus standalone tools your team adopted on their own. You get a clear picture of what’s turned on, who’s using what, and where your data is going.
Recommendations. You get a report with specific calls, not generic advice. Switch a feature off. Standardize on one approved tool instead of five overlapping ones. Tighten data-sharing settings. Or leave something alone because it’s genuinely low risk. We walk you through the reasoning before you decide anything.
Execution. We only implement what you approve. Nothing gets turned on, turned off, or changed in your environment without you signing off first.
Training. If you’re rolling out a company-wide AI tool for the first time, we can run end-user training so your team actually knows how to use it well. That’s a separate engagement, quoted upfront.
Ongoing management. Once a supported AI tool is deployed, day-to-day work like access requests falls under your existing managed services by default. For larger or more complex environments, this becomes an ongoing conversation: AI governance policy, department-by-department rollout, and tighter integration with your compliance work.
Where to start
Most companies don’t need to ban AI tools, and honestly, they shouldn’t. The teams that use them well are moving faster than those that don’t. The real problem is that almost nobody has made a deliberate call about which tools to use, how, and with what data. That call gets made either on purpose, now, or by accident later, usually right when an investor, auditor, or client asks a question nobody in the room can answer.
If you don’t currently know what AI tools are running across your environment, that’s the first thing worth fixing, before you write a policy, before you buy or ban anything.
Let’s talk about scoping an AI audit for your environment.