Why the fastest way to get AI into your company is through the security team

Three-quarters of employees are already using AI at work. Security chiefs who build safe on-ramps are winning influence; those who say 'no' are being routed around.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial shot of a modern open-plan office at dusk, warm desk lamps glowing, several laptop screens showing generic chat interfaces with s
Share

Key points

  • McKinsey's 2024 State of AI report found 76 percent of employees now use AI at work, up from 55 percent the year before.
  • Most of that use is happening outside any formal review, on personal accounts and free tools.
  • Security teams that build a fast, sanctioned path to AI are gaining board influence; those that block it are being bypassed.
  • The practical fix is a lightweight approval lane, not a 40-page policy nobody reads.

Here is the uncomfortable bit for anyone still drafting an AI acceptance policy in a Word document. Your staff already made the decision for you.

McKinsey's latest State of AI survey, cited this week by The Hacker News, says 76 percent of employees are using AI in some part of their job. A year ago it was 55 percent. That is a big jump in a short time, and most of it is happening without the security team knowing about it.

What does this actually mean for a normal company?

It means people are pasting work into chatbots. Sales staff drop customer emails into ChatGPT to rewrite them. Finance people ask an AI to summarise a spreadsheet. Developers get code suggestions from a free assistant. Nurses, teachers, shop managers, the same story everywhere.

Most of that traffic is going through personal accounts on home laptops or phones. Which means the company has no record of what left the building, no way to pull it back, and no audit trail if a regulator asks.

In practice, the failure mode here is not a dramatic hack. It is a slow leak of customer data, product plans and internal documents into training sets and chat histories the company does not own.

Why blocking it does not work

Security teams have tried the old playbook. Block the domain. Add it to the acceptable use policy. Send a stern email.

Staff route around it. They use their phones. They forward things to a personal Gmail. They screenshot a document and retype it into Claude at home. One thing the post-mortem will say, every time, is that the tool was too useful to give up and the sanctioned alternative did not exist yet.

The security teams doing well right now have flipped the script. Instead of being the department of no, they are running the on-ramp. They pick two or three enterprise AI tools with proper data handling, wire them into single sign-on, and make them the easiest option on a Monday morning.

What a working AI on-ramp looks like

A few concrete pieces show up in the companies getting this right.

First, an enterprise contract with the AI vendor, so prompts are not used for training and there is a data processing agreement on file. That is table stakes for anything involving customer information under GDPR or HIPAA.

Second, logging. Every prompt and response captured, the same way you would log a database query. If your team cannot answer 'what did marketing ask the AI about our unreleased product last Tuesday', you do not have governance, you have a policy PDF.

Third, a fast approval lane for new use cases. Two weeks, not two quarters. If it takes longer to get an AI tool approved than it takes to find a workaround, staff will find the workaround.

Fourth, training that treats staff as adults. Show them what data is fine to paste and what is not. Give examples from their actual job.

Why CISOs should care about the politics

The security leaders getting promoted this year are the ones the CEO calls before an AI project starts, not after. That only happens if the security team is seen as the group that makes AI possible, not the group that delays it.

Vendor pitch decks will call this 'AI governance transformation'. Strip the PR and it is simpler. Build the safe path, log everything, review quickly, and staff will use the front door.

Operational takeaway: if your sanctioned AI tool is harder to use than the free one, you have already lost the visibility fight.

© 2026 Threat Vectr