Artificial intelligence has become a routine part of everyday work: employees increasingly rely on AI tools to complete tasks faster and more efficiently. At the same time, many organizations have not kept pace with this adoption and still lack clear internal policies or secure, auditable frameworks for managing AI use.
What is "shadow AI" and why is it risky?
According to a KPMG survey, 58 percent of employees use AI tools daily, yet 44 percent do so partially or entirely in ways that conflict with corporate policies. Experts call this phenomenon shadow AI—when staff employ AI solutions that are not approved or supervised by their organization.
Swami Chandrasekaran, KPMG’s U.S. and global leader for AI and data solutions, said: “Shadow AI is not an isolated phenomenon, but a sign that employees are faster than the systems meant to support them. With proper frameworks, however, shadow AI can be a source of innovation, agility and long-term competitive advantage.”
Shadow AI poses particular hazards where sensitive business data are involved: uncontrolled AI use increases the likelihood of data leaks and compliance breaches. KPMG also reports that 46 percent of employees have uploaded sensitive corporate data or intellectual property to publicly accessible AI platforms.
Regulation is lagging behind adoption
McKinsey’s research shows that 88 percent of organizations regularly use AI in at least one business area. Nevertheless, KPMG finds that only 41 percent of employees say their workplace has clear internal guidelines for generative AI use.
An ISACA Europe survey found a similar gap: 83 percent of respondents said employees are actively using AI tools, while only 31 percent of organizations have comprehensive, official AI policies. In other words, practice often outpaces governance, leaving room for informal and hard-to-control AI usage.
Ban or controlled rollout?
For most companies, the question is not simply whether to ban AI. A blanket prohibition is often ineffective, particularly where AI is already embedded in daily workflows. Many experts and vendors therefore recommend combining clear internal rules and employee training with controlled enterprise platforms that support productivity while reducing the risks of data leakage and unauthorized applications.
Secure AI on private infrastructure — the SUSE approach
SUSE experts argue that the answer lies in enterprise AI environments that are fully controllable, auditable and can run on an organization’s own infrastructure. The SUSE AI platform enables companies to run AI models on their own systems so that data do not leave a controlled environment.
The platform can operate on-premises, in cloud setups, or on air-gapped infrastructure disconnected from the internet, making it adaptable to varying business and compliance requirements. This is particularly beneficial in industries where data security and regulatory compliance are critical.
SUSE’s solution also provides detailed visibility into AI operations: it tracks application token usage and associated costs, and continuously monitors GPU resource utilization and performance. These metrics support more accurate cost planning and more transparent, efficient operation of enterprise AI deployments.
Conclusion
Organizations should move from prohibition toward control and transparency: clear internal policies, employee training, and auditable enterprise AI platforms can reduce the data and compliance risks associated with shadow AI while preserving the productivity gains offered by AI tools.



