Shadow AI Often Emerges Due to Governance Itself
Shadow AI is already a reality-and often emerges because of governance itself. In an interview with SecurityToday, Patricia Leppert, Team Manager of Customer Trust & Safety at TeamViewer, explains how approval hurdles push employees toward unofficial AI tools. According to a TeamViewer survey, about 40 percent of employees circumvent official tools because the approved technology doesn’t work for them.
Key Takeaways
- Shadow AI is avoidance behavior. Approved AI tools that don’t fit, are difficult to use, or are unfamiliar push employees toward personal devices and public services.
- 40 percent have already bypassed official tools. In a global TeamViewer survey, 40 percent of employees admitted to using workaround solutions because the technology provided at work didn’t meet their needs.
- Governance can create detours. Password resets and patches at the wrong time, approval bottlenecks, and authentication loops turn security into a barrier.
- The safest path must be the easiest. Security-by-design, usable alternatives, AI ambassadors, and training-rather than outright bans-are key.
Related: Five line items you need before your SIEM budget · What management must document under NIS2
What Is Shadow AI?
What Is Shadow AI? Shadow AI refers to the use of unauthorized AI tools or services as a workaround-such as on personal devices or via publicly available platforms-because the officially provided technology doesn’t fit, is difficult to use, or is unfamiliar. This leaves security teams without control over data processing, storage, and further use. The interview with Patricia Leppert contextualizes the phenomenon and highlights the governance barriers driving employees to take such detours.
Leppert views Shadow AI not as malicious side behavior but as a reality of modern work. Deadlines, client responses, and project pressure push employees toward public services, often without any intent to endanger data.
Workarounds Instead of Policy Violations
SecurityToday: Ms. Leppert, what does Shadow AI look like in the day-to-day work of a company?
Patricia Leppert: Most large companies today have a policy that specifies which AI tools are approved for employees. However, if these approved tools don’t align well with tasks, are difficult to use, or are simply unknown, employees turn to alternative solutions. They may resort to using their personal devices or leveraging freely available AI platforms or services online. That’s Shadow AI. In a global survey by TeamViewer, 40 percent of employees admitted to having used such workarounds because the technology provided at work didn’t meet their needs.
of employees have already used workaround tools because the approved technology at work failed to meet their needs
Source: TeamViewer global survey, 2026
SecurityToday: How can a security team detect when employees are using AI tools outside official channels?
Patricia Leppert: My view is that Shadow AI is a reality in most companies today, though its extent varies. The survey I mentioned earlier confirms this. However, I’m not a fan of workplace surveillance practices. Instead, our role as a security team is twofold: First, we must raise awareness among employees about the risks associated with Shadow IT. People are more likely to follow security guidelines when they understand the reasons behind them. Second, we need to ensure that the approved AI tools are practical, accessible, and user-friendly. For security teams, this means cybersecurity should never become a barrier to adopting AI tools.
When Governance Becomes a Detour
SecurityToday: Shadow AI often emerges precisely because of governance itself. What barriers push departments toward unofficial tools?
Patricia Leppert: The role of security is to protect a company. However, if it creates too many workflow interruptions, it’s perceived as an obstacle-pushing employees out of secure environments and ultimately making the company even less secure. Common barriers include password resets or forced patches at the wrong moment, overly complex approval processes, endless authentication loops, or a locked-down platform that turns a simple task into an unnecessarily complicated ordeal. When time-sensitive projects are on the line, the temptation to switch to a readily available AI tool on the open internet becomes overwhelming. This isn’t done with malicious intent-in fact, employees are simply trying to meet a deadline, respond to a customer, or advance a project.
Data Leakage, Fake AI, and Unverified Outputs
SecurityToday: What happens when employees input sensitive content into unauthorized AI services?
Patricia Leppert: The company then loses control over how that data is processed, stored, or reused. This becomes particularly critical with financial and customer data, source code, or internal roadmaps. A common fraud phenomenon is fake AI-websites or apps that pose as high-performance AI tools or image generators but actually steal data. It is a key responsibility of the security team to transparently inform employees about these risks.
SecurityToday: Where does shadow AI truly become dangerous-from data leakage to compliance violations and hallucinations?
Patricia Leppert: All of these risks pose a danger to the company in different ways. If confidential information leaks, it harms the business-potentially even leading to legal liability, such as when customer data is exposed. Compliance violations are especially relevant for employees who use shadow AI. Regarding incorrect results and hallucinations, companies can take action by training their staff accordingly. Outputs from generative AI should never be adopted without verification-this applies even to results from approved AI tools. Additionally, using unauthorized AI services can violate regulatory or contractual obligations if data processing or storage methods are not traceable.
Security That Fits Seamlessly into Your Workflow
SecurityToday: What does a secure yet user-friendly alternative look like in day-to-day work?
Patricia Leppert: The control mechanisms must integrate naturally into workflows. They should enable productivity without disrupting the process. When security feels intuitive, employees are far more likely to adopt it. Authentication is a prime example. Passwords have long frustrated employees while remaining a well-known vulnerability exploited in many cyberattacks. Approaches like Zero Trust and biometric authentication can enhance protection while improving usability. The strongest controls are often those that remain nearly invisible to users-because that’s when they gain widespread acceptance.
The safest path must also be the simplest.
Governance as a Shared Responsibility
SecurityToday: How can organizations structure AI governance so that Security, IT, and business units all get on board?
Patricia Leppert: With a security-by-design approach, many processes-such as authentication-can be seamlessly integrated into AI workflows. This requires Security teams to be involved from the very beginning. However, many other teams also play a role in AI governance. At TeamViewer, for example, alongside Security, departments like Legal, Data Protection, and Training are all involved. Additionally, we’ve trained one or more AI Ambassadors in every team to serve as direct points of contact for colleagues. There’s a centralized overview of approved AI tools and which teams are authorized to use them. We also conduct regular training sessions on proper AI usage to ensure all employees stay up to date. Our goal is to enable the secure and responsible use of AI across the entire company. Relying solely on control measures isn’t enough.
SecurityToday: Who needs to be at the table-and what’s the most common stumbling block?
Patricia Leppert: Beyond cybersecurity implications, the use of shadow AI signals to leadership that the provided tools are inadequate, mismatched to tasks, overly complex, or simply unknown. The focus should therefore be on identifying and removing these barriers. This is a shared responsibility among Security, IT, business units, and management.
SecurityToday: How does the role of Security teams evolve when AI becomes part of everyday work?
Patricia Leppert: The role of Security teams is shifting from a predominantly controlling function to one that is advisory and enabling. Security must understand how employees actually use AI, identify risks early, and provide secure solutions that integrate seamlessly into daily workflows. The emphasis is less on prohibitions and more on enabling innovation safely.
SecurityToday: If a CISO were to take one thing away from this interview and change immediately, what should it be?
Patricia Leppert: If you want to reduce AI risks, start by ensuring employees can actually use secure, approved alternatives. The most effective AI governance combines security and productivity-not by adding more hurdles, but by making the safest path the easiest one.
The conversation highlights concrete levers Security teams can pull without needing a new tool portfolio. The checklist below distills the operational steps from Leppert’s answers for the next CISO stand-up.
CISO Checklist from the Interview
- ✓Review approved AI tools for suitability, awareness, and usability
- ✓Scan approval and authentication processes for unnecessary friction
- ✓Educate employees transparently about data risks and fake AI
- ✓Involve Security from the outset in AI workflows (security by design)
- ✓Bring together Legal, Data Protection, Training, and AI Ambassadors at the table
While this list doesn’t replace a full governance program, it highlights where unnecessary friction drives employees toward unofficial AI services-and where security-by-design can realign productivity with control.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What is Shadow AI as opposed to Shadow IT?
Shadow AI refers to the use of unauthorized AI tools or services as a workaround—often on personal devices or public platforms. The mechanism mirrors Shadow IT: when official channels fall short, users find alternative routes.
Why does Shadow AI emerge despite existing policies?
Because released tools don’t fit the task, are hard to use, or are unfamiliar. On top of that, approval bottlenecks, authentication loops, and untimely interruptions push users toward makeshift solutions.
Which data are particularly critical when using unofficial AI services?
Financial and customer data, source code, and internal roadmaps. The company loses control over how this data is processed, stored, or repurposed.
Is a ban and surveillance the right response?
Patricia Leppert opposes workplace surveillance practices. More effective, she argues, is raising awareness of risks alongside approved alternatives that are practical and easy to use.
What should be the first step for CISOs?
Ensure that secure and approved alternatives are actually usable. The most effective AI governance balances security and productivity—the safest path must also be the simplest.
Lesetipps der Redaktion
LesetippFünf Posten, die vor dem SIEM Budget brauchenLesetippWas die Geschäftsführung unter NIS2 dokumentieren mussLesetippBitLocker-Bypass bei physischem Zugriff
Mehr aus dem MBF Media Netzwerk
cloudmagazinShadow AI verbieten: der teuerste IT-Security-ReflexMyBusinessFutureDie KI-Aufsicht in Deutschland hat jetzt eine AdresseDigital ChiefsDie Rechnung für zehn Jahre Insellösungen






