Executives are by far the largest users of unapproved artificial intelligence tools in the enterprise, with 65% of global decision-makers admitting they tap unsanctioned AI services, according to research published July 27, 2026, by Microsoft solutions partner TrustedTech. Yet 56% of those same leaders say they worry about shadow AI among their workforces—a glaring gap between stated concern and personal behavior that IT and security teams now must address.

The Numbers That Should Keep Security Teams Up at Night

TrustedTech’s data, drawn from its second wave of AI adoption research, reveals a uncomfortable reality: U.S. decision-makers are even more likely to go rogue, with 67% using unapproved AI tools. That’s more than double the rate among employees below the decision-maker level. The interview with Andy Nolan, TrustedTech’s VP of Technology, puts a number on a problem many IT leaders have sensed but couldn’t quantify.

“What our data surfaces is a striking paradox,” Nolan told Pulse 2.0. “65% of global decision-makers and 67% of U.S. decision-maker-level employees use unapproved AI tools, more than double those below decision-maker level, while at the same time 56% of global decision-makers are concerned about employees using Shadow AI, despite being the most active users themselves.”

Even more troubling: 21% of global shadow AI users said they deliberately choose unsanctioned tools because they don’t want their organizations to see or access their data. That insider-risk signal shows shadow AI isn’t always about naive convenience—it can be a calculated way to bypass corporate oversight. And when executives, who routinely handle financial models, strategic plans, customer records, and board materials, are the ones hiding data flows, the potential blast radius expands dramatically.

Executives operate under constant time pressure. An AI assistant that can draft a board briefing, summarize a 100-page legal contract, or analyze a dataset in seconds is immensely attractive. Nolan pointed out that leaders often feel governance policies were designed for the workforce, not for them. “They’re setting the vision, not following the playbook,” he said.

That cultural divide turns AI governance from a policy exercise into a credibility test. When a chief financial officer uploads an earnings forecast to a consumer AI chat, or a CEO asks a public tool to refine acquisition talking points, the data likely leaves the organization’s control entirely. Depending on the tool’s terms of service, that sensitive information could be used to train models, stored on third-party servers, or processed in jurisdictions that violate data residency rules, contractual obligations, or regulatory requirements.

“A data breach that traces back to executive Shadow AI use would be extraordinarily difficult to explain to a board, a regulator, or a customer,” Nolan warned. The risks span confidentiality (exposing nonpublic financials, M&A plans, product roadmaps), compliance (breaking GDPR, HIPAA, or industry-specific rules), intellectual property loss, and a crippled incident-response capability—security teams cannot investigate what they cannot see.

The Microsoft 365 Copilot Option—Promise and Pitfalls

For organizations deeply invested in the Microsoft ecosystem, Copilot offers a path out of the shadow. It operates within the Microsoft 365 compliance boundary, respects existing user permissions, and does not use prompts or responses to train foundation models. Audit logs, eDiscovery, and retention policies all apply, making Copilot a stark contrast to ungoverned consumer AI accounts.

But Nolan and other experts caution that Copilot is not a magic wand. It honors existing permissions—it does not fix them. If a SharePoint site is overshared, Copilot will happily surface sensitive documents to anyone with access. That flips AI readiness into a data-governance project. Before scaling Copilot broadly, organizations should:

  • Review permission structures across SharePoint, Teams, OneDrive, and Exchange.
  • Apply sensitivity labels and retention policies via Microsoft Purview.
  • Configure data loss prevention rules tailored to AI prompt and file-sharing patterns.
  • Enforce conditional access and multifactor authentication.
  • Establish clear guidelines for web grounding, plugins, and third-party connectors.

TrustedTech, which holds all six Microsoft Solutions Partner designations and a Direct Cloud Solution Provider relationship, sells readiness assessments and implementation services to help companies navigate this complexity. However, Nolan’s core message is vendor-agnostic: a sanctioned AI tool is only as secure as the data foundation underneath it.

From Denial to Control: A 90-Day AI Governance Plan

Organizations that discover widespread unapproved AI use should resist the urge to simply block public services. Nolan argued that blocking often drives dangerous behavior further underground, onto personal devices and cellular networks. Instead, he advocates a structured approach that combines visibility, policy reform, and credible alternatives.

Days 1–30: Shine a Light and Stop the Bleeding

Start by identifying what tools are being used, by whom, and for what purposes. Browser logs, network telemetry, and endpoint data can reveal which AI services are accessed. Immediately communicate an interim policy: no confidential, regulated, or attorney-client privileged data can be entered into unapproved AI tools. Assign an executive sponsor who visibly complies.

Days 31–60: Build Governance and Offer Real Alternatives

Create an AI steering committee that includes IT, security, legal, compliance, HR, and business leaders. Roll out Microsoft 365 Copilot or Copilot Chat if you’re a Microsoft shop, but only after locking down permissions and confirming audit trails work. For non-Microsoft shops, identify enterprise-grade alternatives with contractual data protection. Crucially, make the sanctioned tool as easy to use as the public ones—otherwise, shadow behavior will persist.

Days 61–90: Train by Role, Measure Adoption, Iterate

Move beyond generic annual training. Executives need briefings on how to handle board materials securely with AI. Finance teams need guidance on which models may consume data. Developers need rules around code-generation tools. Windows administrators need to know what’s acceptable when using AI to troubleshoot PowerShell or Azure. Track whether the sanctioned tools are actually solving the tasks that drove people to shadow AI. If not, governance has identified a capability gap that leadership must fund.

Accountability Starts in the Corner Office

TrustedTech’s data makes one thing clear: AI governance that exempts senior leaders isn’t governance—it’s theater. “Governance frameworks have historically been designed to manage behavior from the bottom up, policies trickle down, compliance is monitored at the employee level, and exceptions are assumed to come from the ranks,” Nolan said. “That model is broken for AI.”

The fix requires executives to model the behavior they expect. That means using the corporate-sanctioned AI tool for their own work, participating in readiness training, and accepting that their AI activity is logged just like everyone else’s. The moment a VP uses an unapproved AI to draft a board briefing, any policy demanding that frontline workers use only sanctioned tools loses all credibility.

Nolan’s research also underscores that training and communication are woefully inadequate. Forty-six percent of U.S. respondents said their organization lacks adequate training on secure AI use, and 41% said they lack clear workplace guidance. Meanwhile, 36% of employees primarily teach themselves AI skills, compared to just 23% who received formal employer training. That skills vacuum fuels the shadow problem.

Outlook: Governance as an Ongoing Operational Reality

As AI capabilities embed into Windows, Office, Azure, and every line-of-business application, the line between “sanctioned” and “shadow” will blur further. The coming wave of AI agents, browser extensions, and copilots for everything from CRM to HR will make unaudited AI use even easier. Organizations that treat AI governance as a one-time project, or as a purely bottom-up enforcement challenge, will find themselves in a perpetual cycle of firefighting.

The TrustedTech data serves as an early warning: the biggest source of ungoverned AI risk may be sitting in the executive suite. Addressing it takes technological controls, but more importantly, it demands a cultural shift where data stewardship is seen as a leadership responsibility, not an IT chore. For Windows admins, Microsoft 365 architects, and CISOs, that means building partnerships with the business that start with transparency and end with secure productivity—for everyone, from the helpdesk to the boardroom.