Newsroom >
AI Governance

The AI You Can't See: 66% of CISOs Admit Only "Limited Visibility" Into AI Across Their Org

July 15, 2026
Topics
AI Governance
Share

Enterprise AI adoption is moving faster than security teams can track it.

A recent benchmark survey of 300 U.S. CISOs found that 67% report having only limited visibility into how AI is deployed across their organizations, while not a single respondent claimed full visibility into enterprise AI usage. 

The findings highlight a growing gap between AI adoption and AI governance as organizations rapidly deploy copilots, AI agents, and embedded AI features.

The Visibility Gap Is Becoming a Security Risk

The report identifies limited AI visibility as one of the biggest barriers to securing enterprise AI, alongside a lack of AI expertise and purpose-built security tools

As AI usage expands across business units, security teams often struggle to identify which AI applications employees are using, what data those tools can access, and where sensitive information is flowing.

The trend extends beyond one study. Recent research from Protiviti found that 47% of large enterprises lack full visibility into employee AI usage, while IBM reported that 70% of technology leaders believe AI adoption is moving faster than IT can track.

AI Agents and Shadow AI Are Expanding the Blind Spot

The visibility challenge has become more complex with the rise of AI agents and embedded AI capabilities.

Unlike standalone AI applications, AI agents can maintain persistent access to enterprise systems through APIs and OAuth permissions, while embedded AI features often operate inside existing SaaS platforms. 

At the same time, employees continue using personal AI accounts outside corporate oversight, creating additional blind spots for security teams.

These trends are shifting AI governance from simply discovering AI tools to continuously monitoring AI identities, permissions, and data access.

What It Means for Enterprises

The findings suggest that AI governance can no longer rely on inventories or approved application lists alone.

Organizations increasingly need visibility into which AI tools are in use, what data they can access, who is using them, and whether AI agents retain persistent permissions. 

Without that context, security teams may be governing only a fraction of their actual AI footprint.

As enterprises scale AI adoption, platforms that combine AI discovery, Shadow AI detection, browser-level controls, and AI identity governance, such as CloudEagle.ai can help close these visibility gaps.

The Biggest AI Risk Is The One You Missed

It's already in use.
Find It

Get Our CloudEagle Newsletter

Let the headlines come straight to you with Access Granted — a monthly edition of Okta announcements, expert perspectives, analysis, and more.