Gather Synthetic
Pre-Research Intelligence
Custom Research

"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"

Persona Types
8
Projected N
150
Questions / Interview
5
Signal Confidence
Avg Sentiment

⚠ Synthetic pre-research — AI-generated directional signal. Not a substitute for real primary research. Validate findings with real respondents at Gather →

Quantitative Projections · 150n · ±35% margin of error

By the numbers

Projected from interview analyses using Bayesian scaling. Treat as directional estimates, not census measurements.

Feature Value
—/10
Perceived feature value
Positive Sentiment
12%
89% neutral · 49% negative
High Adoption Intent
0%
0% medium · 0% low
Pain Severity
—/10
How acute the problem is
Sentiment Distribution
12%
89%
49%
Positive 12%Neutral 89%Negative 49%
Theme Prevalence
Shadow AI visibility gap
91%
Policy vs. enforcement misalignment
87%
Productivity vs. security tradeoff
83%
Data leakage and residency risk
79%
DLP and detection capability gaps
74%
Organizational ownership ambiguity
71%
Persona Analysis

How each segment responded

Side-by-side comparison of sentiment, intent, buying stage, and decision role across all personas.

Interview Transcripts

Full interviews · 8 respondents

Complete question-by-question responses with per-persona analysis. Click any respondent to expand.

A
Alex R.
CTO · Series C SaaS · Seattle, WA
mixed92% conf
44 yrsB2B Tech$275kbuild vs buy mindset · security-first · vendor fatigue · API-obsessed

Alex is a technically fluent CTO grappling with a well-defined but unsolved Shadow AI governance problem. He is neither panicked nor satisfied — he has partial controls in place (sanctioned Azure OpenAI, some API gateway guardrails) but acknowledges clear gaps in endpoint DLP, unsanctioned tool visibility, and policy adoption. His framing is pragmatic: he understands why employees reach for unauthorized tools and is skeptical of enforcement-only approaches. His primary unmet needs are audit-trail-level prompt visibility and verifiable data residency — not marketing assurances. He would respond positively to vendors who offer genuine transparency and operational simplicity over SOC 2 reports alone. Overall tone is measured and analytical, with frustration directed at the problem complexity, not at any vendor or team.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night right now is that we've got engineers and product folks using AI tools in ways that our procurement and security teams have basically zero visibility into. It's not malicious — people are trying to move fast — but when someone pastes a customer data schema or internal API docs into ChatGPT or Claude to get help debugging, that's a data leakage event whether we called it one or not. The harder problem is that the traditional "block it at the firewall" approach just doesn't work anymore. People are on laptops, on phones, using personal accounts. So I'm wrestling with how do you actually enforce a meaningful policy without completely killing productivity, because the pressure from leadership to ship AI-enabled features is real and constant. We're also evaluating whether to route everything through Azure OpenAI or Bedrock where at least we're the tenant and the data handling terms are clearer — but that still doesn't solve for the person who just opens a browser tab on their own. I don't have a clean answer on enforcement yet, which is frustrating.

2

What's the most important thing you need to understand or solve here?

The core problem for us right now is visibility. We don't have a complete picture of what AI tools our engineers and product folks are actually using day-to-day. Someone's running code through ChatGPT, someone else is using Claude via a personal account — and that data is potentially leaving our environment without any audit trail. The second piece is that even when we do have sanctioned tools, I'm not fully confident about where the prompt data goes and how it's retained on the vendor side. OpenAI says it's secure, fine, but when we're talking about customer data or proprietary product logic, "they say it's secure" isn't a posture I can defend to our board or to a customer during a security review. So the short version: visibility into what's being used, and data residency confidence on the tools we do sanction. Those are the two things I need to actually solve before I can have a coherent Shadow AI policy.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having a clear inventory of every AI tool touching our environment — sanctioned or not — with data classification enforced at the point where a prompt leaves our perimeter. So if someone's pasting customer PII or proprietary pricing logic into some random ChatGPT wrapper, that gets flagged or blocked before it ever hits a third-party API. The policy layer and the technical enforcement layer are actually aligned, which is rarer than it sounds. How far are we? Honestly, we're probably 60% there on the sanctioned tooling side. We've got decent controls around the tools we've approved — Azure OpenAI with our own tenant, some guardrails at the API gateway level. Where it breaks down is the unsanctioned stuff. Someone installs a browser extension, or they're copy-pasting into a free tier of some tool on their personal browser, and we have limited visibility into that. Our DLP coverage has gaps at the endpoint, especially for browser-based exfiltration. The other piece we're still working through is policy clarity. We have an AI acceptable use policy, but I'd be surprised if more than half the team has actually read it. So there's a cultural enforcement gap on top of the technical one. Those two things together — incomplete visibility and inconsistent policy adoption — are where most of the real risk lives for us right now.

4

What would change your perspective on this entirely?

Honestly? If I saw a vendor actually solve the data residency and prompt logging problem in a way that was genuinely transparent — not just a SOC 2 report and a handshake — that would shift things meaningfully for me. Right now the core issue is that when an employee pastes something into a third-party AI service, I have limited visibility into what left the building and where it went. If someone built tooling that gave me actual API-level audit trails on every prompt, with real tenant isolation and verifiable data handling, and didn't require me to trust their marketing copy — that changes the calculus. The other thing that would move me is if the internal deployment story got meaningfully cheaper and less operationally heavy. Right now the "run it yourself" path is appealing from a security-first standpoint but the infrastructure overhead is real. If that gap closes, the build-or-self-host argument gets a lot stronger and I stop having to weigh security against operational burden every time.

5

What question are you not being asked that you wish someone would ask?

Honestly, I don't have some grand "the question nobody asks" framing ready for you. But if I had to pick something... I think people spend a lot of time asking about detection — how do you find Shadow AI, how do you know what data left the building — and not enough time asking about *why* employees reach for unauthorized tools in the first place. Because in my experience, when someone on my team is pasting customer data into a public LLM, it's usually because the approved internal tooling is too slow, too limited, or requires jumping through too many hoops to get access. The policy failure and the usability failure are the same failure. And if you only solve for detection and enforcement without fixing that underlying friction, you're just playing whack-a-mole.

"The policy failure and the usability failure are the same failure. And if you only solve for detection and enforcement without fixing that underlying friction, you're just playing whack-a-mole."
Language Patterns for Copy
"data leakage event whether we called it one or not""block it at the firewall just doesn't work anymore""visibility into what's being used and data residency confidence""60% there on the sanctioned tooling side""DLP coverage has gaps at the endpoint""I'd be surprised if more than half the team has actually read it""not just a SOC 2 report and a handshake""actual API-level audit trails on every prompt""approved internal tooling is too slow, too limited, or requires jumping through too many hoops"
A
Alex R.
CTO · Series C SaaS · Seattle, WA
mixed92% conf
44 yrsB2B Tech$275kbuild vs buy mindset · security-first · vendor fatigue · API-obsessed

Alex is a technically grounded CTO operating in a recognized but partially unsolved risk posture around AI tool sprawl. He is neither alarmed nor complacent — he understands the problem clearly, has taken initial steps (acceptable use policies, enterprise licenses, network monitoring), and estimates he is roughly 60% toward his definition of 'good.' His primary concerns are visibility into unsanctioned AI tool usage, the gap between policy and technical enforcement, and the inadequacy of vendor contractual assurances as a substitute for verifiable architectural controls. He is also grappling with an organizational tension between enabling AI adoption and managing data risk. The most underexplored area he identifies is detection rather than prevention — knowing when Shadow AI is occurring, not just prohibiting it. His tone is measured and pragmatic throughout; he acknowledges open problems without dramatizing them.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep coming back to is that we're playing a bit of a whack-a-mole game right now. We've got policies in place — acceptable use, data classification, the usual — but enforcing them when every SaaS tool your team uses is quietly adding an AI feature is genuinely hard. It's not like people are doing anything malicious. An engineer pastes some internal code into a coding assistant, a product manager drops a customer dataset into some summarization tool — they're just trying to move faster. But now that data has potentially left your control and you have no visibility into where it went. The vendor side makes this worse. Every quarter there's another tool in our stack that's added "AI-powered insights" or whatever, and half the time the data handling terms in those contracts haven't caught up. So I'm wrestling with whether our existing DLP controls even cover these new surfaces, or whether we've got gaps we haven't fully mapped yet. And then there's the pressure from leadership to actually *enable* AI adoption, not just lock things down. So it's less "should we allow this" and more "how do we build guardrails that don't kill productivity." I don't have a clean answer to that yet.

2

What's the most important thing you need to understand or solve here?

The core problem for us right now is visibility. We genuinely don't have a complete picture of what AI tools our engineers and product folks are actually using day-to-day. Someone's running Claude in their browser, someone else has a Cursor subscription on their personal card, and some of our sales team is pasting customer data into ChatGPT because it's just... easy. We can write all the policies we want, but if we can't see the surface area, we can't manage the risk. The second piece is that even when we do have approved tools, I'm not fully confident about what happens to our data on the other side. Vendors say they're not training on your data, they have enterprise agreements, whatever — but the contractual assurances and the actual technical controls are two different things. I'd rather have architectural enforcement than a ToS clause.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having a consistent, enforceable policy layer that sits between my users and whatever AI services they're hitting — whether that's something we've sanctioned or something they've found on their own. Ideally I know what data is leaving my environment, I have auditability on prompts and responses for anything touching sensitive data, and my developers aren't just copy-pasting customer PII into ChatGPT because it's faster. Where are we today? Honestly, we're maybe 60% of the way there. We've got acceptable use policies written down, we've deployed a couple of enterprise-licensed tools so people aren't just using personal accounts, and we've done some network-level monitoring. But the enforcement gap is real — I can't tell you with confidence right now exactly what's going out to third-party inference endpoints. That's the part that bothers me most. The other piece I'd flag is that my posture on prompt data is still more "trust and hope" than "verify." We've had conversations about private cloud deployments or single-tenant arrangements for the more sensitive workflows, but that adds cost and complexity, and I haven't fully solved the tradeoff yet. So we're making progress, but "good" is still a moving target.

4

What would change your perspective on this entirely?

If we found a technical control that actually worked at scale without becoming its own management burden. Like, right now the gap between "we have a policy" and "we can enforce it" is pretty wide. If someone showed me a solution that could do real-time inspection of AI traffic, accurately classify what's sensitive versus not, and integrate cleanly into our existing stack via API — not another fat agent on every endpoint — that might shift how I think about the problem. The other thing that would change my view is if the major providers — your Microsofts, your Anthropics — got serious about enterprise data isolation in a way that was actually verifiable, not just a terms-of-service promise. Right now I have no real audit trail proving our prompts aren't feeding someone else's training pipeline, and until that's solved with something I can actually point to in a compliance review, the skepticism stays.

5

What question are you not being asked that you wish someone would ask?

Honestly, I think the more interesting question is around *detection* versus *prevention*. Everyone asks me "how are you preventing Shadow AI?" But nobody asks "how do you even know when it's happening?" Those are two very different problems. We've put policies in place, we've got an acceptable use policy that covers GenAI, but the actual telemetry to detect when someone on my engineering team is piping customer data into some third-party API — that's genuinely hard. Network egress monitoring catches some of it, but it's incomplete. I don't have a clean answer to that detection question, which is kind of the point. I'd rather someone push me on that gap than ask me to walk through our policy documentation.

"The contractual assurances and the actual technical controls are two different things. I'd rather have architectural enforcement than a ToS clause."
Language Patterns for Copy
"whack-a-mole game""enforcement gap""can't see the surface area, can't manage the risk""trust and hope rather than verify""architectural enforcement over a ToS clause""real-time inspection of AI traffic""detection versus prevention""good is still a moving target"
J
Jordan K.
Senior PM · Fintech Startup · Austin, TX
mixed92% conf
28 yrsFintech$130klean methodology · user research believer · rapid iteration · engineering-empathetic

Jordan is a measured, analytically grounded senior PM navigating a real but not-yet-critical AI governance challenge in a fintech environment. The core tension is between leadership pressure for AI adoption and genuine compliance exposure around PII and payment data. Jordan's primary concern is visibility — not knowing what tools are being used or what data is leaving the organization — rather than opposition to AI use itself. The posture is pragmatic and risk-aware rather than fearful: Jordan explicitly wants to avoid blanket restrictions and understands the productivity tradeoffs. The unsolved problems are governance ownership (no clear internal mandate), tooling immaturity for monitoring third-party API usage, and a policy-practice gap where approved tools coexist with unapproved shadow usage. Jordan is open to loosening controls given credible vendor transparency, but current caution stems from unverifiability rather than ideology. Tone throughout is calm and reflective — this is someone who has thought carefully about the problem but is genuinely still working through it.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Yeah, so the thing I keep coming back to is that we're in this weird middle ground where leadership is pushing hard for AI adoption — like, everything needs to have an AI story — and at the same time our security and compliance folks are genuinely worried about what's actually leaving the building when engineers or analysts just... start using whatever tool they found. For us specifically, the fintech context makes it sharper. We're dealing with PII, transaction data, some fairly sensitive customer behavior stuff. So the question of what happens when someone pastes a data sample into a third-party model to debug something — that's not hypothetical, that's probably already happened. I just don't have full visibility into it. What I'm honestly wrestling with is the policy side. We don't have a great answer yet for how to draw the line between "sanctioned AI usage" and shadow usage, without just... blanket blocking things and killing productivity. Because I've seen that movie too — you restrict everything, people find workarounds anyway, and now you have the same risk plus resentment. So it's less about the technology itself and more about governance that actually works in practice. That's the unsolved thing for me right now.

2

What's the most important thing you need to understand or solve here?

The biggest thing for us right now is just getting visibility into what's actually happening. Like, I know people on my team are using ChatGPT, Claude, probably a handful of other tools — and I don't have a clear picture of what data is going into those prompts. We handle payment data, some lending-adjacent stuff, and the compliance exposure there is real. It's less about blocking everything and more about understanding the actual blast radius if something goes wrong. I don't have a strong view yet on the right technical solution — whether that's some kind of proxy layer, or pushing toward enterprise-licensed versions of these tools where at least the data handling terms are clearer — but the first step is just getting honest about what's being used and why. Right now I feel like we're making policy decisions with incomplete information.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like a state where we have visibility into what tools people are actually using, some sensible guardrails around data classification, and a policy that people actually follow because it makes sense to them — not just because compliance said so. Right now I'd say we're somewhere in the middle. We have a policy on paper, we've approved a handful of tools, but I know people are using things outside that list. It's that classic thing where someone posts a solution in Slack and half the thread is "wait, is this approved?" rather than actually engaging with whether it solves the problem. That gap between policy and practice is what I'd really want to close. The honest answer is we're probably 40-50% of the way there. The tooling to get full visibility into what's actually going out to third-party services like OpenAI or whoever — that's still pretty immature for us. And on the data leakage side, we handle some sensitive financial data, so the question of what's hitting external APIs is genuinely not trivial. We don't have a clean answer for that yet.

4

What would change your perspective on this entirely?

That's a good question to sit with for a second. Honestly, if I saw solid evidence that the data leakage risks were actually much lower than we assume — like, if a vendor could show me a credible audit trail demonstrating that prompts containing sensitive data were truly isolated and never used for model training or exposed elsewhere — that would shift how aggressively I push back on tool adoption internally. Right now a lot of our caution is based on "we can't verify what's actually happening on their end," which is a reasonable but somewhat paranoid stance. The ask I keep coming back to is what one commenter put well — show me the architecture diagram, show me how you're segregating our data, show me the content monitoring controls. If vendors could actually deliver that transparency in a verifiable way, not just a checkbox in a SOC 2 report, my posture would probably loosen up considerably. The other thing that would shift my view is if our own users started demonstrating real harm from the shadow usage we're seeing, rather than just theoretical risk. Right now it's mostly "this could go wrong" — if it stayed that way for another couple years with no actual incidents, I'd probably conclude we've been over-indexed on fear and under-indexed on enablement.

5

What question are you not being asked that you wish someone would ask?

Honestly, I think the question people skip over is: "Who actually owns this problem in your org?" Because in most companies I talk to — and this is true for us too — shadow AI sits at this weird intersection of security, IT, legal, and the business units, and nobody has a clear mandate. So you end up with a policy document that exists somewhere but nobody's enforcing it, and the security team is pointing at the business, the business is pointing at IT, and meanwhile engineers and PMs like me are just using whatever tools help us ship faster. I'd love for someone to ask that accountability question more directly, because until you nail down ownership, all the technical controls in the world are kind of secondary.

"Until you nail down ownership, all the technical controls in the world are kind of secondary."
Language Patterns for Copy
"weird middle ground""governance that actually works in practice""actual blast radius if something goes wrong""policy that people actually follow because it makes sense to them""40-50% of the way there""show me the architecture diagram""shadow AI sits at this weird intersection""nobody has a clear mandate""over-indexed on fear and under-indexed on enablement"
J
Jordan K.
Senior PM · Fintech Startup · Austin, TX
mixed92% conf
28 yrsFintech$130klean methodology · user research believer · rapid iteration · engineering-empathetic

Jordan is a Senior PM at a fintech startup navigating genuine, day-to-day tension between leadership pressure to ship AI-enabled features quickly and real regulatory exposure from unsanctioned AI tool usage. The tone is pragmatic and candid — not alarmed, but genuinely unsatisfied with the status quo. The core concern is not sophisticated attacks but mundane, well-intentioned behavior: employees using personal ChatGPT accounts or unapproved coding assistants because approved tools are slower or less capable. Jordan frames Shadow AI as a visibility problem first, not a policy problem — and self-rates their organization at a 4/10 on readiness. Enforcement is thin, leadership deprioritizes compliance in favor of productivity gains, and vendor transparency on data segregation is insufficient. The most underexplored question Jordan identifies is how Shadow AI policy actually translates from org-level documents to individual contributor behavior — a gap they see as where the real risk lives.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Yeah, so the thing I keep coming back to is — we're a fintech startup, right, so we've got real regulatory exposure, we handle financial data, and at the same time there's this constant pressure to move fast and ship things with AI baked in. And those two things are in real tension right now. What I'm actually wrestling with day-to-day is less about the sophisticated attack vectors and more about the mundane stuff — like, someone on my team is pasting customer data into ChatGPT to summarize support tickets, or an engineer is using a coding assistant that's sending context to a third-party server, and nobody really knows what's in that context window. We don't have great visibility into that. It's not malicious, it's just... people finding the path of least resistance to get their work done. And the policy side feels underdeveloped. We have some guidelines, but enforcement is pretty thin. It's one of those things where leadership is excited about AI productivity gains, and the risk and compliance conversation kind of gets deprioritized because it's not as exciting. I've seen that pattern — everyone wants the AI features, fewer people want to sit down and think through what data is actually leaving the building. So yeah, that gap between "we said people shouldn't do this" and "we actually know whether people are doing this" — that's the thing I don't have a good answer for right now.

2

What's the most important thing you need to understand or solve here?

The thing I keep coming back to is: how do you actually know what's happening? Like, we talk about Shadow AI as a policy problem, but it's fundamentally a visibility problem first. If I don't know which tools my team is using or what data they're pasting into them, I can't even scope the risk, let alone address it. At our company specifically, the pressure from leadership is very much "we need to be AI-forward," and I get that, but the risk and compliance conversation doesn't always keep pace with that enthusiasm. So my practical concern is figuring out where the real exposure is — are people feeding customer PII into ChatGPT? Are they pasting in our transaction data? That's the stuff that actually matters from a fintech regulatory standpoint. I don't have a strong view yet on the right enforcement mechanism, whether that's tooling, policy, or some combination. But the starting point has to be understanding the actual behavior, not just writing a policy and hoping people follow it.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like a state where we have visibility into what tools people are actually using — not just the approved stack — and where policy enforcement isn't purely reactive. Like, I want to know when someone on my team pastes customer transaction data into a consumer ChatGPT instance *before* it becomes a compliance issue, not six weeks later in an audit finding. Where we are today? Honestly, we're probably at a 4 out of 10. We have an acceptable use policy that most people have technically acknowledged but probably haven't internalized, and we've got some approved tools — we went through the enterprise OpenAI procurement process specifically because of the data segregation concerns. But shadow usage is real. I see it. People are using personal accounts on their work machines because the approved tools feel slower or more restricted, and I don't have great telemetry on that. The gap for us is really around detection and culture simultaneously — it's not enough to block things at the network level if people just switch to mobile hotspots. So "good" also means people understand *why* the guardrails exist, not just that they exist. We're not there yet.

4

What would change your perspective on this entirely?

That's a good question. I think the thing that would really shift my view is if we started seeing Shadow AI actually cause a significant, well-documented breach at a major company — like not just a theoretical data leakage risk, but a real incident where someone pasted customer financial data into a public LLM and it surfaced somewhere else. Right now a lot of the conversation still feels precautionary, and leadership tends to treat it that way too. The other thing that would change my thinking is if the enterprise AI vendors — your OpenAIs, your Microsofts — got genuinely transparent about data segregation and security architecture in a way that was independently verifiable. Right now when I ask vendors how they're securing our data versus other tenants, the answers are pretty vague. If that became more rigorous and auditable, the calculus on what's an acceptable tool versus what's Shadow AI risk would shift considerably.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I'd want someone to ask is: "How does Shadow AI policy actually get enforced at the team level, not just the org level?" Because I feel like most of the conversation is happening at the CISO or security architecture layer — like, here's our policy document, here's our approved vendor list — but nobody's asking how that translates to individual contributors actually changing their behavior. Like, on my team, people know the policy exists, but the friction between "approved tool" and "tool that actually helps me ship faster" is real. And when leadership is pushing everyone to be AI-native and move fast, the enforcement question becomes genuinely complicated. You can't just say "use only the approved tools" when half the approved tools aren't solving the actual workflow problem someone has. I don't have a strong view on what the right answer looks like technically, but from a product and team management perspective, that gap between policy-on-paper and policy-in-practice feels like where most of the actual risk lives.

"The gap for us is really around detection and culture simultaneously — it's not enough to block things at the network level if people just switch to mobile hotspots."
Language Patterns for Copy
"path of least resistance to get their work done""policy side feels underdeveloped, enforcement is pretty thin""fundamentally a visibility problem first""we're probably at a 4 out of 10""people using personal accounts on their work machines because the approved tools feel slower""policy-on-paper and policy-in-practice""right now a lot of the conversation still feels precautionary""the answers are pretty vague""how does Shadow AI policy actually get enforced at the team level, not just the org level"
C
Chris W.
Head of Demand Gen · Series A Startup · Austin, TX
mixed88% conf
32 yrsB2B SaaS$135kpipeline-obsessed · channel tester · attribution headache · CAC-conscious

Chris is a demand gen leader at a Series A company navigating genuine but unresolved tension between AI productivity and data governance risk. He is aware that shadow AI usage is happening on his team without visibility or enforceable policy, and he's uncomfortable with that — but he frames the risk as largely theoretical compared to his immediate pipeline pressures. His primary concern is not security per se, but workflow continuity and avoiding downstream liability. He is notably resistant to the dominant security-first framing in these conversations and advocates for the underrepresented cost of over-restriction on revenue teams. His tone is measured, pragmatic, and self-aware — not alarmed, not dismissive.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep bumping into is that our team is using AI tools constantly — ChatGPT, Claude, whatever — and most of it is happening without anyone really signing off on it. Like, I'm not the security team, but I'm the one pasting campaign briefs, competitive intel, sometimes pricing context into these tools, and I've started to wonder how much of that is actually leaving the building in ways we don't fully understand. We're a Series A company, so we don't have a huge IT or security function sitting on top of this. The guidance is pretty thin. And the tension I feel is — if I slow down on using these tools, I'm probably slower than competitors who aren't thinking about it at all. But if something gets exposed — customer data, a positioning strategy we haven't announced — that's a real problem. I don't have strong visibility into what our actual policy is, or if there even is one. It's more like a general understanding that we should "be careful." That's not really a policy.

2

What's the most important thing you need to understand or solve here?

Honestly, for me it's less about the security side directly and more about the downstream effects on my team's workflow. Like, if IT or security locks down tools that my demand gen folks are relying on day-to-day — whether that's AI writing assistants, enrichment tools, whatever — that creates real friction and I need to understand where the guardrails are going to land before I build processes around something that might get shut off. The other piece is data. My team is constantly working with prospect data, campaign performance data, some CRM exports — and I genuinely don't have a great picture of what's flowing into which AI tools. That's a gap I know exists and I haven't fully solved it. The procurement thread around "what's actually going into OpenAI" resonates with me — we're not handling supplier pricing or anything super sensitive, but we do have intent data and pipeline data that I wouldn't want sitting in someone's training set. So I guess the core question for me is: how do I stay productive and keep my team moving fast, without inadvertently becoming the example in the security team's post-mortem slide deck.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, is knowing exactly what's happening with AI tool usage across my team without having to play detective. Like, if someone's pasting prospect data or competitive intel into a public ChatGPT session, I want to know that's a risk before it becomes a problem — not after. And I want a policy that's actually enforceable, not just a PDF that lives in a Confluence page nobody reads. How far are we from that today? Pretty far, honestly. Right now it's mostly honor system. We've got loose guidance around not putting customer data into consumer AI tools, but there's no real visibility into whether that's being followed. My team is using Claude, ChatGPT, some Perplexity — and I'd be surprised if every one of those sessions is clean from a data standpoint. The tooling to actually monitor that or enforce guardrails just isn't fully wired in yet for a team our size and budget.

4

What would change your perspective on this entirely?

Honestly, the thing that would shift my view the most is if I saw real, clear evidence that shadow AI was causing actual, measurable damage at companies my size — like a Series A or B SaaS — not just at big enterprises with massive compliance teams and legal exposure. Most of what I hear is hypothetical risk or it's framed around Fortune 500 scenarios that don't really map to where I am. The other thing would be attribution, ironically. If someone could show me a clean connection between, say, a rep pasting a prospect list into ChatGPT and a concrete negative outcome — a deal lost, a data incident, a compliance fine — that would make it feel more urgent. Right now it feels like a lot of the concern is theoretical, and I've got pipeline problems that are very real and very immediate competing for my attention.

5

What question are you not being asked that you wish someone would ask?

Honestly, I think the question nobody's really digging into is: **what's the actual cost to pipeline when you over-restrict AI access?** Everyone in these conversations is focused on the risk side — data leakage, shadow usage, policy enforcement — and that's legitimate. But nobody's asking the demand gen or revenue teams what it costs when your security policy is so locked down that your marketers are doing manually what a competitor's team is doing in a tenth of the time. Like, I get the compliance concerns, especially around sending proprietary stuff to third-party models. But if my team can't use AI-assisted tooling because IT locked it down, and a competitor's team can spin up campaign variations or do faster account research, that's a real CAC and velocity problem. I just don't see that trade-off being quantified in most of these security-focused conversations.

"How do I stay productive and keep my team moving fast, without inadvertently becoming the example in the security team's post-mortem slide deck."
Language Patterns for Copy
"most of it is happening without anyone really signing off on it""that's not really a policy""I need to understand where the guardrails are going to land before I build processes around something that might get shut off""mostly honor system""the concern is theoretical, and I've got pipeline problems that are very real and very immediate""what's the actual cost to pipeline when you over-restrict AI access""that's a real CAC and velocity problem"
C
Chris W.
Head of Demand Gen · Series A Startup · Austin, TX
mixed88% conf
32 yrsB2B SaaS$135kpipeline-obsessed · channel tester · attribution headache · CAC-conscious

Chris is a pragmatic demand gen leader who is aware of Shadow AI risk but does not yet feel acute pain from it. His primary concern is lack of observability into what data his team is sending to AI tools — he frames this as both a security and competitive intelligence issue. He is not alarmist; he self-assesses his organization at roughly 40% of a desired governance state and describes informal norms rather than enforcement. He is explicitly resistant to blanket restrictions because of pipeline and CAC accountability, and he sees the risk as abstract until he encounters concrete peer-company examples or internal compliance pressure. His most distinctive insight is that IT-to-marketing governance conversations largely don't happen, resulting in policies that get worked around — which he acknowledges is itself the Shadow AI problem.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep coming back to is that my team is using AI tools constantly — like, it's just baked into how we work at this point — but I have no real visibility into what's actually leaving our environment. Like, someone on my team is probably pasting prospect data or campaign attribution models into ChatGPT right now, and I genuinely don't know what guardrails exist around that. Our IT and security teams are small — we're Series A — so there's not a robust policy framework in place. It's more like informal norms than actual enforcement. The other piece is that I'm CAC-conscious by nature, and some of these AI tools are genuinely driving efficiency for us, so I don't want to be in a position where security concerns force a blanket restriction that kills productivity. That procurement community framing of "air-gapped vs. third-party" is real — I think about it — but we're nowhere near having the infrastructure or budget to run our own models. So we're kind of just... hoping the enterprise agreements we have with vendors are enough, and I'm not sure they are.

2

What's the most important thing you need to understand or solve here?

Honestly, the thing I keep running into is that I have zero visibility into what my team is actually doing with AI tools day-to-day. Like, I know people are using ChatGPT, probably Claude, maybe some other stuff — but I don't know what data is going into those prompts. And from a marketing standpoint, that's not just a security concern, it's a competitive concern. We're putting campaign strategy, prospect data, positioning work into these tools, and I genuinely don't know where that ends up. The policy side is almost secondary to the visibility problem. You can write a policy, but if you can't see what's happening, the policy is kind of theater. So the core question for me is: how do you get actual observability into AI usage without just locking everything down and killing productivity? Because my team needs these tools — I'm not going to pretend otherwise.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, is knowing exactly what's moving through our AI tools and having confidence that nothing sensitive is leaving the building without us knowing about it. Like, we use a handful of AI tools across the marketing stack — some for content, some for data analysis — and honestly I don't have full visibility into what my team is pasting into those tools on any given day. That's the gap. The ideal state is probably something like: approved tool list, clear guidance on what data categories are off-limits for public AI endpoints, and some kind of lightweight monitoring so I'm not just taking people's word for it. Not air-gapped, that's too extreme for a team our size, but at least a controlled set of tools where we know the data handling terms and have actually read them. Where are we today? Maybe 40% of the way there. We have an informal "use approved tools" policy but no real enforcement mechanism, and security is focused on bigger stuff than marketing's AI usage. It's not a crisis, but it's a blind spot I'm aware of.

4

What would change your perspective on this entirely?

Honestly, the thing that would probably shift my view the most is if I started seeing real, concrete examples of data leakage actually causing measurable business damage at companies my size — like a Series A or B SaaS company, not just a Fortune 500 case study. Right now it feels somewhat abstract to me, like a concern I acknowledge but haven't personally felt the pain of. The other thing would be if our legal or compliance team started getting more vocal about it. Right now the pressure I feel day-to-day is pipeline and CAC — if someone upstream from me started flagging Shadow AI as a genuine liability risk with teeth, that would probably change how much budget and attention I'd push toward it. It's kind of like what I hear from IT and security folks — they're worried about risk management and compliance while leadership is chasing the shiny AI use cases, and those two conversations aren't really meeting in the middle yet.

5

What question are you not being asked that you wish someone would ask?

Honestly, I don't have some big contrarian insight that's being missed. But one thing I don't get asked enough in conversations like this is — what's the actual impact on pipeline when you lock things down too hard? Like, everyone's focused on the risk side of Shadow AI, and that's legitimate. But on my end, if IT puts up walls that make it so my team can't use the tools that help us move faster — content generation, data analysis, whatever — that has a real cost too. I'm trying to hit pipeline targets, and slow is slow, whether it's a security policy or a bad process. So I'd love it if someone asked how security and marketing actually collaborate on AI governance, because right now that conversation mostly doesn't happen. It's usually IT hands down a policy and we figure out how to work around it, which is probably exactly the Shadow AI problem you're researching.

"You can write a policy, but if you can't see what's happening, the policy is kind of theater. So the core question for me is: how do you get actual observability into AI usage without just locking everything down and killing productivity?"
Language Patterns for Copy
"no real visibility into what's actually leaving our environment""informal norms than actual enforcement""policy is kind of theater""observability into AI usage without locking everything down""maybe 40% of the way there""feels somewhat abstract to me""IT hands down a policy and we figure out how to work around it""slow is slow, whether it's a security policy or a bad process""hoping the enterprise agreements we have with vendors are enough"
M
Marcus T.
VP of Marketing · Series B SaaS · San Francisco, CA
mixed88% conf
34 yrsB2B Tech$180kdata-driven · ROI-obsessed · skeptical of fluff · ex-agency

Marcus is a pragmatic, self-aware marketing VP who recognizes a real and active data leakage risk from unsanctioned AI tool use on his team, but frames it primarily as a visibility and governance problem rather than a crisis. He is not alarmed or reactive — he understands why employees use these tools and is sympathetic to that behavior. His central frustration is the lack of measurable insight into actual exposure. He is moderately skeptical of vendor threat narratives and heavy-handed enforcement approaches, and sees the core problem as an organizational ownership gap rather than a technology or policy gap per se. He estimates his organization is roughly a third of the way to a mature posture. His tone throughout is measured, analytical, and candid rather than urgent or emotionally charged.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I'm most actively wrestling with is the gap between what our security policy says on paper and what's actually happening day-to-day on my team. We have a policy that says don't put confidential data into external AI tools, but I know people are doing it anyway — they're pasting campaign briefs, competitive intel, pricing-adjacent stuff into ChatGPT or Claude because it makes their work faster. And I get it, I'm not unsympathetic, but from a data leakage standpoint that's a real exposure. The other piece is I don't have great visibility into it. I'm not in IT or security, so I'm kind of relying on self-reporting and vibes. I've heard from our IT manager that they're looking at some tooling to detect this, but I don't know how mature that is yet. It feels like the enforcement infrastructure is lagging pretty far behind how fast people have actually adopted these tools.

2

What's the most important thing you need to understand or solve here?

Honestly, for me it comes down to visibility. I don't have a strong view on the security architecture side — that's more of an IT and InfoSec problem — but from where I sit in marketing, the thing that keeps coming up is: we have no clear picture of what tools people on my team are actually using day-to-day. Like, someone's pasting campaign briefs or customer segmentation data into ChatGPT or Claude, and I genuinely don't know if that's hitting OpenAI's servers in a way that creates risk for us. The procurement thread mentality of "they say they're secure but do we actually know that?" resonates. We're a Series B company, so we're not huge, but we're handling enough customer data that it matters. So the core problem isn't really policy — we have a policy, it's just not enforced in any practical way. It's that I can't measure the exposure, and if I can't measure it, I can't manage it.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having visibility into what tools people are actually using, a policy that's practical enough that people follow it rather than route around it, and some kind of data classification layer so that sensitive stuff — customer data, pricing, pipeline information — doesn't end up in a third-party model's training pipeline. How far are we from that? Honestly, probably a third of the way there. We have a policy on paper, we have some approved tools, but the visibility piece is weak. I don't have a clean answer to "what GenAI tools is the marketing team actually using right now" — and I'm the VP of Marketing, so that should tell you something. The enforcement layer basically doesn't exist beyond trust and awareness.

4

What would change your perspective on this entirely?

Honestly, the thing that would probably shift my thinking the most is if I saw a well-documented, verified case of a major data breach that was directly attributable to shadow AI usage — not just a near-miss or a theoretical risk scenario, but an actual material incident with a clear causal chain. Right now a lot of the conversation feels like it's still in the "here's what could happen" zone, and I'm a little skeptical of vendor-driven threat narratives where the solution conveniently matches the problem they're selling. The other thing that would move me is cleaner ROI evidence — if security tooling vendors could show me that enforcement-focused approaches actually reduce risk exposure in a measurable way without just creating friction that drives employees to find workarounds anyway. From what I've seen, heavy-handed policy enforcement tends to push behavior underground rather than eliminate it, which seems counterproductive. If someone could demonstrate that's not true with real data, I'd reconsider.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I don't hear enough is: "Who actually owns the Shadow AI problem inside your org?" Because right now it falls into this weird no-man's land between IT, security, legal, and marketing — and everyone assumes someone else is handling it. In my world, marketing teams are often the heaviest GenAI users, but security is designing the policies without really understanding how we work or what we need. So you end up with either overly restrictive rules that people just route around, or basically nothing enforced at all. I don't have a strong view on the technical enforcement side, but from a business process standpoint, the governance question seems underdeveloped compared to all the conversation about the tools themselves.

"I don't have a clean answer to 'what GenAI tools is the marketing team actually using right now' — and I'm the VP of Marketing, so that should tell you something."
Language Patterns for Copy
"gap between what our security policy says on paper and what's actually happening day-to-day""enforcement infrastructure is lagging pretty far behind how fast people have actually adopted these tools""if I can't measure it, I can't manage it""probably a third of the way there""heavy-handed policy enforcement tends to push behavior underground rather than eliminate it""everyone assumes someone else is handling it""the governance question seems underdeveloped compared to all the conversation about the tools themselves"
M
Marcus T.
VP of Marketing · Series B SaaS · San Francisco, CA
mixed92% conf
34 yrsB2B Tech$180kdata-driven · ROI-obsessed · skeptical of fluff · ex-agency

Marcus is a pragmatic, operationally-grounded marketing leader who sees AI governance as a visibility and enforcement problem, not a policy-writing problem. He acknowledges real productivity gains from AI tools and explicitly does not want to block them. His core concern is that he has no audit trail or monitoring capability, meaning he cannot confirm whether sensitive data — campaign briefs, pricing models, competitive intel — has left the organization through personal AI accounts. He views existing policies as insufficient without detection infrastructure to back them up, and he pushes back on security-centric framing that ignores the business cost of over-restriction. His tone is measured and analytical throughout — concerned but not alarmed, and pragmatic rather than reactive.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep coming back to is that my team is using AI tools constantly — ChatGPT, Claude, various writing assistants — and I have no real visibility into what's going into those prompts. We're talking about campaign briefs, competitive positioning, pricing messaging. Stuff that's actually sensitive from a business standpoint. Security hasn't really handed us a clear policy yet, and the guidance we do have is pretty vague — like "use good judgment." That's not really workable when you've got a team of twelve people making individual calls every day on what's okay to paste into a third-party model. The part I'm wrestling with most is that I don't want to slow the team down — the productivity gains are real — but I also can't tell you with confidence right now that proprietary information isn't sitting in some external model's training pipeline somewhere. That's the tension I haven't resolved.

2

What's the most important thing you need to understand or solve here?

Honestly, the biggest thing for me right now is just visibility. I don't have a clear picture of what tools my team is actually using day-to-day. People are pasting campaign briefs, competitive intel, customer data into ChatGPT or Claude on their personal accounts, and I have no real way to audit that. It's not malicious — they're trying to move faster — but from a data leakage standpoint, I genuinely don't know what's leaving the building. The policy side is almost secondary until you solve the visibility problem. You can write an acceptable use policy, but if you can't see what's happening, it's just a document that makes legal feel better.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having visibility into what tools my team is actually using, some reasonable guardrails around what data is going into those tools, and a policy that people actually follow rather than work around. That's the bar — not zero AI usage, just governed AI usage. How far are we from that? Honestly, medium distance. We have a policy on paper, but enforcement is pretty loose. I know people are using ChatGPT, Claude, whatever — for drafting, research, campaign analysis — and I can't tell you with confidence that nobody's pasted a customer list or a pricing model into a prompt somewhere. That's the gap that bothers me most. It's less about blocking tools and more about not having any real audit trail or awareness of what's leaving the building.

4

What would change your perspective on this entirely?

Honestly, the thing that would shift my view the most is if I started seeing real enforcement stories — not just policy documents, but companies that actually caught something, stopped it, and had a clear chain of how they did it. Right now most of what I hear is "we have a policy" and then a shrug when you ask how it's monitored. If vendors started showing me actual detection and response workflows with some track record behind them, I'd take the tooling more seriously. And if our security team came to me with something that was genuinely measurable — like here's what we caught, here's what it would have cost us — that would change the internal conversation too.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I'd want someone to ask is: "What's the actual cost of over-restricting AI access versus under-restricting it?" Because every conversation I'm in with security teams is about locking things down — and I get why — but nobody's quantifying the productivity drag on the other side of that equation. My team is moving fast on campaign work, competitive research, content production. If security blanket-blocks tools without an approved alternative that actually works, people just find workarounds. That's how you get more shadow usage, not less. So the framing of "how do we stop Shadow AI" feels incomplete to me without also asking "what happens to the business if we succeed?"

"The policy side is almost secondary until you solve the visibility problem. You can write an acceptable use policy, but if you can't see what's happening, it's just a document that makes legal feel better."
Language Patterns for Copy
"no real visibility into what's going into those prompts""use good judgment — that's not really workable""the productivity gains are real""I genuinely don't know what's leaving the building""just a document that makes legal feel better""governed AI usage""no real audit trail""actual detection and response workflows with some track record""quantifying the productivity drag on the other side""how you get more shadow usage, not less"
Methodology

How to interpret this report

What this is

Synthetic pre-research uses AI personas grounded in real buyer archetypes and (where available) Gather's interview corpus. It produces directional signal — hypotheses worth testing — not statistically valid measurements.

Statistical projection

Quantitative figures are projected from interview analyses using Bayesian scaling with a conservative ±35% margin of error. Treat as estimates, not census data.

Confidence scores

Reflect internal response consistency, not statistical power. A 90% confidence score means high AI coherence across interviews — not that 90% of real buyers would agree.

Recommended next step

Use this to build your screener, align on hypotheses, and brief stakeholders. Then run real AI-moderated interviews with Gather to validate findings against actual respondents.

Primary Research

Take these findings
from synthetic to real.

Your synthetic study identified the key signals. Now validate them with 150+ real respondents across 8 audience types — recruited, interviewed, and analyzed by Gather in 48–72 hours.

Validated interview guide built from your synthetic data
Real respondents matching your exact persona specs
AI-moderated interviews with qual depth + quant confidence
Board-ready report in 48–72 hours
Book a call with Gather →
Your Study
"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"
150
Respondents
8
Persona Types
48h
Turnaround
Gather Synthetic · synthetic.gatherhq.com · August 12, 2026
Run your own study →