67% of US workers are currently using unapproved AI tools to get their jobs done. This isn’t just a minor policy infraction; it is a fundamental disconnect between how work actually happens and how it is managed. While employees are busy integrating autonomous agents into their daily workflows, enterprises are scrambling to build a governance stack that, for now, feels like a ship passing in the night.
The scale of this shadow AI usage is staggering. According to the Okta ‘AI Agents at Work 2026’ survey, the US leads the world in this behavior, with workers bringing their own tools to the office 78% of the time. Meanwhile, 92% of executives report that autonomous AI agents are already in widespread or moderate use within their organizations. The problem is that these two groups are operating in different realities.
In a frantic attempt to bridge this divide, a new governance stack emerged in August 2026. Within a single week, the industry saw the general availability of Okta Agent SSO, IBM AgentOps, and Broadcom AgentMinder. Each of these tools targets a different layer of the stack: Okta focuses on identity, IBM on orchestration and evaluation, and Broadcom on runtime and action authorization. It is a sophisticated response, but it assumes that the enterprise has a clear view of the battlefield.
The reality is far messier. There is a massive gap between executive perception and technical visibility. While 90% of executives express confidence in their visibility into AI tools, only 11% of those applications are actually visible to IT. This is the core of the shadow AI problem: you cannot govern what you cannot see. Even when organizations do attempt to apply controls, they are often inconsistent. Only 34% of organizations currently apply the same security standards to AI agents as they do to human workers.
This lack of visibility creates a dangerous measurement problem. Gartner projects that Fortune 500 companies will run over 150,000 AI agents by 2028, a massive leap from fewer than 15 in 2025. Yet, according to Dataiku and Harris Poll, only 5% of AI output is fully traceable. Without traceability, the enterprise is essentially flying blind, hoping that the agents running on their networks are acting in accordance with company policy.
The human and financial costs of this gap are mounting. The median time to detect unauthorized AI tools is 403 days, leaving a massive window for data leakage or security incidents. ISACA reports that 67% of CISOs have dealt with a security incident linked to an unsanctioned AI tool in the last year, and 58% of executives have reported a similar close call. On average, shadow AI costs enterprises $670,000 annually, with the average breach cost reaching $4.99 million.
It is important to note that these governance tools are not a silver bullet. While they provide the necessary infrastructure to manage identity, orchestration, and authorization, they only work if they are actually deployed and adopted. The existence of a governance stack does not automatically solve the shadow AI problem if the tools are too cumbersome for employees to use.
The data suggests that the most effective way to curb shadow AI is not just through restriction, but through provision. Research from CSA and Unseen indicates that providing approved AI alternatives can cut unauthorized use by 89%. When employees have access to tools that are both secure and functional, they are far less likely to go rogue.
As we look toward 2028, the race between shadow AI adoption and enterprise governance will only intensify. The governance stack is finally being built, but it is currently playing catch-up to a workforce that has already moved on. Until the visibility gap is closed and security controls are applied consistently, the enterprise will continue to absorb the risk of a shadow stack that it neither sees nor controls.