Senior executives are driving a disproportionate share of shadow AI use
Nearly two-thirds of senior decision-makers admit to using unapproved AI tools. Among lower-level employees, the figure is 31%. That gap, reported in a survey by Microsoft solutions partner TrustedTech, makes one point clear: shadow AI is not only an employee-level security problem. It is an executive governance problem.
Lack of awareness does not explain the behavior. Three in four employees acknowledge that shadow AI creates security or data privacy risks. TrustedTech therefore argues that training alone will not solve it. Users often understand the risk and still choose an unauthorized service because the approved option is missing, too limited, or too slow.
This matters more when senior executives are involved. Their work can include financial data, strategic plans, intellectual property, customer information, and material business decisions. Entering such information into an unmanaged AI service can move company data beyond normal security controls. IT may not know what was shared, where it was processed, how long it was retained, or whether it could be used under the provider’s terms.
The core constraint is the quality and accessibility of the approved alternative. TrustedTech says employees use shadow AI when mainstream products work better than the tools their employer provides, or when the company has not approved an adequate tool at all. A policy that blocks useful technology without providing a capable replacement gives users a strong reason to bypass the policy.
For the C-suite, the practical response is not to prohibit AI more aggressively. Companies need sanctioned tools that can perform the work users are trying to complete. They also need appropriate controls for sensitive data, identity, access, logging, and retention. The secure option must also be practical under real business deadlines.
Executive behavior is especially important. A company cannot credibly treat shadow AI as unacceptable employee behavior while its senior leaders routinely bypass the same controls. Leadership needs to make secure AI adoption part of normal business operations rather than a constraint delegated to IT.
Executive use of shadow AI weakens governance across the organization
AI governance depends on leadership following the controls it expects employees to follow. When CEOs and other C-suite executives use unauthorized AI services, CIOs and CISOs face a structural problem. They may be responsible for technology and security risk without having enough authority to stop a senior executive from creating that risk.
Andy Nolan, VP of technology at TrustedTech, identifies the organizational consequence. “If senior leaders bypass approved AI tools or policies, it sends an implied message that speed matters more than security and compliance,” he says. Employees observe those decisions. IT then has a much harder job enforcing standards that executives do not follow themselves.
This makes executive behavior part of the control system. Written policies matter, but they cannot compensate for inconsistent leadership. If exceptions become normal at the top, employees have reason to treat AI governance as optional. That can increase untracked use and make it harder for security teams to understand which services receive corporate information.
The answer is not to turn the CIO or CISO into what Nolan calls the “AI police.” Their role is to help the business use AI without creating unmanaged exposure. That requires clear rules about which tools and data are permitted, but it also requires approved products that employees and executives want to use.
Governance should therefore focus on the decisions that create material risk. Companies need to know who can use an AI service, which data can enter it, what records must be retained, and how usage can be audited. High-risk activities involving confidential financial information, customer data, intellectual property, contracts, or strategic plans require stronger controls than low-risk experimentation with public information.
Nolan’s position is that executive alignment, clear governance, and usable secure tools must operate together. He adds that when leadership adopts those solutions, “the rest of the organization is almost sure to follow.”
That gives CEOs and boards a specific responsibility. They should not frame AI governance as an IT policy that applies mainly to employees. The C-suite itself is part of the governance model. If leaders want fast AI adoption, their job is to make the approved route fast enough to support the business while maintaining the controls needed to protect company data.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Shadow AI makes CIOs and CISOs accountable for risks they cannot see
Shadow AI creates a basic control problem. CIOs and CISOs can remain accountable for security and compliance even when senior executives use AI services that IT cannot monitor. The organization carries the risk, but the people responsible for managing that risk may have no record of how it was created.
The problem becomes serious when AI affects business decisions. An executive might use an unapproved service to review a contract, assess a financial commitment, summarize confidential material, or process company data. The resulting decision still belongs to the business. Yet IT may have no audit trail showing what information entered the system, what the AI returned, or how its output influenced the final decision.
Amit Maloo, CISO at AI procurement provider Ivalua, describes this as an accountability gap. “When senior leaders use ungoverned AI tools for business decisions, those decisions still have consequences, such as financial commitments, contract reviews, and data sharing,” he says. “But there is no audit trail, no permissions model, or no way to reconstruct what happened or why.”
That lack of traceability has implications beyond cybersecurity. Legal, compliance, procurement, and audit teams may need to establish how a decision was made or determine whether confidential information was disclosed to an external provider. With sanctioned enterprise systems, identity controls, access permissions, logging, and data-management rules can provide that evidence. Personal or unmanaged AI accounts may sit outside those controls.
More policy is not enough. Maloo argues that restrictions can reduce shadow AI use but are unlikely to eliminate it, particularly when senior executives have enough authority to accept the disciplinary risk. An approved tool that cannot complete the required task creates continued pressure to use an unrestricted alternative.
The better approach is to combine control with capability. Approved AI services need appropriate access to the systems and data required for legitimate work, subject to permissions and security rules. This allows users to obtain useful results without moving activity into unmanaged services.
For C-suite leaders, accountability should follow authority. Executives who expect CIOs and CISOs to manage AI risk must also give them visibility into AI use and support common controls across senior leadership. Secure AI adoption is much easier when the organization can identify users, control data access, record important activity, and investigate decisions when necessary.
Workflow friction is pushing users toward ungoverned AI
More than two-thirds of C-level executives prioritize speed over security when using AI tools, according to a June report from employee monitoring software vendor Teramind. The same report found that about two-thirds of enterprise AI activity runs through personal accounts on platforms for which the employer already owns licenses.
Those findings change the diagnosis. In many cases, companies have already purchased the necessary product. Users still bypass the governed version because the approved way to access it is slower or poorly connected to their work.
Nik Kale, principal engineer and product architect at Cisco and a member of the Coalition for Secure AI, highlights this distinction. “People are paying for the governed version and using the ungoverned version of the same product, so the problem isn’t the tools,” he says. “The approved path is slower, buried in procurement, or disconnected from where the work actually happens, and speed wins every time under a deadline.”
This creates an operational issue as much as a security issue. AI can produce results within seconds, but corporate approval, account provisioning, data-access requests, or procurement processes may take much longer. When the business expects immediate output, that gap creates a strong incentive to use a personal account that is already available.
Personal accounts can remove controls that the company has paid to obtain. Depending on the product and configuration, enterprise versions may support centralized identity management, administrative policies, usage logs, data protections, and other security features. Moving the same work to an unmanaged account can reduce IT’s ability to enforce those controls or determine what corporate information has been processed.
Kale therefore argues that the critical issue is friction. As he puts it, “People aren’t going around the front door because the room is locked. They’re going around it because the front door is slower.” For executives, the underlying message is that access speed has become part of AI security. Controls that create excessive delay can encourage the behavior they are designed to prevent.
The practical response is to examine the full approved workflow. Companies should measure how long it takes employees to obtain AI access, connect permitted data, receive required approvals, and use the tool inside normal business processes. Unnecessary delays should be removed while controls for identity, sensitive data, logging, and regulatory requirements remain in place.
The Teramind findings also suggest that software spending alone does not establish governance. Buying enterprise AI licenses has limited value if employees continue to conduct business through personal accounts. CIOs should therefore measure actual use of sanctioned services.
For the C-suite, the objective is straightforward: make governed AI sufficiently capable and fast for real business conditions. Security remains necessary. But when an organization can deliver security without unnecessary operational delay, it removes one of the strongest incentives for shadow AI.
Poor awareness and training push employees toward unauthorized AI
Buying an approved AI tool does not mean employees will use it. Organizations also need to tell people which tools are available, what they can be used for, and how to use them effectively. When that work is missing, employees often choose familiar consumer AI products instead.
Matthew Scavetta, chief technology innovation officer at IT solutions provider Future Tech Enterprise, identifies awareness as a key weakness. Many organizations do not adequately communicate which AI applications have been approved. They also fail to train employees on how those applications support real business tasks. As a result, users may not know that a sanctioned alternative exists or may consider it harder to use than a product they already understand.
“If you don’t solve problems for people quickly or make people aware of which tools they can use safely, they will find a workaround,” Scavetta says. “AI tools are no different than anything else.”
The important distinction is between compliance training and practical product training. Telling employees not to enter confidential data into unapproved AI systems can explain the risk, but it does not teach them how to complete their work with the approved system. Users need clear guidance on permitted services, acceptable data, useful functions, access procedures, and where to get support.
Companies should also avoid treating every AI use case as equally risky. A worker using AI to improve generic text presents a different risk profile from an executive uploading customer records, intellectual property, contracts, or financial plans. Training and access controls should reflect those differences. That gives employees clearer boundaries without placing unnecessary controls on low-risk work.
For executives, adoption is a useful measure of whether the program is working. Companies should look beyond how many AI licenses they have purchased. They should monitor whether employees activate those licenses, use approved platforms consistently, complete relevant training, and continue using personal accounts for business tasks. Low adoption may indicate that the sanctioned service does not meet users’ needs or that employees do not understand how to use it.
Training cannot compensate for an inadequate product. TrustedTech’s broader findings make that clear: users may understand the risks of shadow AI and choose it anyway. The strongest program combines awareness, practical training, capable technology, and straightforward access. The goal is to make secure AI useful enough that employees have little reason to seek an unauthorized alternative.
CIOs must reconcile AI ambition with security and measurable business value
CIOs face pressure from two directions. CEOs and boards want access to rapidly improving AI capabilities. At the same time, CIOs and CISOs remain responsible for security, governance, operational reliability, and the economics of technology investments.
Matthew Scavetta, chief technology innovation officer at Future Tech Enterprise, says that pressure is increasing. “CIOs, in particular, are under more and more pressure each year to keep up with what’s possible as tech influencers keep preaching about the potential of these tools,” he says.
Executive enthusiasm can accelerate experimentation, but it does not establish a business case. Scavetta notes that CEOs and board members can become caught up in AI expectations while case studies increasingly show that some organizations have realized little return on investment. He describes the CIO’s challenge as a continuing balance between what technology can do and what is practical for the business.
The key constraint is not access to AI. Organizations can now buy AI capabilities from many enterprise and consumer vendors. The harder task is identifying where those capabilities produce enough measurable value to justify their cost, implementation effort, security exposure, and governance requirements.
That calls for greater discipline in how AI initiatives are selected and measured. Executives should define the business outcome before deployment. Depending on the use case, that could mean lower processing costs, faster contract review, increased developer output, reduced customer-service handling time, or higher revenue. The organization can then compare those gains with licensing, integration, training, oversight, and risk-management costs.
This approach also helps reduce shadow AI. When the company identifies valuable use cases early, IT can provide sanctioned tools and controls that support them. When leadership adopts a new AI service independently, IT instead has to address security, data, compliance, and integration questions after usage has already begun.
Security and innovation therefore should not be managed as competing objectives. Secure systems allow valuable AI use to scale across the enterprise with greater visibility and consistency. Excessive controls can slow adoption, but uncontrolled adoption can create data exposure, poor traceability, duplicated spending, and decisions that are difficult to audit.
The C-suite should give the CIO a clear mandate: enable AI where the expected business value is credible, make approved tools practical to use, and apply controls in proportion to the data and decisions involved. The aim is not maximum AI adoption. It is sustained business value from AI at an acceptable level of risk.
Key takeaways for decision-makers
- Shadow AI risk starts at the top: Nearly two-thirds of senior decision-makers use unapproved AI, versus 31% of lower-level employees. Leaders should ensure sanctioned tools can meet real business needs without exposing sensitive company data.
- Executive behavior determines whether governance works: AI policies lose authority when C-suite leaders bypass them. Executives should follow the same controls they expect employees to follow and support secure tools that are practical under business deadlines.
- CIOs need visibility to own AI risk: Shadow AI can leave CIOs and CISOs accountable for decisions and data flows they cannot audit. Organizations should require appropriate identity controls, permissions, logging, and traceability for business AI use.
- Reduce friction in the approved path: Teramind found that more than two-thirds of C-level executives prioritize speed over security, while about two-thirds of enterprise AI activity occurs through personal accounts on platforms already licensed by employers. Streamline access and integration so secure AI does not become the slower option.
- Training must solve practical problems: Employees need more than warnings about shadow AI. Companies should clearly identify approved tools, teach users how to apply them to real work, and measure actual adoption rather than licenses purchased.
- Tie AI adoption to measurable value: CIOs face pressure to accelerate AI while controlling security, cost, and uncertain ROI. Executives should prioritize use cases with defined business outcomes and scale them only when value justifies the investment and risk.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


