Deep dive

Wiz defines shadow AI as the unauthorized use or implementation of AI that is not controlled by, or visible to, an organization’s IT department — tools adopted without IT approval or security governance. The academy piece argues that easy interfaces widen the gap between what employees can reach and what organizations can control, and that outright bans can push more work into unsanctioned channels.

+50%Worker AI access rose in 2025 (Deloitte 2026 State of AI, via Wiz)
1 in 5Companies with a mature AI governance model (same Deloitte cite)
>40%Orgs Gartner expects to face shadow-AI compliance/security incidents by 2030
Visibility first — inventory before ban lists.

What Wiz sees in the cloud (2026)

Wiz’s State of AI in the Cloud 2026 report — linked from the academy primer’s broader security framing — finds AI embedded across environments: at least 81% of organizations using managed AI services, 90% running self-hosted models, and 80% of organizations using AI IDE extensions. Those figures describe sanctioned and unsanctioned footprint together; the shadow-AI risk is that security teams inherit tools and data flows without central oversight.

81%Orgs using managed AI services (Wiz State of AI in the Cloud 2026)
90%Running self-hosted models
80%Using AI IDE extensions
SecurityEnterpriseShadow AIWiz