Cohesity mitigating shadow AI by empowering staffers
Mon, 27th Jul 2026 (Today)
As the threat of shadow AI looms, companies are reducing the use of unsanctioned artificial intelligence tools by providing employees with approved alternatives.
A senior industry executive has warned, however, that it presents a much broader governance challenge than simply exposing sensitive corporate data.
The rapid adoption of generative AI has prompted employees across many industries to turn to personal ChatGPT, Claude and Copilot accounts to accelerate everyday tasks, often without formal approval from their employers.
While concerns have largely focused on confidential information being uploaded into external large language models, the more significant long-term risk lies in how AI-generated content can undermine the quality and governance of enterprise data.
Shadow AI has emerged for many of the same reasons as 'shadow IT' did during the early days of cloud computing, when employees bypassed internal processes to access public cloud services, according to Greg Statton, CTO APJ at Cohesity.
"I think by calling it shadow AI, people put a negative connotation around it," he said.
Drawing parallels with the rise of cloud platforms such as AWS, Statton explained employees naturally gravitate towards technologies that improve productivity, particularly when official channels are slow or unavailable.
During the early years of cloud adoption, employees would input their own payment details for AWS or other services, to bypass internal red tape. Statton argues AI is following the same trajectory.
Employees recognise that AI assistants can summarise documents, analyse information and automate repetitive administrative work.
If a staffer's most valuable resource is time, a small investment in a personal AI subscription could be well worth the money.
"The employee's perspective makes total sense," Statton said. "Now, if you zoom out and you're looking at a business perspective, well, I need to be able to control my data."
While some information can safely be processed through AI services, other datasets are subject to strict governance, privacy or commercial confidentiality requirements. Using personal accounts can bypass those controls entirely.
But data leakage is only part of a much larger challenge.
As organisations increasingly use AI to generate internal documentation, summaries and knowledge assets, AI-generated content itself becomes part of the enterprise knowledge base. Without appropriate oversight, those newly created documents may not receive the same validation, ownership and classification processes as the human-produced material from which they were derived.
"The reason AI is working so well for us is we have so much internal documentation in the enterprise that is generated, that is validated, that is annotated all by humans," Statton said.
"That data is being used with AI to create synthesis... are those new assets going through the same rigour of classification, of vetting, of ownership?"
This creates the potential for a self-reinforcing feedback loop, where inaccurate information can multiply over time as AI systems reference previous AI-generated content.
As an example, if one incorrect document claimed the sky is purple, not blue, and AI repeatedly used that document to generate new content, eventually the balance of enterprise knowledge could shift towards the incorrect answer, because more documents contained the same error.
"With shadow AI, you're subverting corporate governance," Statton said. "That can cause a lot of problems that we're seeing short-term, but massive problems long-term with accuracy."
The warning comes as organisations rapidly expand internal AI deployments while simultaneously attempting to establish governance frameworks around their use.
Short-term risks remain significant, particularly when employees upload sensitive intellectual property or customer information into consumer AI platforms without corporate oversight.
High-profile incidents where proprietary information entered public AI systems have already shown commercial consequences.
Although enterprise AI offerings often include contractual commitments regarding data handling and retention, those protections won't extend to personal AI accounts used outside approved environments.
Organisations may be able to negotiate contractual protections with providers such as OpenAI, including provisions covering data retention. However, individuals using personal accounts have no visibility into how their data is handled.
The temptation to use personal AI tools often comes from employees seeking shortcuts, not malicious intent.
Statton cited examples where employees could export CRM data into spreadsheets before asking an LLM to automatically generate charts and quarterly business review presentations.
Similarly, software developers may upload proprietary source code into personal AI assistants to troubleshoot bugs if approved development tools are unavailable.
Such shortcuts can significantly improve productivity but potentially expose commercially sensitive information without the organisation's knowledge.
"We've seen ChatGPT, Claude, be really good at synthesising that," Statton said. "Humans can be lazy at times."
Cohesity empowering their employees
Instead of relying solely on restrictive policies, Cohesity has sought to reduce shadow AI by giving employees access to approved platforms tailored to their specific roles.
Engineering teams, sales staff and marketing departments each use different AI capabilities connected to approved internal datasets through corporate-managed accounts.
By making sanctioned AI tools readily available, employees won't need to look at personal subscriptions or bypass governance controls, because their company has provided them with the appropriate tools.
"By giving access to it, we've curtailed a lot of the shadow AI," Statton said.
"There's no reason for them to go there."
AI governance cannot remain static as both the technology and regulatory landscape continue evolving.
Instead of treating AI governance as solely a technology issue, organisations should establish cross-functional governance boards that bring together leadership from across the business before deploying or restricting AI capabilities.
"Policies, just like technology, they have to be fluid," Statton said.
"This is not a technology problem. This is a corporate policy problem."