Businesses are struggling to keep track of how artificial intelligence is being used across their organizations as AI tools and features spread through workplace software.
According to Bitdefender’s 2026 Cybersecurity Assessment, 51.8% of IT and cybersecurity professionals said their organizations have full visibility into approved and unauthorized AI use. However, 47.4% reported having only partial or no visibility into shadow AI tools or personal AI accounts being used for work.
The research surveyed 1,200 IT and cybersecurity professionals at organizations with at least 500 employees across parts of Europe, Singapore, and the US.
Bitdefender argues that AI visibility is becoming an ongoing governance issue rather than a one-time inventory exercise, particularly as AI capabilities continue to appear inside software businesses already use.
Bitdefender also found a notable difference between managers and frontline security professionals. Some 57.8% of managers said they had full visibility into workplace AI use, compared with 45.9% of practitioners.
The findings highlight a growing challenge for businesses as AI becomes embedded in browsers, productivity software, development tools, meeting platforms and other workplace applications.
This makes shadow AI harder to identify than simply tracking employees who use standalone services such as ChatGPT. Workers may also use personal AI accounts for tasks involving documents, source code, emails or other corporate information without going through normal security approval processes.
As AI adoption expands, companies need to revise policies covering which tools employees can use, what information can be shared with AI services and how newly added AI features are reviewed.

Leave a Reply