Seventy-five percent of knowledge workers already use AI at work, according to Microsoft's 2025 Work Trend Index survey of 31,000 workers across 31 markets. Nearly half of them started less than six months ago. That adoption curve should change how you think about AI policy.
Most organizations respond to AI risk in one of two ways. Some block everything and hope compliance follows. Others approve a handful of tools, write a policy memo, and move on. Neither approach works, because both assume the organization controls the adoption curve, when in reality employees do.
McKinsey's 2025 State of AI survey found that 78% of organizations now use AI in at least one business function. The Verizon 2025 DBIR found that 72% of employees who routinely access GenAI on corporate devices do so through non-corporate email accounts, completely outside corporate authentication. IBM's Cost of a Data Breach report found that shadow AI added an average of $670,000 to global breach costs. The gap between "what's approved" and "what's in use" is where risk accumulates.
Your workforce has already adopted AI. The only open question is whether you'll have visibility when they do.
Why "Block Everything" Fails
Blanket AI bans feel decisive. In practice, they create the exact problem they're trying to prevent.
When you block AI tools at the network or policy level, employees don't stop using them. They switch to personal devices, personal accounts, mobile hotspots, browser extensions that don't route through your proxy. The usage continues, but your visibility drops to zero. ISACA's 2025 survey of 3,200 IT and business professionals found that 83% believe employees in their organization are already using AI, yet only 31% have a formal, comprehensive AI policy in place.
Gartner predicts that by 2030, more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI. The organizations most likely to hit that number are the ones enforcing blanket bans, because blanket bans are what produce shadow AI in the first place.
There's also a productivity cost. Microsoft's 2025 Work Trend Index found that employees with AI access reported saving more than 10 hours per month on routine tasks. GitHub Copilot now has over 20 million users and generates 46% of all code written by its users, according to GitHub's own research. When you block these tools, you're removing time savings that employees have already built into how they work. The productivity loss compounds across teams, especially in engineering, customer support, content, and sales functions where AI adoption is highest.
Then there's the talent side. Engineers increasingly evaluate employers based on AI tool access. A company that bans Copilot or Claude while competitors provide them with guardrails is making a recruiting pitch that gets harder to sustain every quarter.
The gap between "block everything" and "allow everything" is where safe enablement lives. Organizations that figure out how to give employees AI access with the right visibility and guardrails get both the productivity gains and the risk coverage.
Discovery First, Policy Second
You can't write a reasonable AI policy without knowing what your workforce is already using. Most organizations skip this step. They pick two or four tools to approve, publish a policy, and assume compliance. The actual AI surface is usually much larger than what anyone expects.
Stanford HAI's 2026 AI Index recorded 362 documented AI incidents in 2025, up 55% from 233 in 2024. The share of organizations rating their AI incident response as "excellent" dropped from 28% to 18% over the same period. Incidents are rising because adoption is outpacing the ability to see and manage what's in use.
Discovery means answering concrete questions. How many employees are logging into AI services with personal accounts on managed devices? Which AI browser extensions are installed across the fleet? Which desktop AI apps are running on endpoints? Are any AI tools connecting to internal systems through MCP servers or OAuth grants? Which tools are accessing source code, customer data, or financial models? And which AI tools are getting the most adoption across the org, by team and by function?
That last question matters for more than security. Usage data tells you which AI tools are actually delivering value. If 60% of your engineering org has adopted one coding assistant while the tool you officially approved sits unused, that's a signal about which tool to standardize on. Discovery reduces risk and helps you make better procurement and enablement decisions based on how people actually work.
These questions require visibility across two surfaces: browser and endpoint. On the browser side, you need to see web logins to AI services, AI-related browser extension installs, OAuth grants to AI providers, and DNS-level traffic. On the endpoint, you need to see desktop app installs, IDE extension installs, MCP client and server connections, and configuration changes.
Most organizations that run a discovery exercise find that the real AI surface is four to ten times larger than the approved tool list. That gap is the starting point for a useful policy, not the approved list itself.
Graduated Controls, Not Binary Approve/Deny
Once you know what's in use, the instinct is to sort tools into two buckets: approved and blocked. That's too coarse. Different AI tools carry different risk profiles, and the same tool can carry different risks depending on how it's configured.
An AI coding assistant running on a managed endpoint, authenticated through corporate SSO, with MCP server connections limited to the employee's own repositories, is a different risk than the same tool running on a personal device, authenticated through a personal account, with plugins that bridge corporate data to third-party services.
The right model is graduated posture management. For tools you want to enable broadly, log activity without interrupting the user. For tools that carry moderate risk, show the user a warning when they take a risky action (pasting sensitive data, connecting to an unapproved MCP server) and record the event. For tools you want to restrict heavily, treat specific operations as policy violations and surface them as findings.
This per-tool, per-action approach lets you keep most AI usage flowing while tightening controls around the specific behaviors that create actual exposure. Engineers keep their coding assistants, the security team keeps its visibility, and the policy reflects how people actually work rather than how a committee imagined they would.
Governance Is a Loop, Not a Memo
AI governance fails when it's treated as a one-time project. You audit the AI surface, publish a policy, check the box, and move on. Six months later the surface has changed completely because employees have installed new tools, added new plugins, connected new MCP servers, and granted new OAuth permissions.
McKinsey found that despite 78% adoption, only 6% of organizations achieve significant enterprise-wide AI impact. PwC's research shows that companies broadened workforce AI access by 50% in a single year, growing from fewer than 40% to around 60% of workers equipped with sanctioned AI tools. The surface is expanding faster than governance programs can keep up.
A working governance program runs continuously. It discovers new AI tools as they appear on endpoints and in browsers and classifies them against the approved list. It flags deviations from expected usage patterns, surfaces the 1-2% of activity that warrants investigation, and lets the rest flow.
The feedback loop matters too. When discovery reveals that 40% of your engineering team has adopted a tool you haven't approved, that's a signal the tool is useful and your approved list needs updating. Governance programs that treat every unapproved tool as a violation end up recreating the blanket ban problem under a different name.
What Matters More Than the Tool List
Knowing which AI tools are in use is necessary but insufficient. The deeper questions are about behavior.
Microsoft's 2026 Work Trend Index found that organizational factors like culture, manager support, talent practices, and team norms drive roughly twice the AI impact of individual mindset, a 67% to 32% split. In other words, the governance framework matters more than whether any single employee is using AI responsibly. The system-level visibility is what determines whether AI adoption creates value or creates risk.
Is the person using the tool in a way that's consistent with how their peers use it? An engineer connecting an MCP server to their own repository is ordinary. The same person connecting that server to a finance team's database is not, regardless of whether the tool itself is approved.
Is sensitive data flowing into the tool? An employee pasting a public API doc into an AI assistant is low risk. The same employee pasting a customer list or board deck is high risk, even if the AI tool is on the approved list.
Has the tool's configuration changed since it was approved? AI tools are modular. A coding assistant that had two plugins at approval time might have twelve now, each with its own permissions and data access. The approval covered the tool as it existed then, but the risk surface is the tool as it exists now.
These questions require behavioral baselines, peer-group comparisons, and continuous monitoring of how tools are configured and used over time. A static approved-tool list can't answer them.
How Anzenna Helps
Anzenna gives you the discovery, posture management, and behavioral monitoring layers without adding agents to your endpoints or proxies to your network.
- Full AI surface discovery across browser and desktop. Anzenna detects web logins to AI services and distinguishes personal from corporate accounts, AI browser extension installs, OAuth grants to AI providers, DNS-level traffic, desktop AI app installs, IDE extension installs, MCP client and server connections, configuration changes, leaked AI provider API keys, and unapproved LLM usage. You get a complete picture of AI adoption across your workforce, not just what's on the approved list.
- Direct hooks into major AI platforms. Anzenna has hooks into Claude Code, Claude Desktop, GitHub Copilot, Microsoft 365 Copilot, Cursor, Gemini, Codex, Windsurf, and others. These hooks provide visibility into what those tools actually do on a managed device, from file reads and shell commands to MCP server connections and configuration tampering.
- MCP server security scanning. For every MCP server Anzenna discovers, it scans the server's dependencies for known vulnerability advisories and analyzes its tool definitions for injection risk. You see which servers are safe, which carry known CVEs in their packages, and which expose tools that could be exploited through prompt injection.
- Per-tool posture management. For each AI client, you can set a posture level: permissive (log activity without disruption), balanced (warn users on risky actions and record events), or strict (treat specified operations as policy violations). You configure which MCP tools are allowed per client. The controls are graduated, not binary.
- Peer-group baselines for AI usage. Anzenna doesn't flag "employee used an AI tool" as a finding. It flags "employee used an AI tool in a way that deviates from how their peers use it." An engineer wiring an MCP server to their own repo is normal. The same tool reaching across the org is not. The baseline adapts to role, department, and individual history.
- Every action tied to a person. AI activity on its own is noise, but AI activity tied to the employee behind it, their role, employment status, peer group, and behavioral history, is actionable context. Anzenna connects the two so your security team can distinguish productivity from risk.
- Investigation Agents write the case. When an AI-related finding warrants investigation, Anzenna's Investigation Agents draft a case file: what tool was involved, what data was accessed, who was behind the activity, how the behavior compares to baseline, what the recommended action is. Your analyst reviews a narrative, not a raw log. Median case draft time is under 2 minutes.
- Agentless, metadata-only, read-only by default. Anzenna doesn't read the content of what employees type into AI tools. It reads metadata: which tools, which endpoints, which data stores, how much, how often, by whom. No endpoint agents. No browser proxies. No inline content inspection. 15-minute install through API integrations with tools you already run. SOC 2 Type II certified.
Built to Be Trusted
AI enablement programs fail when employees perceive the governance layer as surveillance. If people believe their AI usage is being watched in a way that punishes productivity, they'll find ways around it. That's how you end up back at shadow AI.
Anzenna is designed around this constraint. It's agentless, so there's no daemon on the employee's machine. It reads metadata, not content, so there's no keystroke logging or screen capture. It connects through APIs to the stack you already run (CrowdStrike, Jamf, Okta, Entra, GitHub, Slack, and 130+ others), so your architecture stays unchanged.
Across its customer base, Anzenna has blocked 81,400 AI uploads and 79,500 exfiltrations, protecting more than 756,000 users.
As one security leader put it:
We had no insights into our AI usage and Anzenna was able to provide us with a comprehensive visibility layer.
The Real Lesson
The organizations that get the most from AI will be the ones that built visibility early enough to let their workforce move fast without losing control of where the data goes.
AI enablement means having enough visibility to say yes to the right things and set guardrails around the gray areas before a policy gap becomes an incident.
Your employees are going to use AI. Give them a path that works for both of you.
Ready to see what your AI surface actually looks like? Request a demo and see it on your data in 30 minutes.
Statistics sourced from Microsoft Work Trend Index (2025 and 2026), McKinsey State of AI (2025), Stanford HAI AI Index (2026), ISACA AI Pulse Poll (2025), GitHub Copilot research, PwC Global AI Jobs Barometer (2025-2026), IBM/Ponemon 2025 Cost of a Data Breach Report, Verizon 2025 Data Breach Investigations Report, and Gartner (2025-2026 predictions). Anzenna product metrics from anzenna.ai.