Complimentary Gartner Research

Your data is already in an AI tool you never approved.

You just don't know which data. Get The Gartner® Report: Use Agile, Adaptive, AI-Ready (3A) Data Security Governance to Secure Shadow AI, and see how security leaders are getting visibility back without becoming the department of no.

Cover of the Gartner report, Use Agile, Adaptive, AI-Ready (3A) Data Security Governance to Secure Shadow AI
Get the complimentary report.

The full 9-minute read, sent the moment you submit.

2026 Gartner Shadow AI
Why now

Blocking AI didn't stop it. It made it invisible.

Most security teams responded to GenAI the way they've responded to every new tool category. Restrict it, review it, approve it slowly. It worked exactly as well as you'd expect. The business moved anyway, on personal devices, personal accounts, and browser tabs nobody logged.

So the shadow AI problem isn't really an AI problem. It's a question about your data. Every prompt someone types is a file, a record, or a customer detail leaving a place you controlled and landing somewhere you don't. The tool is visible or it isn't. The data underneath it is the part that carries the risk, and that part was exposed before anyone opened a chat window.

What's inside

A way to say yes without losing control

The Gartner Report: Use Agile, Adaptive, AI-Ready (3A) Data Security Governance to Secure Shadow AI, by Craig Porter and Joerg Fritsch, makes a case most security leaders will recognize. Governance that moves slower than the business doesn't reduce risk, it just relocates it somewhere you can't see. The report lays out an agile, adaptive, and AI-ready model for data security governance, including how to get unsanctioned AI use on the record, how to move approvals fast enough that people stop routing around them, and how to evolve classification and controls for AI-specific risk.

If you own the AI conversation at your organization, or you're about to inherit it, this is the analyst's view of what the operating model needs to look like.

Where to start

You can't tag what you never found

The report is clear that AI-readiness has to reach the data itself. Classification schemes need to say what AI can touch and what it can't, and unstructured data carries the most risk. That's the right call. It's also where most programs stop, because the tagging exercise assumes you already know where the data is.

Most organizations don't. That's the first job, not the last one.

01

Find it

Every place sensitive data lives, across endpoint, cloud, and mainframe. Not a sample. The whole estate.

02

Classify it

Tag what's restricted, what's approved for AI, and what needs a human in the loop before anything reaches a model.

03

Protect it

Encrypt, mask, or redact the restricted data so the wrong record can't be pasted into a prompt in the first place.

Discovery without protection is just a list of problems. PKWARE fixes them.

Get the report. Your data's already moving.