IGEL CTO: Shadow AI Policy Needs Endpoint Controls

IGEL CTO Matthias Haas says shadow AI governance requires endpoint visibility and network controls as MSPs help organizations manage AI risk.

Written By
Jordan Smith
Jordan Smith
Sep 24, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Shadow AI is creating a widening gap between corporate AI policy and how employees actually use generative AI tools, prompting security leaders to look beyond written governance rules toward technical enforcement at the endpoint.

The UK’s National Cyber Security Centre (NCSC) has warned that unauthorized AI use can expose sensitive data and create security blind spots. But IGEL CTO Matthias Haas told Channel Insider that guidance and policy are only effective when organizations can see and control how AI tools are being accessed.

“Policy alone is not able to govern shadow AI, unless it’s backed by the visibility and technical enforcement at the point of access,” Haas said. “What organizations need to know is which services are people using.”

For MSPs and MSSPs, that gap creates an opportunity to move beyond one-time AI policy work and provide ongoing governance across endpoints, browsers and network infrastructure.

Shadow AI exposes the gap between policy and employee behavior

There’s a difference between having AI governance documented and actually understanding how employees use AI. Helping users move toward AI use that aligns with their organization’s requirements and regulatory environment is critical.

“People are using AI tools to make their work more efficient and achieve goals in a meaningful amount of time. And in this context, it’s important to know what’s happening in your infrastructure,” Haas said. 

“If you are in highly regulated industries, you might have higher limits or higher requirements of what types of AI workload is allowed and what type of data you can put in.”

Endpoint and network controls add visibility into AI use

As browser-based AI tools increase in popularity, the need for controls at both the network and endpoint layers has increased as well. Haas highlights a need to monitor AI workloads and the data being sent to AI models.

“On a network layer – depending on how you’ve built your infrastructure – there are ways in how you can actually track and monitor what type of AI workloads are being used, and even what type of data is being sent through to those AI models,” explained Haas. 

Advertisement

“On the other hand, there’s also a need to make sure that on an endpoint device you have the ability to actually track and control what data is being prompted towards those AI tools.”

Secure browsers emerge as an AI governance layer

Haas notes that there are solutions out there, such as secure enterprise browsers, that allow organizations to track and monitor the types of prompting being done. They can also block specific AI prompts that are noncompliant with company policies.

Keeping an eye on which browsers employees can use helps organizations maintain a consistent endpoint architecture and apply their AI security policies.

Overall, true AI governance, Haas says, is a combination of user awareness, endpoint application controls, and network-level controls rather than a single security feature.

“There is not one single feature; it’s a combination of how you work with the users to create awareness about the ability to manage what type of applications are accessible on an endpoint, and this includes which type of browser is being accessible based on your specific needs,” said Haas.

“There is also the infrastructure component where you have to think about how you’re controlling network traffic and the data that flows from your organization into the different modern types,” he added.

MSPs can turn shadow AI governance into an ongoing service

For MSPs and MSSPs, building a technology stack with visibility and controls across cloud, network, and endpoint layers is key to curbing the shadow AI threat.

“I think you should not forget about the endpoint because the endpoint gives you control and visibility with telemetry and insights that you can generate on how people are using the applications to make sure you fully understand how people are trying to achieve their day-to-day tasks,” Haas reemphasized.

The opportunity for the channel is to provide ongoing AI governance services rather than simply selling an AI-blocking tool, while keeping pace with evolving user demand and managing risk.

Haas says the opportunity is to operate a governance AI access service that keeps pace with end-user demand and, at the same time, is able to react to a fast-changing environment.

“What NCSC was providing is a clear ability for us to continue to invest in those types of architectures, helping not to hinder AI or block AI, but to make sure it’s in compliance with the policies and also to make sure that you have the ability to be very much risk aware of what’s happening in your infrastructure,” said Haas.

Advertisement

WATCH NEXT: Some MSPs are already building those AI services. Our video interview with Andy Nolan, the VP of Technology at Microsoft-focused provider Trusted Tech, dives into security and governance offerings for Copilot adoption.

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.