
AI agents have become deeply embedded in the operations of everyday business. From streamlining workflows to enhancing decision-making, they offer valuable efficiencies and contribute to reducing operational costs. Yet, despite these benefits, a concerning pattern is emerging. While senior executives feel confident about how AI is governed, their employees are quietly bypassing official channels in favour of unapproved tools. This creates a substantial security blind spot that must be addressed.
A false sense of security
According to Okta’s 2026 AI Agents At Work report, most UK executives (96%) believe they have full visibility into how AI tools are managed. The reality is quite different, with more than half of UK employees (55%) using unsanctioned AI tools, often without their leaders’ knowledge.
This gap isn’t just statistical; it is cultural. Leaders place their trust in official security systems, while employees prioritise efficiency, choosing convenience over strict compliance.
Not so long ago, software was deterministic, its behaviour was both predictable and transparent. Today, that simplicity has been superseded by rapid change and technological innovation. Anyone can create an AI agent, and agents can generate further agents, each connecting across apps, APIs, SaaS tools, and data systems. Enterprises are essentially dealing with countless “black box” entities operating at machine speed, often benefitting from privileged access that allows them to bypass the security safeguards built for humans.
When leadership is overly confident in their oversight, vulnerabilities multiply. This is not a theoretical threat either as globally, 58% of organisations have experienced AI-related security incidents in the past year alone.
The unmanaged threat of shadow AI
Shadow AI usage is the symptom of a deeper problem. Employees, frustrated by slow approval processes and unclear policies, turn to tools to get their work done, even if it means feeding agents sensitive company and personal data.
100% of the knowledge workers Okta surveyed employ AI in some capacity. As it stands, there is a wide array of tools in use, ranging from chatbots and writing assistants to browser extensions, coding agents and other industry-specific utilities. The commonality between all these tools is their need for data and, in many cases, access to an organisation’s internal systems.
Of those employees using unapproved AI tools worldwide, over half (54%) share internal messages and emails, 45% share HR-related information, and 39% share confidential company documents. Once these tools begin autonomously transferring files and retaining long-term memory of previous interactions, organisations must question where that information ultimately resides.
The danger extends well beyond data leakage. Workers are granting these tools direct access to critical internal systems, including email, cloud storage, collaboration tools and CRM databases. If a breach occurs, the potential impact is huge. The productivity gains are clear, but without official oversight, AI agents quickly become the weakest link in the security chain.
Falling behind on governance
Governance frameworks simply have not kept pace with the speed of AI adoption. While 65% of UK executives say their AI policies are very clear, 57% of knowledge workers disagree, finding the rules confusing or non-existent. Worse still, only 34% of said organisations enforce the same security controls for AI agents as they do for human employees. That double standard is more than just a technical flaw; it is a strategic failure that allows AI agents to move laterally across systems, amplifying the damage of any breach.
Interestingly, this confidence gap is particularly pronounced in the UK. Okta’s survey shows that employees In France and Germany are far less likely to use unapproved AI, meaning their executives’ optimism aligns closer to reality. In the UK, however, leaders remain disconnected from how their teams actually operate.
If British businesses fail to bridge this divide, they risk falling behind on both innovation and security. Enterprises must understand why 78% of staff using shadow AI view it as standard practice, and more importantly, how to properly secure the tools their workforce clearly needs.
Rethinking the AI Blueprint
The enterprise stands at a turning point. 53% of enterprises organisations globally now have an established AI deployment strategy. However, inconsistent identity controls and the ongoing disconnect between leadership and employees continue to expose businesses to unnecessary risk.
Resolving this requires a fundamental shift in approach. Rather than relying on rigid restrictions, organisations need practical, enabling governance. Secure AI use must become the path of least resistance. If approved modern tools are readily available and integrated smoothly into daily work, employees will not feel the need to bypass official channels. Achieving this requires investing in education, maintaining transparent communication, and rewarding responsible data handling.
Above all, organisations must be able to answer three essential questions: Where are our agents? What can they connect to? What can they do? By establishing clear accountability, businesses can transform their current blind spot into a robust blueprint for secure innovation.



