Most security teams believe they know which AI tools their people use. The real number is almost always higher, and the gap between the two is exactly where the risk lives.

In a recent conversation, an enterprise told us it had six sanctioned AI tools. Its leaders were confident in that number, and they had built a program around it. Then they deployed visibility at the browser and found 243 AI products already in active use across the organization. Had we installed the Island Desktop component as well, I’m certain we would have seen even more unsanctioned desktop AI applications in use.
That gap is the pattern, not the exception. In a recent Thomson Reuters study, organizational use of generative AI nearly doubled in twelve months, and roughly two-thirds of workers report reaching for unapproved AI tools to get their jobs done. Shadow AI already runs quietly inside most environments today, well ahead of the programs meant to govern it.
Which points to the reframe at the heart of this issue: shadow AI is fundamentally a visibility problem, and treating it as something to block only hides it further. The tools were never the crisis; the blind spot was, because you can't govern what you can't see. This is where Island earns a look, as the proof point for what governance at the source actually requires.
The instinct, understandably, is to shut it down. If the tools are ungoverned, block them at the gateway and the risk goes away. Most organizations that try this discover the opposite, because every block simply reroutes the same behavior somewhere harder to see. An employee who loses access to a sanctioned assistant opens the same model on a personal account, on a phone, or on a home machine, and the data leaves the environment entirely.
That happens because the underlying value is real. People adopt these tools to draft faster, summarize dense material, and clear work they used to dread, and no policy memo competes with a genuine productivity gain. When roughly half of employees adopt AI without approval, and when leaders themselves are among the heaviest adopters, blocking stops being governance and starts being theater.
This is the trap security teams know too well. For years the function has been cast as the department of no, the group whose job is to slow things down in the name of safety. Blocking shadow AI reprises that role at the worst possible moment, right as the business is betting its future on moving faster and staying ahead of a competitive landscape that is successfully leveraging AI. The organizations navigating this well have stopped asking how to stop the behavior and started asking a more useful question: what are people actually using, and why.

The deeper issue is that traditional controls can't tell governed use from personal use at the exact moment it happens. Tool count is a symptom; the blind spot at the point of use is the cause. From a URL alone, gemini.google.com looks identical whether an employee is signed into a sanctioned corporate tenant or a personal account they opened over the weekend. The address bar tells you nothing about who owns the data on the other side.
Legacy architectures were built for a cleaner world. Network choke points assume traffic flows through a place you control, and that assumption frays the moment work moves to unmanaged devices and personal logins. The controls that remain tend to be blunt: allow the destination or block it, with very little room in between. Real AI usage lives in that missing middle, where a tool should be allowed for one task, restricted for another, and monitored for the sensitive data that must never leave.
Adding more rules to a brittle system rarely helps. A common pattern we see is a data-protection program buried under thousands of atomic rules, each one written to catch a specific pattern in a specific place. One organization we worked with had accumulated roughly 12,000 such rules and cut that to around 200 by governing at an application boundary instead. The volume of rules was never the fix, because the control point itself sat in the wrong place.
If the risk lives at the last mile, that's where the control has to live too. The durable answer is to move governance to where people actually touch AI, across the browser, the desktop, and the network, so control becomes context-aware and proportional rather than a binary allow-or-block switch. This is the shift that lets security stop saying no and start saying yes, safely.
Island Enterprise AI is built around that idea. Because the environment sits where work happens, it can see every AI entry point and tell a corporate tenant apart from a personal one, which is precisely the distinction a URL can't reveal. Visibility comes first, since you can't protect what you don't know is there. Once you can see usage clearly, you can steer it: point people toward a better-governed option, allow the tool they love with guardrails, and reserve hard restrictions for genuine data risk.
Control then operates at the level of the data itself. Sensitive information can be redacted before a prompt ever reaches a provider, and responses can be inspected before they land back in front of a user, all without the person feeling policed. That's governance embedded in the flow of work rather than bolted on around it. The result is proportional control, matched to the task and the context, instead of one heavy gate that everyone learns to walk around.
A fair objection is that this all sounds like shadow IT wearing a new outfit, and haven't we managed that for years? The honest answer is that agentic AI raises the stakes in a way spreadsheets and rogue SaaS apps never did. An agent doesn't just view data, it acts, and a single misconfigured step can move records from a business application to an external service before anyone notices.
The connective tissue makes the surface larger still. Agents reach back-end systems through connections like Model Context Protocol (MCP) servers, which act as gateways into the applications where your most sensitive data lives. A policy document does nothing to govern that traffic, because the action happens at runtime, in the moment the agent executes.
With enterprise AI adoption still climbing across the enterprise, the number of these entry points is only growing. The same last-mile governance model that watches human usage has to extend to agents and their connections, or the visibility gap widens faster than any team can staff around it.

Pull back far enough and the shift is clear. Security's job has become making yes safe at the speed the business demands, rather than standing as the last line of refusal. When governance is embedded where work happens, across the browser, the desktop, and the network, enablement and visibility come first and policy enforcement follows naturally. The environment carries the control, so the person carries only the work.
That's the resolution to the gap we opened with. Those 243 hidden tools became a problem only because no one could see them. Start by seeing what your people actually use, govern it at the source, and the choice between innovation and safety stops being a choice at all. Saying yes to AI begins with the simple, radical act of turning on the lights.
What exactly counts as shadow AI?
Shadow AI is any AI tool, extension, or agent employees use for work without the security or IT team's knowledge or approval. It spans everything from a personal chatbot account to an unsanctioned browser extension to plugins to popular development environments (IDE) to an autonomous agent wired into a business system. What defines it is operating outside the organization's visibility and governance, whatever form the tool takes.
If we can't block it, doesn't that mean giving up control?
Just the opposite. Blocking gives up control the moment usage moves to a personal account you can't see, whereas visibility and proportional governance keep the activity inside your environment where policy still applies. You trade the illusion of a hard wall for the reality of context-aware control at the point of use.
How is this different from the shadow IT problem we've managed for years?
Traditional shadow IT mostly meant unsanctioned apps storing or moving data. Agentic AI adds autonomous action, so a tool can now reach into back-end systems and move data across boundaries on its own. The visibility principle is the same, but the speed and blast radius are considerably higher.
Where should governance actually live: the network, the endpoint, or the browser?
It should live across all three, because that's where people and agents actually touch AI. Governance concentrated at a single network choke point misses usage on unmanaged devices and personal logins, so the control has to be embedded at the last mile where work genuinely happens.
What's the first move for a leader who suspects shadow AI is already widespread?
Start with visibility before policy. Get an accurate picture of which AI tools, tenants, and agents are actually in use, then use that reality to decide what to steer, what to enable with guardrails, and what to restrict. Almost every organization that measures this finds the real number is far higher than assumed.