Companies Build AI Governance to Tame Shadow Tools

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Employees run three to five AI tools daily, most unreviewed by IT, and many connect to corporate data via OAuth tokens or browser sessions, exposing shared drives, emails, and internal documents.
- Gartner reports that 69% of organizations suspect or confirm prohibited AI tool use, while only 37% have an AI governance policy.
- OAuth connections are a primary source of shadow AI, granting read/write permissions to Google Workspace or Microsoft 365; quarterly audits often reveal dozens of unreviewed tools.
- Browser extensions enable AI tools to operate without touching the OS, evading traditional endpoint management, and can be detected via browser management solutions or lightweight agents.
- Microsoft Copilot, Google Gemini, and Salesforce Einstein are AI features bundled inside already‑approved tools that may be introduced after vendor review without separate security evaluation.
- Adaptive Security offers an AI Governance product that provides real‑time visibility into AI tool usage, automated policies, and just‑in‑time employee coaching.
Why it matters: Security teams gain real‑time visibility into unauthorized AI usage, reducing data exposure risk, while employees retain access to productive AI tools through approved channels; the structured governance cuts shadow AI prevalence and eases compliance burdens for organizations and streamlines audit processes.
Ask SkimNews




