惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
Y
Y Combinator Blog
WordPress大学
WordPress大学
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
About on SuperTechFans
小众软件
小众软件
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
GbyAI
GbyAI
I
InfoQ
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
C
Check Point Blog
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
量子位
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
Enterprise data is creeping its way into shadow AI tools
Paige Gross · 2026-05-28 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

Executives and employees are clashing over usage policies as AI security concerns rise, an Okta report found.

Published May 28, 2026

Fingers hover over a computer keyboard with numbers on a screen, against a shadowy backdrop.

Getty Images

First published on

CIO Dive

Dive Brief:

  • Nearly all executives are confident their employees are using AI responsibly, but shadow AI is creeping its way into organizations, an Okta survey released Wednesday found. More than half of employees reported they’re using personal AI tools without approval, the security platform provider learned in surveying nearly 300 tech executives and 500 knowledge workers along with market research firm Apprize360.
  • Workers reported using unapproved AI tools for productivity reasons, saying they allow the tools access to internal messages, HR-related information and confidential company documents. The practice is heightening security risks, as 58% of executives said their organization had an AI-related security incident or a close call last year, according to the report. 
  • Lack of clarity in AI usage policies or banning personal AI tools can actually increase shadow AI use, said Harish Peri, Okta’s SVP and GM for AI security, in an email. “By taking a more collaborative approach with employees, leaders can offer sanctioned, enterprise-grade alternatives to the unapproved tools that teams are using.”

Dive Insight:

Executives feel strongly that the AI usage policies they've set are clear and consistent. But the sentiment doesn’t resonate with employees, according to the Okta report. More than half of employees say their organization’s policies are unclear, difficult to find or non-existent. 

American employees especially are turning to unsanctioned tools to fill in productivity gaps. Two-thirds of U.S.-based employees use unsanctioned AI, and nearly a quarter do so regularly, the report found. 

Shadow AI use usually isn’t done maliciously, Peri said, but is a result of employees wanting to experiment with new tools and agents to meet deadlines or solve specific problems. Employees aren’t usually aware of what data an AI tool might access or for how long.

“The risk isn’t necessarily because of intent, but because employees are experimenting without thinking through visibility, governance, or consistent security controls,” he said. 

Organizations should be working with employees in a collaborative approach to understand what they need for productivity gains and what they feel is lacking in their company AI offerings. From there, they can establish a governance framework that provides secure sandboxes to test drive AI tools safely.

“The old adage in cybersecurity is that you can’t protect what you can’t see,” Peri said. “If you don’t know what agents exist or where they are in your environments, there’s no way to reliably enforce access policies.”

Peri said many tech leaders feel an illusion of control over their AI governance, but most policies could use frequent refreshes and security checks. He encourages enterprise leaders to regularly ask themselves what agents have access to and what they’ve been given permission to do. 

“If you can’t answer those questions, you’re flying blind,” Peri said. “That is the baseline for operating a secure agentic enterprise today.”