
Artificial intelligence is breaking a long-standing model within many organizations.
AI isn't arriving through carefully planned IT projects or lengthy procurement cycles. It's arriving organically—through every department, every browser, every SaaS platform, and increasingly, every employee.
This has created one of the major blind spots in enterprise cybersecurity today: internal AI visibility.
The 2026 Bitdefender Cybersecurity Assessment asked 1,200 IT & cybersecurity professionals how much visibility they have into AI usage across the organization. More than four-in-ten (44.8%) acknowledge they only have partial visibility into employee AI usage, saying they can monitor sanctioned enterprise LLMs but lack visibility into personal AI accounts and Shadow AI subscriptions used for work. And while 51.8% say they have full visibility into all AI usage at their organizations, that figure is optimistic and warrants scrutiny.

We explored the topic recently on a webinar around cybersecurity benchmarks and blind spots, and my colleague Martin Zugec made a key point on AI visibility: "We had a roundtable with CISOs where we discussed this. It turns out you have a lot of tools that you approved and have been using for a while that suddenly turn themselves into LLM enabled, and you probably don't even consider them."
Many organizations believe they understand their AI exposure because they can account for the enterprise AI platforms they've approved. Those sanctioned tools represent only a fraction of the AI ecosystem employees interact with every day.
When executives think about AI governance, many still picture employees opening ChatGPT in a browser.
That was the conversation twelve months ago.
Today's reality is far more complex. AI is now embedded throughout the modern enterprise. Productivity suites summarize meetings automatically. CRM platforms draft customer communications. Development environments generate code. Browsers offer AI assistants. Design software creates images. Security products analyze threats using generative AI. Employees sometimes don't even realize they're interacting with AI.
That means organizations aren't simply trying to inventory AI applications anymore—they're attempting to understand AI capabilities woven into hundreds of existing business tools.
The conversation has evolved from: "Which AI tools are employees using?" to "Where does AI exist across our technology stack?"
Shadow AI may be the new Shadow IT, but the risks are far greater than the typical issues we've seen in the past.
When cloud adoption was the hot new thing, departments sometimes spun up their own S3 buckets or employees stored files in any number of unauthorized cloud services and apps. That was shadow IT. But with Shadow AI, your employees are likely asking AI to summarize contracts, rewrite customer communications, analyze financial data, generate source code, interpret legal documents, and answer sensitive business questions.
In many cases, sensitive corporate information is becoming part of these conversations.
And employees are increasingly granting AI platforms access to their corporate emails, calendars, and even private meeting rooms as they use AI tools to record every word and summarize next steps. Would your organization even know if these interactions have occurred?
Shadow AI is a significantly more dynamic attack surface than we've faced before.
Recent Bitdefender research finds that more than half of IT & cybersecurity professionals believe they have "full visibility" into AI usage, however, I suspect many organizations are defining the term differently than reality demands.
The AI landscape changes almost weekly. New capabilities appear through software updates organizations didn't request and sometimes don't notice. In that environment, visibility is less a destination than an ongoing operational discipline.
And in my daily work with organizations around the globe, I'm finding that many need help to ask the right questions around AI usage, so they can form a baseline around AI visibility and decide where they should go from there.
When it comes to AI governance, technology alone will not solve this problem.
Many organizations are understandably looking for monitoring tools to improve visibility. But technology addresses only part of the challenge.
The larger issue is governance.
Organizations should ask themselves:
Governance cannot be delegated entirely to IT or security. AI is now an enterprise-wide business capability and managing it often requires enterprise-wide accountability.
AI capabilities are being integrated into enterprise software faster than traditional governance models were ever designed to accommodate. And security leaders should not assume that the absence of incidents means the absence of risk.
The AI Visibility challenge isn't simply a technology problem. It's also a leadership challenge that requires accurately assessing how intelligence itself is becoming embedded throughout the organization. The sooner organizations recognize that distinction, the sooner they'll begin managing the AI risks they can't yet see.
See the rest of the AI benchmarks and blind spots:
Download the 2026 Bitdefender Cybersecurity Assessment
tags
Nicholas is an accomplished professional, currently serving as the Director of Cyber Operations at Bitdefender. In his current capacity, Nicholas is responsible for 3 services; Offensive Security, Security Advisory, and Delivery Management. With an extensive cybersecurity background gained across various globally recognized organizations, he offers a wealth of cyber security experience. His journey through diverse cybersecurity landscapes has equipped him with a nuanced understanding of the field, making him a trusted leader in shaping robust and effective cybersecurity strategies.
View all posts