TrustedTech research found a widening gap between AI adoption and enterprise governance, with 87% of IT and telecom workers saying they are confident using AI effectively even as 68% expressed concern about shadow AI.
For MSPs and technology partners, that disconnect is creating an opportunity to help customers put governance, security and approved AI alternatives in place without slowing employee adoption.
AI adoption is moving faster than governance
The findings point to a challenge that TrustedTech VP of Technology Andy Nolan sees playing out as employees adopt AI faster than their organizations can establish formal strategies around its use.
Technically experienced workers, he said, may understand the security and data risks associated with AI while still seeing enough productivity value to use the technology anyway.
“When someone knows an AI tool can save them hours of work, simply knowing there is risk associated with that use may not be enough to stop them from using it,” Nolan said, particularly when employers have not provided an approved alternative offering comparable value.
Shadow AI reflects an organizational readiness gap
For that reason, Nolan said he sees shadow AI less as an employee behavior problem and more as an organizational readiness issue.
Employees can begin experimenting with a new AI tool within minutes, while organizations need considerably more time to address identity, data access, security, compliance, acceptable-use policies, governance, and training.
“We’re seeing organizations where AI adoption has effectively started from the bottom up before leadership has established a formal strategy from the top down,” Nolan said.
That leaves some businesses trying to establish controls after employees have already found AI use cases and incorporated the technology into their workflows.
Instead of attempting to reverse AI adoption, Nolan said organizations can use existing use cases to understand where employees find value and build a more intentional AI strategy around them.
Industry-specific risks complicate AI governance
TrustedTech’s research also suggests shadow AI concerns extend well beyond the technology sector. After IT and telecom, manufacturing and utilities reported the next-highest level of concern at 53%, followed by finance at 52%.
Nolan said that while organizations across these industries face a common underlying concern, the risks are not necessarily the same.
“The fundamental concern is similar across industries, which is losing visibility and control over where organizational data is going, but the consequences can be very different,” Nolan said.
For financial organizations, unapproved AI use can involve sensitive customer and financial information, as well as regulatory, auditability, and data-lineage requirements. TrustedTech’s research also found that 48% of finance respondents said their organizations lack adequate training on using AI safely and securely.
Manufacturing and utilities face a different mix of risks, with AI potentially interacting with intellectual property, engineering data, operational technology, supply chain information, proprietary processes, and critical infrastructure.
“That’s why I don’t believe AI governance can be treated as a simple blanket policy exercise,” Nolan said.
“Organizations need to understand their data, regulatory environment, business processes, and actual employee use cases, then build controls around the risks that matter most to their environment.”
Training and guardrails alone may not stop shadow AI
Training is another part of the problem. Across TrustedTech’s broader research, 44% of employees said their organization lacks training on using AI tools safely and securely, while only 23% said they learned most of their AI skills through employer-provided training.
“Too much AI guidance is still focused on what employees shouldn’t do instead of teaching them how to use AI effectively and safely,” Nolan said.
That means AI training needs to go beyond simply warning employees against sharing sensitive information. Nolan said workers also need practical guidance around approved tools, sensitive data, how AI platforms handle information, and when AI-generated outputs should be validated.
Technical controls present a similar challenge.
Organizations can use identity management, permissions, data classification, data loss prevention, application access controls, and monitoring to limit AI-related risks. However, Nolan cautioned that controls alone may not be sufficient if employees lack an approved alternative that meets their needs.
“If the approved experience creates significantly more friction than the tool an employee can access on their own in thirty seconds, you’re creating the conditions for Shadow AI,” Nolan said.
“The objective shouldn’t be to block AI. It should be to create an environment where the easiest way for employees to use AI is also the safest way.”
MSPs can take a broader role in AI governance
For MSPs and other technology partners, Nolan sees shadow AI as a problem that increasingly cuts across areas they may already manage for customers.
“This is where the role of the partner is becoming much more strategic,” Nolan said.
“Most organizations don’t need another vendor simply telling them which AI product to buy. They need help understanding what is already happening inside their environment, where their data and security risks exist, what capabilities they already own, and how to build a practical roadmap from where they are today.”
Nolan specifically pointed to Microsoft partners, which can help connect areas that organizations often manage separately, including licensing, identity, security, data governance, Microsoft 365, Copilot, cloud architecture, adoption, and ongoing management.
Because shadow AI cuts across these areas, Nolan said treating it solely as a security project can be difficult and inefficient.
“For organizations without dedicated AI governance teams, a partner can effectively help provide that framework,” Nolan said. “That starts with assessing readiness and identifying risk, but it should ultimately lead to secure deployment, governance, employee enablement, monitoring, and continuous optimization.”
The longer-term goal, Nolan said, is not simply to eliminate shadow AI, but to reduce employees’ reasons to turn to unapproved tools in the first place.





