Shadow AI is creating a widening gap between corporate AI policy and how employees actually use generative AI tools, prompting security leaders to look beyond written governance rules toward technical enforcement at the endpoint.
The UK’s National Cyber Security Centre (NCSC) has warned that unauthorized AI use can expose sensitive data and create security blind spots. But IGEL CTO Matthias Haas told Channel Insider that guidance and policy are only effective when organizations can see and control how AI tools are being accessed.
“Policy alone is not able to govern shadow AI, unless it’s backed by the visibility and technical enforcement at the point of access,” Haas said. “What organizations need to know is which services are people using.”
For MSPs and MSSPs, that gap creates an opportunity to move beyond one-time AI policy work and provide ongoing governance across endpoints, browsers and network infrastructure.
Shadow AI exposes the gap between policy and employee behavior
There’s a difference between having AI governance documented and actually understanding how employees use AI. Helping users move toward AI use that aligns with their organization’s requirements and regulatory environment is critical.
“People are using AI tools to make their work more efficient and achieve goals in a meaningful amount of time. And in this context, it’s important to know what’s happening in your infrastructure,” Haas said.
“If you are in highly regulated industries, you might have higher limits or higher requirements of what types of AI workload is allowed and what type of data you can put in.”
Endpoint and network controls add visibility into AI use
As browser-based AI tools increase in popularity, the need for controls at both the network and endpoint layers has increased as well. Haas highlights a need to monitor AI workloads and the data being sent to AI models.
“On a network layer – depending on how you’ve built your infrastructure – there are ways in how you can actually track and monitor what type of AI workloads are being used, and even what type of data is being sent through to those AI models,” explained Haas.
“On the other hand, there’s also a need to make sure that on an endpoint device you have the ability to actually track and control what data is being prompted towards those AI tools.”
Secure browsers emerge as an AI governance layer
Haas notes that there are solutions out there, such as secure enterprise browsers, that allow organizations to track and monitor the types of prompting being done. They can also block specific AI prompts that are noncompliant with company policies.
Keeping an eye on which browsers employees can use helps organizations maintain a consistent endpoint architecture and apply their AI security policies.
Overall, true AI governance, Haas says, is a combination of user awareness, endpoint application controls, and network-level controls rather than a single security feature.
“There is not one single feature; it’s a combination of how you work with the users to create awareness about the ability to manage what type of applications are accessible on an endpoint, and this includes which type of browser is being accessible based on your specific needs,” said Haas.
“There is also the infrastructure component where you have to think about how you’re controlling network traffic and the data that flows from your organization into the different modern types,” he added.
MSPs can turn shadow AI governance into an ongoing service
For MSPs and MSSPs, building a technology stack with visibility and controls across cloud, network, and endpoint layers is key to curbing the shadow AI threat.
“I think you should not forget about the endpoint because the endpoint gives you control and visibility with telemetry and insights that you can generate on how people are using the applications to make sure you fully understand how people are trying to achieve their day-to-day tasks,” Haas reemphasized.
The opportunity for the channel is to provide ongoing AI governance services rather than simply selling an AI-blocking tool, while keeping pace with evolving user demand and managing risk.
Haas says the opportunity is to operate a governance AI access service that keeps pace with end-user demand and, at the same time, is able to react to a fast-changing environment.
“What NCSC was providing is a clear ability for us to continue to invest in those types of architectures, helping not to hinder AI or block AI, but to make sure it’s in compliance with the policies and also to make sure that you have the ability to be very much risk aware of what’s happening in your infrastructure,” said Haas.
WATCH NEXT: Some MSPs are already building those AI services. Our video interview with Andy Nolan, the VP of Technology at Microsoft-focused provider Trusted Tech, dives into security and governance offerings for Copilot adoption.





