Skip to content

Executives Undermine AI Governance Through Shadow AI Tools

Bottom line: When executives use unapproved AI tools, they undermine governance by example and force CISOs to choose between stricter policies or better tools — policies alone do not work.

Around two-thirds of executives use unapproved AI tools, while only 31 % of lower hierarchy levels do so. This creates a governance problem at the top of the organization for CISOs that cannot be solved through policies alone.

A study by Microsoft partner TrustedTech reveals a systemic problem: While 75 % of employees recognize security and data protection risks from uncontrolled AI tools, nearly two-thirds of senior decision makers deliberately use unapproved systems. TrustedTech states in a whitepaper: “Most shadow AI users do not ignore the risks – they consciously decide to use these tools anyway. This is not a training problem, but a question of corporate culture, incentives, and available offerings.”

The core problem often lies in the availability of approved alternatives. Employees use shadow AI tools because the provided solutions are inferior to public systems or because no AI tools have been officially released. Executives typically work with highly sensitive data: financial information, strategic plans, trade secrets, and customer data flow into decisions for which there are no audit trails and no permission models.

CISOs and CIOs face a dilemma without a solution through policies alone. Andy Nolan, VP of Technology at TrustedTech, emphasizes: When executives circumvent approved guidelines, it sends a message across the organization that “speed trumps security”. This behavior is observed by employees and undermines the credibility of compliance standards. At the same time, CISOs cannot act as AI police – their role is to enable secure innovation.

Amit Maloo, CISO at AI procurement specialist Ivalua, sees the real solution in design: “Policies alone are not enough – organizations must pair governance with usability.” Successful companies would make the secure path the easiest path: tools that are fast enough for business pace, simultaneously offer necessary access and data sharing with audit trail, and thus create no incentive for workarounds in the first place.


Source: www.csoonline.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: