Header image

Shadow AI is reshaping enterprise security risk

AI is already embedded in how employees work, from drafting communications to analyzing data. But, as employees turn to unapproved tools outside security and governance controls, enterprise visibility into AI usage is rapidly diminishing. For security leaders, this loss of oversight is quickly becoming an operational risk. 

Lenovo’s latest Work Reborn research, Leading your workforce to AI triumph, highlights a widening gap between how quickly AI is being adopted and how slowly formal oversight is expanding to match. 

The security and operational risk of shadow AI 

Defined as the use of unapproved or unmanaged AI tools and models by employees, outside IT oversight and governance, shadow AI creates blind spots that introduce security and operational risk. This isn’t just unsanctioned usage—it’s a loss of visibility into how data, decisions and workflows are being shaped. 

And it’s a growing problem. Between a fifth and a third of employees are now using AI tools outside IT governance, often through public platforms and consumer-grade services. At scale, this creates a distributed and largely invisible attack surface, where sensitive data and AI-driven decisions are outside the reach of traditional monitoring and controls. 

A two-tier AI workforce is emerging 

In Lenovo’s research, more than one in five employees say their employer doesn’t provide any AI tools, and nearly a third say they receive no AI training at all. When organizations fail to give people sanctioned options and clear guidance, they don’t slow AI adoption, they push it outside the walls of enterprise visibility and into the shadows. 

The result is a structural divide within organizations, creating a two-tier AI workforce: 

  • Those using approved, governed enterprise AI tools, who are supported with at least some level of security oversight. 
  • Shadow AI users working independently with public AI services, exposing sensitive data to opaque models beyond the reach of enterprise visibility and control. 

Because employees are increasingly using AI directly in routine tasks and workflows—often before any formal guardrails exist—this fragmented landscape creates inconsistent processes, uneven protections and a growing surface area for cyber risk. Shadow AI is no longer just a compliance concern, it’s an operational reality that can shape how data moves, how decisions are made and how attackers might exploit new pathways into the enterprise. 

The point is that employees are trying to get work done. If AI tools are not available or if approved AI tools are slow, limited, difficult to access, or poorly integrated into workflows, they'll look elsewhere. 

Employees are worried and looking to security for reassurance 

Lenovo’s research suggests many workers worry about where their data goes, who has access to it and what AI-generated outputs might get wrong. And these concerns cannot be addressed with a single awareness campaign or an annual compliance module.  

As organizations encourage employees to use AI more often, they also need to show that approved AI tools are secure, governed and fit for everyday work. This matters because employees are handling business data and customer information through AI-enabled workflows. 

Three-quarters say they would feel more confident if they received better cybersecurity training focused specifically on AI-related risks. Almost as many say they would be reassured if cybersecurity teams themselves used AI to counter AI-enabled threats.  

That finding doesn’t mean employees are focused on how security teams operate day to day. It suggests they want to feel confident that the organization is taking AI risk seriously. For security leaders, the task is to make approved AI use easier to trust than unmanaged alternatives. 

Security cannot sit outside the AI-powered employee experience 

As AI becomes a fixture of everyday work, security cannot operate as a separate function that occasionally “checks in” on employees. Without embedded controls and guidance, employees will continue to make risk decisions independently and beyond visibility. AI security must be part of the workflow itself: contextual guidance, in-the-moment controls, and protections that travel with the data wherever it goes. 

When security measures feel bolted on or get in the way of productivity, people will look for workarounds. But if AI is used to automate the safest path—flagging risky behaviors, suggesting compliant alternatives and quietly enforcing policy in the background—security becomes a critical enabler. 

Three priorities to increase visibility and control 

Lenovo’s Work Reborn research points to a practical roadmap for security and technology leaders who want to bring AI out of the shadows without stifling its benefits. 

1. See more to secure more 

The starting point is simple: you cannot secure what you cannot see. AI introduces new visibility gaps across tools, workflows and data flows. As shadow AI usage expands beyond traditional security parameters, it’s even more critical that organizations have better visibility into where, how and by whom AI is being used. 

That means: 

  • Instrumenting networks and endpoints to detect AI traffic and usage patterns, not just known tools. 
  • Mapping sanctioned and unsanctioned AI tools across the business. 
  • Setting clear, accessible policies that spell out which tools are approved, which are not, and why. 

2. Enable safe behavior 

Once visibility improves, the next priority is guiding usage to build employee confidence that they can use AI safely, achieving their work goals within approved guardrails. 

Security teams should: 

  • Make safe AI use part of day-to-day work, not an abstract concept discussed once a year. 
  • Embed guidance and training into workflows, surfacing prompts, reminders and short scenario-based guidance at the moment of risk.  
  • Communicate how approved AI tools are configured, what data they can and cannot access, and how outputs are monitored. 

3. Operationalize AI in security 

The same capabilities that make AI attractive to attackers—speed, scale and adaptability—can be powerful force multipliers for defenders. 

Security leaders should explore how AI can defend AI environments by: 

  • Detecting anomalies in data flows that may indicate shadow AI usage or data exfiltration. 
  • Correlating signals across endpoints, identities and applications to spot AI-enabled attacks earlier. 
  • Supporting faster, more informed security decisions by summarizing intelligence and recommending actions.  

From restriction to secure enablement 

The overarching message from Lenovo’s Work Reborn research is clear: the future of enterprise AI security will be shaped less by restriction and more by secure enablement. 

For security leaders, the challenge now is to create environments where: 

  • Employees trust the AI tools provided to them. 
  • Governance is easy to understand and visibly enforced. 
  • Training is integrated into the flow of work. 
  • AI is embedded naturally into everyday processes, with security built in from the start.  

The risk is no longer whether employees will use AI, it’s whether organizations can see and guide that usage. Those that succeed will not be the ones that restrict AI, but those that make it visible, governed, and built into everyday work. 

How Lenovo can help 

Lenovo is already helping its customers ensure secure and compliant AI adoption by providing visibility into AI usage, preventing data leakage and misuse, and enforcing policy-driven guardrails across the enterprise. Some of the key features of Lenovo’s services are: 

  • Eliminating blind spots and gaining visibility of AI risk surface. 
  • Driving safe AI usage through approved AI tools while preventing unsanctioned apps. 
  • Preventing data breaches by blocking confidential data exposure to third-party AI models. 
  • Supporting regulatory investigations with complete AI audit trails. 
  • Providing frictionless AI experiences to enterprise users through invisible privacy enforcement. 

To dive deeper into the data, explore sector-specific insights and see how leading organizations are preparing their workforce for secure, scalable AI adoption, read the full Lenovo Work Reborn report, Leading your workforce to AI triumph.

Brought to you by:

Rakshit Ghura
Rakshit Ghura Vice President and General Manager of Digital Workplace Solutions Lenovo

Rakshit Ghura is the Vice President and General Manager of Digital Workplace Solutions (DWS) at Lenovo, where he leads the company’s strategic initiatives in the digital workplace and cybersecurity domains.

In this role, Rakshit is instrumental in shaping Lenovo’s vision for the future of work, focusing on areas such as workplace mobility, Device as a Service, Persona-based configuration, automation,analytics, employee experience, and collaboration, with a strong emphasis on consulting and advisory services.

Prior to joining Lenovo, Rakshit served as the Senior Vice President and Global Head of Digital Workplace Services & ServiceNow business at HCLTech. 

During his tenure, he was responsible for defining, incubating, and creating the product roadmap and strategy for digital workplace services.Rakshit is a recognized thought leader in the industry, frequently sharing insights on the impact of Generative AI, the evolution of the hybrid workplace, and the importance of unifying people, culture,and technology to redesign the future of work. He has contributed to various industry discussions, including podcasts and whitepapers.

Rakshit Ghura
Rakshit Ghura Vice President and General Manager of Digital Workplace Solutions Lenovo

Rakshit Ghura is the Vice President and General Manager of Digital Workplace Solutions (DWS) at Lenovo, where he leads the company’s strategic initiatives in the digital workplace and cybersecurity domains.

In this role, Rakshit is instrumental in shaping Lenovo’s vision for the future of work, focusing on areas such as workplace mobility, Device as a Service, Persona-based configuration, automation,analytics, employee experience, and collaboration, with a strong emphasis on consulting and advisory services.

Prior to joining Lenovo, Rakshit served as the Senior Vice President and Global Head of Digital Workplace Services & ServiceNow business at HCLTech. 

During his tenure, he was responsible for defining, incubating, and creating the product roadmap and strategy for digital workplace services.Rakshit is a recognized thought leader in the industry, frequently sharing insights on the impact of Generative AI, the evolution of the hybrid workplace, and the importance of unifying people, culture,and technology to redesign the future of work. He has contributed to various industry discussions, including podcasts and whitepapers.

Upcoming Events

No events found.