AI Data Security

Shadow AI Isn't a Tool Problem. It's a Data Problem.

New Gartner® research lays out the governance model for getting shadow AI under control. Here's what's inside it, and the precondition we think most teams haven't met yet.

PKWARE
PKWARE · Data discovery, classification, and protection wherever your data lives

Someone at your company used an AI tool this week that nobody approved. They pasted something into it to finish faster. You don't know what they pasted, and neither does your SOC.

That's shadow AI. Not a policy violation by a bad actor. A good employee under deadline, reaching for the fastest tool available, because the approved one either doesn't exist yet or takes six weeks to get.

Anyone who's run security awareness knows the pattern. If the right way takes three clicks and the wrong way takes one, people take the one. Not because they've weighed the consequences and accepted them. Because in that moment they aren't thinking about consequences at all. They're thinking about the thing that's due at four o'clock.

And it's not rare. Gartner reports that 69% of organizations suspect or have evidence that employees are using public GenAI tools they aren't permitted to use. Another 52% of organizations suspect or have evidence that employees are building custom GenAI without including cybersecurity risk evaluation

So the honest question isn't how to stop it. It's what happens to your data when you can't.

Key takeaways

  • Shadow AI is unsanctioned use of AI tools inside the business. Gartner reports 69% of organizations suspect or have evidence of employees using public GenAI they aren't permitted to use.
  • The Gartner research lays out a 3A model, agile, adaptive, and AI-ready, built to give security visibility and control back without becoming the department that says no.
  • Agile means fast intake and short approval clocks. Adaptive means pushing approval authority out to the edge instead of routing everything through the CISO.
  • AI-ready means evolving data classification so the rules know which data an AI tool should never touch. That's the pillar that decides whether the other two hold.
  • We believe governance tells you which tools people declared. It doesn't tell you what those tools can reach. Finding and protecting the data is what turns a policy into a control.

What we believe the Gartner research actually delivers

This isn't another piece warning you that AI is risky. You already know that. It's a working model for a security leader who has to move faster than the business is already moving without pretending a ban will hold.

The core argument is that blocking everything backfires. Push hard enough and shadow AI doesn't stop, it just goes invisible: personal devices, personal accounts, nothing your tooling can see. So the play is to make the sanctioned path faster than the workaround. Publish a short amnesty window so people can tell you what they're already using without getting punished for it. Put a five-minute intake in front of every request. Set a clock on the answer. Delegate the low-risk calls to people closer to the work.

There's a rapid triage assessment in the report itself, structured so a requester can complete it in five minutes and a reviewer can route it to the right risk tier without a committee. If you've ever watched an AI request sit in a queue for three weeks while the team that filed it quietly went ahead anyway, that framework is worth the read on its own.

Read the whole thing.

Download the complimentary Gartner report →

Now here's our own take, because there's a piece of this that decides whether any of it works.

Governance gives you a list. It doesn't give you a control.

Run the amnesty program. Stand up the intake form. Delegate the approvals. Do all of it, do it well, and here's what you have at the end: a list of the AI tools people were willing to tell you about.

That list is worth having. It's more visibility than most security teams have today. But it's a self-reported inventory, and it inherits every weakness of self-reporting. It covers the people who participated. It's accurate on the day it was filed. It says nothing about the contractor who onboarded last month, the browser extension nobody thinks of as AI, or the feature your existing SaaS vendor turned on by default in a release note nobody read.

We've seen this movie before with discovery-only data security. You end up with documented, timestamped evidence of a problem and no mechanism to close it. A list of exposures isn't protection. It's a record of what you knew and when you knew it, which is a useful thing to hand a regulator and a terrible thing to rely on.

“A list of exposures isn't protection. It's a record of what you knew and when you knew it.”

The approval question you can't actually answer

Look at what the intake form asks the requester to declare. Highest data class involved. PII, yes or no. Unstructured content like email, documents, chat, transcripts. IP or confidential material.

Now think about who's answering. A marketing analyst. A developer. A finance manager on a deadline. They're being asked to classify data that nobody has ever classified for them.

They'll answer honestly. They'll also answer wrong, because “internal” and “restricted” are labels that only mean something if someone already applied them to the files in question. When a requester says the AI tool will read a SharePoint folder, they're describing a location. They aren't describing what's in it. Nobody in that approval chain knows whether that folder holds meeting notes or fifteen years of customer records that outlived their retention policy.

The report is clear that classification has to evolve for AI, with public and non-sensitive data flowing freely to approved tools and restricted data triggering human review. We agree completely. That's the right design. It's also the pillar with a precondition attached, and the precondition is the hard part: you have to already know where your sensitive data lives, across every environment, including the unstructured content that never got classified in the first place.

Without that, the risk tier on every AI request is a guess wearing a checkbox.

“Without that, the risk tier on every AI request is a guess wearing a checkbox.”

We believe you make the data safe to lose

Here's PKWARE's view. You will not catch every AI tool. Accept that as a starting condition instead of a failure, and the strategy changes.

If you can't guarantee you'll find every unsanctioned tool, then the durable control isn't at the tool layer. It's at the data layer. Find your sensitive data first, across endpoints, Microsoft 365, file shares, data stores, and the mainframe. Classify it, so “restricted” is a fact about a file rather than a guess on a form. Then act on it: encrypt what has to stay readable only to the right people, mask or redact what doesn't need to be exposed at all, and cut the standing access that lets a single compromised account hand an AI tool far more than it ever needed.

Do that, and the shadow AI you never find out about reaches a lot less. The unapproved tool that ingests a file share pulls masked values instead of account numbers. The transcript archive nobody classified isn't sitting there in the clear. Governance goes from a promise about behavior to a control over blast radius.

This is also what makes the sanctioned path fast, which is the whole point of the 3A model. When classification is already in place, the low-risk approval really is a 24-hour decision, because the answer to “what data does this touch” is already known and doesn't require a two-week investigation to produce.

The full picture

Governance and data protection aren't competing answers to shadow AI. They're sequential.

The Gartner research is right that security has to stop being the bottleneck, and the 3A model is a practical way to get there. Read it, and steal the intake structure. Our argument is only about what has to be true underneath it. Fast approvals need classified data. Delegated authority needs the edge decision-maker to have real information, not a self-reported guess. And the tools you'll never inventory need to hit protected data when they arrive.

You can't govern what you can't see. You can't protect what you haven't found. Start there, and the rest of the program has something to stand on.

Download the complimentary Gartner report →

Frequently Asked Questions

What is shadow AI?

Shadow AI is the use of AI tools inside a business without security or governance review. It includes public GenAI services, AI features switched on inside approved SaaS products, browser extensions, and internally built AI applications that never went through a risk assessment. Gartner reports that 69% of organizations suspect or have evidence of employees using public GenAI tools they aren't permitted to use. It's driven mainly by speed, not by malice.

You can't protect what you haven't found.

PKWARE finds sensitive data wherever it lives and protects the data itself, across endpoint, cloud, servers, IBM Z and IBM i, under one policy. Bring us the AI request you can't risk-tier and we'll show you what happens underneath it.

Gartner, “Use Agile, Adaptive, AI-Ready (3A) Data Security Governance to Secure Shadow AI,” Craig Porter, Joerg Fritsch, Meghan Hollis, 1 March 2026.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates.

The views on shadow AI governance and on data-level protection expressed in this article are PKWARE's own and do not represent the opinion or endorsement of Gartner.