TrustedTech: Shadow AI Exposes Enterprise Governance Gaps

TrustedTech research finds AI adoption is outpacing governance, creating shadow AI risks and new opportunities for MSPs to guide secure deployment.

Written By
Luis Millares
Luis Millares
Sep 15, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

TrustedTech research found a widening gap between AI adoption and enterprise governance, with 87% of IT and telecom workers saying they are confident using AI effectively even as 68% expressed concern about shadow AI. 

For MSPs and technology partners, that disconnect is creating an opportunity to help customers put governance, security and approved AI alternatives in place without slowing employee adoption.

AI adoption is moving faster than governance

The findings point to a challenge that TrustedTech VP of Technology Andy Nolan sees playing out as employees adopt AI faster than their organizations can establish formal strategies around its use. 

Technically experienced workers, he said, may understand the security and data risks associated with AI while still seeing enough productivity value to use the technology anyway.

“When someone knows an AI tool can save them hours of work, simply knowing there is risk associated with that use may not be enough to stop them from using it,” Nolan said, particularly when employers have not provided an approved alternative offering comparable value.

Shadow AI reflects an organizational readiness gap

For that reason, Nolan said he sees shadow AI less as an employee behavior problem and more as an organizational readiness issue.

Employees can begin experimenting with a new AI tool within minutes, while organizations need considerably more time to address identity, data access, security, compliance, acceptable-use policies, governance, and training.

Advertisement

“We’re seeing organizations where AI adoption has effectively started from the bottom up before leadership has established a formal strategy from the top down,” Nolan said.

That leaves some businesses trying to establish controls after employees have already found AI use cases and incorporated the technology into their workflows.

Instead of attempting to reverse AI adoption, Nolan said organizations can use existing use cases to understand where employees find value and build a more intentional AI strategy around them.

Industry-specific risks complicate AI governance

TrustedTech’s research also suggests shadow AI concerns extend well beyond the technology sector. After IT and telecom, manufacturing and utilities reported the next-highest level of concern at 53%, followed by finance at 52%.

Nolan said that while organizations across these industries face a common underlying concern, the risks are not necessarily the same.

“The fundamental concern is similar across industries, which is losing visibility and control over where organizational data is going, but the consequences can be very different,” Nolan said.

For financial organizations, unapproved AI use can involve sensitive customer and financial information, as well as regulatory, auditability, and data-lineage requirements. TrustedTech’s research also found that 48% of finance respondents said their organizations lack adequate training on using AI safely and securely.

Manufacturing and utilities face a different mix of risks, with AI potentially interacting with intellectual property, engineering data, operational technology, supply chain information, proprietary processes, and critical infrastructure.

“That’s why I don’t believe AI governance can be treated as a simple blanket policy exercise,” Nolan said.

“Organizations need to understand their data, regulatory environment, business processes, and actual employee use cases, then build controls around the risks that matter most to their environment.”

Training and guardrails alone may not stop shadow AI

Training is another part of the problem. Across TrustedTech’s broader research, 44% of employees said their organization lacks training on using AI tools safely and securely, while only 23% said they learned most of their AI skills through employer-provided training.

“Too much AI guidance is still focused on what employees shouldn’t do instead of teaching them how to use AI effectively and safely,” Nolan said.

Advertisement

That means AI training needs to go beyond simply warning employees against sharing sensitive information. Nolan said workers also need practical guidance around approved tools, sensitive data, how AI platforms handle information, and when AI-generated outputs should be validated.

Technical controls present a similar challenge.

Organizations can use identity management, permissions, data classification, data loss prevention, application access controls, and monitoring to limit AI-related risks. However, Nolan cautioned that controls alone may not be sufficient if employees lack an approved alternative that meets their needs.

“If the approved experience creates significantly more friction than the tool an employee can access on their own in thirty seconds, you’re creating the conditions for Shadow AI,” Nolan said.

“The objective shouldn’t be to block AI. It should be to create an environment where the easiest way for employees to use AI is also the safest way.”

MSPs can take a broader role in AI governance

For MSPs and other technology partners, Nolan sees shadow AI as a problem that increasingly cuts across areas they may already manage for customers.

“This is where the role of the partner is becoming much more strategic,” Nolan said.

“Most organizations don’t need another vendor simply telling them which AI product to buy. They need help understanding what is already happening inside their environment, where their data and security risks exist, what capabilities they already own, and how to build a practical roadmap from where they are today.”

Nolan specifically pointed to Microsoft partners, which can help connect areas that organizations often manage separately, including licensing, identity, security, data governance, Microsoft 365, Copilot, cloud architecture, adoption, and ongoing management.

Because shadow AI cuts across these areas, Nolan said treating it solely as a security project can be difficult and inefficient.

Advertisement

“For organizations without dedicated AI governance teams, a partner can effectively help provide that framework,” Nolan said. “That starts with assessing readiness and identifying risk, but it should ultimately lead to secure deployment, governance, employee enablement, monitoring, and continuous optimization.”

The longer-term goal, Nolan said, is not simply to eliminate shadow AI, but to reduce employees’ reasons to turn to unapproved tools in the first place.

Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.