Bottom line: Two out of three employees in SMEs use AI solutions without IT approval, jeopardizing IT security and compliance.
A WatchGuard study documents that 64 percent of employees in small and medium-sized enterprises deploy unapproved AI tools. For CISOs, this creates an uncontrolled risk within their own network.
The WatchGuard study reveals a widespread practice: 64 percent of employees in small and medium-sized enterprises resort to AI tools that their IT department has not approved or authorized. This shadow AI usage occurs parallel to official IT policies and security policies.
For CISOs, this means concretely: sensitive company or customer data are uploaded to unknown cloud services whose data protection standards, security certifications and compliance status are unclear. At the same time, these tools evade any control by DLP systems (Data Loss Prevention), network monitoring or security gateways that are calibrated to approved applications.
The behavior is not malicious, but pragmatic: employees seek productivity gains or faster solutions for their tasks. However, this does not make the phenomenon any less dangerous. SMEs often face the highest relative security risk, as their security teams are resource-constrained and visibility over actually deployed systems is limited anyway.
CISOs should respond with a two-track approach: transparency through enforceable discovery measures (shadow IT detection) and in parallel a risk-based approval strategy for AI tools with clear classifications (permitted for brainstorming, forbidden for personnel data, etc.). A mere prohibitive stance leads to increased circumvention.
Source: itwelt.at · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.