Tankeledere
Hva tallene om Shadow AI skjuler

Ansatte i de fleste organisasjoner bruker allerede AI‑verktøy som arbeidsgiveren deres aldri har godkjent. På dette tidspunktet burde det ikke overraske noen. Ansatte har alltid gravitetet mot teknologier som hjelper dem å arbeide mer effektivt, uavhengig av om verktøyene ble formelt introdusert av IT. AI har bare akselerert denne atferden.
Hastigheten på AI‑adopsjon er bare en del av historien. Det som er mer avslørende, er hva den forteller oss om miljøene der adopsjonen skjer. Når ansatte velger sine egne AI‑verktøy, er det ofte et tegn på at IT mangler et komplett bilde av hvordan arbeidet utføres. De samme organisasjonene som sliter med å identifisere uautoriserte AI‑bruk, kan også ha problemer med treg oppdatering, inkonsekvent kryptering eller enheter som faller utenfor etablerte sikkerhetspolicyer. Shadow AI skaper ikke disse svakhetene, men kan sette dem i skarpere fokus.
Vår egen State of Digital Workspace 2026‑rapport analyserte telemetri fra millioner av administrerte enheter på tvers av 17 bransjer, og unngikk begrensningene ved å be ansatte om å huske eller oppgi hvilke verktøy de bruker. Den fant at bruken av AI‑assistenter økte med nesten 1 000 prosent i 2025, noe som gjør den til den raskest voksende applikasjonskategorien på arbeidsplassen.
The figure tells us how quickly employee behaviour is changing. It also opens a less familiar line of enquiry: do organisations with high exposure to unapproved applications show weaknesses in more established areas of device management? Healthcare provides the clearest indication that they might. In our study, healthcare appears among the industries most exposed to compliance risk from unsanctioned applications; and elsewhere in the report also records some of the slowest patching and higher rates of unencrypted desktops.
Adopsjon er bare en del av bildet
Understanding which AI tools employees use is only one piece of the puzzle. The more revealing question is why they choose them, because those decisions often highlight the gap between the workplace IT believes it has created and the one employees experience every day.
The distribution between approved and unapproved AI tools becomes more revealing once use is established. Microsoft Copilot is installed widely on managed mobile devices where IT controls deployment, helped by its position within Microsoft 365. Outside that managed environment, ChatGPT leads by a considerable margin. It appears on 91 percent of unsanctioned iOS devices and 61 percent of unsanctioned Android devices, while Gemini accounts for much of the remaining Android use.
Approved and self-selected services can easily coexist within one working environment. Employees may have access to the corporate AI service and still turn to another tool because they find it faster, more familiar or better suited to a particular task. From their perspective, this is often the most practical and quickest way to get their job done. For IT and compliance teams, it creates uncertainty about which applications are handling company information and whether existing governance policies are being followed.
The pattern within communication software is similar. Consumer messaging applications account for nearly half of the communication tools installed across managed desktop platforms, alongside Teams, Zoom and Slack. Financial services and healthcare, despite their strict record-keeping obligations, are not exempt. The compliance problem begins when an organisation assumes that sensitive conversations remain within approved channels. A policy query, patient discussion or internal decision moved into a consumer application may no longer sit within the systems used for retention, monitoring or investigation. The employee involved may have no intention of bypassing controls and may simply be using the channel where a colleague responds most quickly.
These patterns point to a broader shift in how work gets done. Employees are increasingly moving between applications, browsers and AI services that don’t always fit neatly into traditional management models. The challenge isn’t simply identifying another application. It’s maintaining a clear understanding of how work happens across the environment so governance can keep pace with employee behaviour.
AI‑adopsjon og enhetshygiene beveger seg i ulikt tempo
The rapid adoption of AI has exposed another reality of enterprise IT: technology doesn’t evolve at the same pace across the organisation. Employees can begin using an AI service within minutes, without a procurement process or a support ticket.
Closing a device management gap can take months, particularly across mixed estates containing corporate laptops, shared devices, ruggedised hardware and employee-owned phones. The telemetry shows wide variation in patching speed. iOS devices reach the latest version roughly eight times faster than Android devices, while macOS updates around one and a half times faster than Windows.
Encryption coverage is also uneven; 23 percent of banking desktops are unencrypted, and the figure rises to around 27 percent in healthcare and high tech, and 28 percent in media and entertainment. More than half of desktop and mobile devices in education are unencrypted, while in government one desktop in five has no encryption.
The industry breakdown for operating system updates adds more context. Healthcare, pharmaceuticals and retail and wholesale have the highest concentrations of Android devices running four or five generations behind the current release. The information exposed by a missed patch differs across those environments, from patient records and clinical data to drug research and payment information.
Older devices are often embedded in operational settings where replacement and maintenance are difficult. A ruggedised handheld on a hospital ward or warehouse floor may still be running an operating system release several major versions out of date, while staff in that environment have access to the latest public AI services. The AI use may attract immediate concern, even though the ageing endpoint presents a longer-standing route to sensitive information.
This is where the relationship between AI adoption and endpoint management becomes clearer. The report places shadow perimeter risk and security hygiene in separate chapters, but healthcare appears in both. It is identified for compliance exposure arising from unsanctioned applications, then appears again because of its slow operating system updates and relatively high rate of unencrypted desktops. That overlap can remain hidden when security, device management and application information sit in separate systems. Each team may have an accurate view of its own part of the estate while missing the concentration of risk across them.
Den regulatoriske tidsplanen har endret seg
Some organisations have expected regulation to create the pressure needed to address these gaps, although the timetable now gives them longer than previously anticipated. Under the political agreement reached by EU negotiators on 7 May, the high‑risk obligations of the AI Act for standalone systems under Annex III have moved from august 2026 to desember 2027. This is the category under which many enterprise AI deployments are expected to fall. Transparency obligations still apply from august 2026, while the broader requirements that would prompt many organisations to create AI inventories and formal risk assessments now arrive sixteen months later.
The delay gives organisations more time to prepare, but it also removes an immediate external deadline that might have accelerated investment.
The market is responding to a recognised governance gap, although the value of that spending will depend on how well those platforms connect with the wider endpoint estate. A separate AI governance dashboard may identify which tools are in use while leaving device condition, encryption and application performance somewhere else. Regulation can set expectations and define accountability, but it cannot create a complete operational picture unless the underlying data can be brought together.
Endepunktet er viktig for alle som implementerer AI
Every organisation’s AI strategy will ultimately depend on the devices employees use every day. That’s true whether AI is delivered through a browser, embedded into a business application or running directly on the endpoint.
Developers and enterprise teams deploying assistants, agents or on-device models must work with the devices employees already use. These devices may be older, heavily managed or already under performance pressure. On Windows desktops, IT administration, security and system tools account for close to two‑thirds of the installed software stack. Endpoint protection, patch management, encryption and asset inventory agents all compete for processor capacity and memory before an AI workload begins.
Adding an assistant to that environment changes the demands placed on the device. This is particularly relevant for on-device inference and agentic workflows, where reliability and available computing resources affect whether the service responds as expected. The Digital Workspace 2026 Report found that Windows devices experience 3.1 times more forced shutdowns and 7.5 times more unresponsive application states than Macs. As employees begin to depend on AI assistants during routine work, those reliability differences have a direct effect on adoption and trust. A service that is unavailable, slow or inconsistent at the moment it is needed will soon be bypassed.
A recently issued executive laptop and a shared clinical device might belong to the same organisation, yet sit at opposite ends of patching, performance and control. Designing an AI deployment around an idealised endpoint risks overlooking the places where implementation will be hardest. Those weaknesses are often concentrated in regulated and operational environments, where devices stay in use for longer and interruptions can affect frontline work. These are also the settings where poor visibility carries the greatest consequences.
Se hele miljøet
Policies remain necessary, but their reach is limited when an organisation cannot see which tools employees use or the condition of the devices through which they access them. Employees will continue to select services that help them complete a task quickly. Some will use an approved assistant, while others will choose a public service that feels easier or produces a better result. Written rules alone will not give IT teams an accurate account of that behaviour.
The operational challenge is to understand AI use in context, which might include the age of the device, its operating system, patch status, encryption coverage and the applications already running on it. Viewed separately, each data set may appear manageable. Combined, they can reveal where several weaknesses are accumulating around the same employees, devices or business processes. Regulated organisations should begin by bringing AI usage, patching and encryption information into a shared view, then identify the parts of the estate that appear repeatedly across those data sets. Shadow AI may be the most visible sign of the problem, while the wider risk sits in the gaps between the systems used to manage the workplace.












