惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
I
InfoQ
C
Check Point Blog
IT之家
IT之家
MyScale Blog
MyScale Blog
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
Last Week in AI
Last Week in AI
GbyAI
GbyAI
P
Proofpoint News Feed
量子位
Stack Overflow Blog
Stack Overflow Blog
Microsoft Azure Blog
Microsoft Azure Blog
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
人人都是产品经理
人人都是产品经理
B
Blog
T
The Blog of Author Tim Ferriss
H
Help Net Security
云风的 BLOG
云风的 BLOG

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Shadow AI risks deepen as 31% of users get no employer tr...
Anamarija Po · 2026-05-01 · via Help Net Security

Between one-fifth and one-third of workers use AI outside the influence and governance of the IT function, according to a global survey of 6,000 full-time employees at enterprise organizations. Researchers found a widening gap between employee AI adoption and the controls organizations have in place to manage it.

shadow AI risks

The Lenovo Work Reborn Research Series 2026 report documents a workforce split into two groups: employees equipped with IT-managed tools, training, and oversight, and those operating independently with consumer AI services.

Training and tooling gaps drive unsanctioned use

Many employees report that their employers fail to supply either AI tools or training, and a sizable share of those who receive training describe it as irregular or ineffective. Half of all employees say better training would help them get more value from AI at work, pointing to a workforce ready to adopt AI faster than its employers can equip it.

Employee enthusiasm for AI continues to climb. Seven in ten use AI tools at least a few times a week, and 80% expect their use of AI to increase over the next year. Lenovo’s research indicates that adoption is outpacing the capacity of enterprises to manage, enable, or align it.

Security implications of unmanaged adoption

The report identifies two security concerns tied to shadow AI. Bypassing compliance controls increases the risk that intellectual property or sensitive data are processed outside governed environments. Fragmented workflows produce inconsistent execution and uneven distribution of productivity gains across teams.

Employee trust in enterprise-provided tools shows measurable cracks. A meaningful share of employees doubt the reliability of information produced by employer-provided AI tools, and a smaller group questions whether their privacy and personal data are safe when using them.

Cybersecurity awareness among employees is uneven. Nearly half of employees are highly concerned about criminals using AI to develop sophisticated cyber attacks against their company, and the same percentage are highly concerned about themselves or a colleague accidentally leaking sensitive company information through public AI systems such as ChatGPT. Forty percent are highly concerned about deepfake videos and AI-generated phishing emails. Only 23% are highly concerned about criminals attacking their company’s AI systems directly, a gap that becomes consequential as organizations deploy AI agents and internal AI infrastructure.

These employee perceptions track with separate findings from Lenovo’s CIO Playbook, which reports that 61% of IT leaders say AI is increasing cybersecurity risks and only 31% are confident in their ability to address those risks.

What employees want from security teams

Seventy-four percent of employees say more or better cybersecurity training on AI-related risks would reassure them that they and their organization are protected. Seventy-three percent say it would be reassuring to know their company’s cybersecurity team is using AI to address these risks. Seventy percent say stricter policies on how employees can use AI would provide reassurance.

The report recommends building governance before scaling AI, embedding security awareness into the flow of work through continuous in-context learning, and standardizing the AI interface across workflows and endpoints.

Webinar: The IT Leader’s Guide to AI Governance