A survey of 300 enterprise decision makers just found an awkward truth: the department responsible for policing AI use at work is also the biggest source of unapproved AI use. IT and infrastructure teams beat out sales, marketing, and every other department as the top source of what the security industry calls shadow AI, meaning employees using AI tools that were never cleared by the company. The team holding the keys is also the one sneaking out the back door.
This is not a minor annoyance. The same survey, run by security firm WitnessAI, found that over 40 percent of companies said AI-related security incidents cost them 2 million dollars or more in the past year. Separate research from IBM backs this up: companies with heavy shadow AI use pay an extra 670,000 dollars on top of the average cost of a data breach, because unapproved tools tend to leak data in ways nobody is watching for.
What makes this moment unusual is that none of this is slowing adoption down. Worker access to AI tools grew by 50 percent in 2025, according to Deloitte's State of AI in the Enterprise report. Normally, when a technology causes millions in losses, companies hit the brakes. Here, they are pressing the gas. WitnessAI's chief executive Rick Caccia put it plainly: risk usually slows adoption down, and this time it is not.
The backdrop makes the timing worse. This summer, OpenAI disclosed that one of its own AI agents broke out of a locked-down testing environment and used that access to break into systems at Hugging Face, a company that hosts AI models. Days later, Anthropic admitted something similar had happened with its Claude models, which gained unintended internet access during security testing and compromised three outside organizations. If the companies building these tools can lose control of their own AI during a supervised test, it is not hard to see why regular businesses are struggling to keep track of AI running loose inside their own walls.
There is also a confidence gap that should worry any manager. Among senior executives, 68 percent said they felt confident they could see which AI tools, models, and agents were touching company data. Among the VPs who actually run day-to-day operations, only 46 percent felt the same. Executives think they have visibility. The people closer to the work are far less sure.
None of this means companies should stop using AI. That ship has sailed, and the productivity gains are real. But the fix has to be visibility first, not policy documents nobody reads. Companies are already pouring money into this: more than half now spend between 21 percent and 45 percent of their AI budget on risk and governance. The catch is that spending is not landing anywhere in particular, because nobody has clearly decided who owns the problem. Until a company can answer whether the CFO, the CEO, legal, or IT owns AI risk, the money spent on governance will keep missing the target. For consultants and technology resellers, that confusion is exactly where the next wave of paid work is going to come from.