
A Pattern Repeating Across Every Sector
From interns to boardrooms, artificial intelligence is being adopted at skyrocketing rates across private and public institutions. Across finance, healthcare, government, and energy, the same pattern is repeating: employees are connecting sensitive data to unsanctioned AI tools, often without the knowledge of IT or security teams. 1
Recent research by Lenovo suggests roughly one in three employees use AI tools with no IT oversight 2. This phenomenon is called ‘Shadow AI’, and for institutions operating under Saudi Arabia’s data protection and cybersecurity frameworks, ignoring it may come with consequences.
The Governance Gap Behind the Numbers
A survey by IBM published in 2026, puts the share of organizations with a formal AI governance policy at just 37% 1, even as IT leaders in a separate Lenovo report say that rising concern: 61% now say AI is increasing their organization’s cybersecurity exposure, and barely a third feel confident in their ability to manage that risk. What does this look like in practice? Consider a finance team drafting a report for an unreleased earnings update, using a public AI tool to “clean up the wording,” unaware that the platform may retain that input. Or an HR department uploading employee records to summarize a new policy, with no record afterward of where that data went. These are the ordinary, well-intentioned tasks that fill most working days, the problem is that none of them are visible to the people responsible for protecting the organization’s data.
From Chatbots to Autonomous Agents: A Risk That’s Multiplying
And the risk is now multiplying. For the past two years, the dominant concern was what employees might type into a chatbot, now a newer one is overtaking it: what autonomous AI agents are permitted to do without anyone watching. In a survey of security leaders conducted by VentureBeat earlier this year, unauthorized tool or data access was consistently ranked the single most feared AI agent failure mode, with concern climbing to 50% 3.
Industry data on breaches involving shadow AI shows they cost organizations roughly $200,000 more on average than standard incidents, and take nearly a week longer to identify and contain 4. When an agent, not a person, is the one moving data, the usual warning signs like a strange email or a misdirected file, often never appear at all.
A Sovereignty Question for Saudi and Gulf Institutions
For Saudi and broader GCC institutions, this is a sovereignty conversation as well. Under the Kingdom’s Personal Data Protection Law and the National Cybersecurity Authority’s frameworks, organizations are accountable not just for keeping data safe, but for knowing exactly where it resides and who, or what, can access it.
The Fix: Infrastructure and Architecture
None of this is an argument for restriction; organizations that try to block AI outright tend to discover that employees simply route around the ban, often making the problem less visible rather than less real.
The more durable fix is infrastructure, and it works as two parts that depend on each other rather than two fixes operating in isolation.
Visibility: Seeing What’s Already Happening
The first is visibility. Most leadership teams significantly underestimate how much AI activity is actually happening inside their organization until they look closely. Security teams running detailed audits in 2026 have repeatedly found far more activity than expected: one organization believed it had a little over a hundred AI agents running; once properly audited, the real number was over 500. Most of this activity moves over standard, encrypted web traffic to legitimate-looking cloud services, which is exactly the kind of traffic conventional monitoring tools are built to ignore.
Architecture: Governance That Lives Inside the System
The second is architecture. Even a perfect audit only describes a single moment. Agentic systems change weekly: new tools get adopted, integrations get approved, permissions get granted, often by employees who don’t see a valid reason to report any of it. A governance policy written after this year’s audit will be out of date well before next year’s. What is needed instead is governance that lives inside the infrastructure itself, and adapts continuously, rather than something inspected periodically from the outside.
In practice, this means two things: First, inference needs to run locally on infrastructure the organization, or a trusted in-country provider, directly controls. A government department processing citizen applications through AI, for example, should be able to confirm that every request is handled on infrastructure physically located inside the Kingdom, not routed through a data center it has no visibility into. Second, every interaction needs to be observable in real time, not reconstructed after the fact. IT and security teams should be able to see, on any given day, exactly which tools are active, what data they are touching, and who is using them the same way a bank can see every transaction moving through its systems as it happens, rather than waiting for a monthly statement.
Closing the Gap Between Policy and Practice
Shadow AI is a sign that the sanctioned alternatives on offer by IT teams don’t match the needs and use cases of the employees or are restricting functionality. Closing that gap is an infrastructure decision that determines whether an organization can say, with confidence, where its data lives and who can reach it.
In today’s world, AI management platforms can fix these challenges by providing teams with sanctioned access to agents through a controlled and vetted environment that is already built with the necessary data protection and access guardrails in place, and with the observability parameters needed to grant employees more freedom of exploration within a safer space. Ideally, that same platform is built for hybrid deployment — running across on-premises, cloud, and edge environments while keeping every workload under one governed control plane — both fixes converge in one place, giving institutions the access employees need and the control regulators require, regardless of where any given workload runs.
References
- Vectra AI — Shadow AI explained: risks, costs, and enterprise governance (May 2026)
- Lenovo — Work Reborn Report (September 18, 2025)
- Venturebeat — The enforcement gap: 88% of enterprises reported AI agent security incidents last year (April 17, 2026)
- IBM — Cost of a Data Breach Report (August 12, 2025)



