Senior executives abuse shadow AI twice as much as regular employees do
Summary
A survey by Microsoft solutions partner TrustedTech reveals that nearly two-thirds (66%) of senior decision-makers admit to using unapproved AI tools, significantly higher than the 31% of lower-level employees. This "shadow AI" usage persists despite three in four employees acknowledging associated security and data privacy risks. The problem stems from a lack of genuinely useful approved tools, organizational cultures prioritizing speed over security, and friction in sanctioned processes. Executives often bypass official channels because the approved path is slower or less capable, even when company licenses exist for the same products. This practice creates significant challenges for CIOs and CISOs, who are held accountable for risk exposure but lack visibility and authority, especially when sensitive corporate data is involved. The issue is framed as a culture, incentives, and alternatives problem, not merely a training deficit.
Key takeaway
For CIOs and CISOs grappling with shadow AI, your strategy must shift from policing to enablement. Instead of solely imposing policies, prioritize providing secure, user-friendly AI tools that genuinely meet business needs and are easier to access than unsanctioned alternatives. Secure executive alignment on AI governance, as leadership's behavior sets the organizational standard. By making the secure path the easiest path, you can significantly reduce risk exposure and foster widespread compliance.
Key insights
Executive shadow AI use is a systemic issue driven by cultural incentives and a lack of viable, user-friendly sanctioned alternatives.
Principles
- Governance effectiveness relies on leadership modeling compliance.
- Secure AI adoption requires making the approved path the easiest.
- Pair AI governance with tool usability.
In practice
- Provide secure, desirable AI tools.
- Align executive leadership on AI governance.
- Increase awareness and training for sanctioned AI.
Topics
- Shadow AI
- IT Governance
- Data Security
- Risk Management
- Executive Leadership
- AI Adoption
Best for: Executive, VP of Engineering/Data, Director of AI/ML, CTO, IT Professional
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by CIO.