⚠ Synthetic pre-research — AI-generated directional signal. Not a substitute for real primary research. Validate findings with real respondents at Gather →
Projected from interview analyses using Bayesian scaling. Treat as directional estimates, not census measurements.
Side-by-side comparison of sentiment, intent, buying stage, and decision role across all personas.
Complete question-by-question responses with per-persona analysis. Click any respondent to expand.
Alex is a technically sophisticated CTO operating under significant anxiety about AI data governance — not from ignorance, but from clear-eyed awareness of how far his current state is from where he needs to be. His core pain is lack of real-time visibility into what customer data is flowing to external AI endpoints, compounded by policy-enforcement infrastructure that amounts to a Confluence page no one reads. He's deeply skeptical of the Shadow AI detection vendor market, which he views as AI-washed DLP proxies at unjustifiable price points. His ideal state — an API-gateway-enforced data plane with cryptographic verifiability analogous to OAuth scopes — is sophisticated and actionable, but he estimates 18 months and unallocated budget stand between him and it. His most underexplored and emotionally loaded concern is incident response readiness: he believes his organization would be improvising in a real Shadow AI data event, and that this conversation is not happening at the board or peer level.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night right now is the delta between what our security policy says and what's actually happening on employees' laptops. I've got engineers copy-pasting customer data schemas into Claude or ChatGPT to debug queries, and they're not doing it maliciously — they genuinely don't think it's a big deal. The policy exists, enforcement is basically nonexistent, and I don't have great visibility into it without turning the place into a surveillance state, which I also don't want to do. The other piece is I'm drowning in vendor pitches for "Shadow AI detection" tools, and half of them are just DLP with an AI wrapper slapped on it — exactly the kind of AI-washing that makes me skeptical. I want to understand what's actually hitting the wire, what model endpoints are being called, what data is leaving our environment, but I haven't found a solution that doesn't require me to buy yet another agent that I have to manage, trust, and eventually rip out in 18 months.
What's the most important thing you need to understand or solve here?
The core problem I'm trying to solve is visibility — I genuinely don't know what AI tools my engineers and product people are pasting our customer data into right now. Like, someone on the product team is almost certainly running customer support transcripts through ChatGPT to summarize them, and that's a direct violation of our data processing agreements with those customers. I can either play whack-a-mole with policy enforcement, or I can build something systematic that gives me actual telemetry on data egress to third-party AI endpoints. The real question is whether I architect that myself on top of our existing CASB investment or buy yet another point solution from some "Shadow AI detection" vendor who's going to AI-wash a glorified proxy and charge me $200k a year for it.
What does 'good' look like to you — and how far are you from that today?
Good looks like a unified data plane where I know exactly what model is touching what data, with policy enforcement happening at the API gateway level before anything hits an external service — not after the fact through audit logs and finger-wagging. Basically, I want the equivalent of what we built for OAuth scopes, but for AI data flows: explicit consent, explicit boundaries, cryptographically verifiable. Where are we today? Honestly, embarrassingly far. We've got Copilot deployed for about 60% of engineering, we've got some employees definitely using Claude and ChatGPT on the side for customer data summarization — I know this because it shows up in our egress monitoring — and our "policy" right now is essentially a strongly-worded Confluence page that nobody reads. The gap between where I want to be and where we are is probably 18 months of real work, assuming I could get budget prioritized over the seventeen other things on the roadmap.
What would change your perspective on this entirely?
If I saw a vendor actually solve the data residency problem in a way that didn't require me to trust their word for it — like, cryptographic proof that my prompts never left a specific compute boundary — that would genuinely shift how I think about third-party AI tooling. Right now it's all "trust us, we're SOC 2 compliant" which is just a checkbox exercise that tells me nothing about runtime data handling. The other thing that would move me is if Microsoft or someone with actual enterprise credibility built shadow AI detection directly into the network layer rather than selling it as yet another bolt-on agent I have to manage. I'm already running 40+ integrations and the last thing I need is another vendor in my security stack promising to solve the problem that their own ecosystem created.
What question are you not being asked that you wish someone would ask?
The question nobody's asking me is: "What's your actual blast radius if your AI governance strategy fails?" Everyone wants to talk about policy documents and acceptable use frameworks, but nobody's pressure-testing the real catastrophic scenario — which for us is a single engineer with good intentions pasting our customer data schema plus behavioral analytics into Claude or Gemini to debug a pipeline issue, and that data becoming training signal or getting exposed in a breach at Anthropic's end. We've spent so much energy on the "what are employees allowed to do" question that we've completely under-invested in the "what does incident response look like when Shadow AI causes a customer data event" question. That's the conversation I want to have with my board, and honestly with peers, because right now I feel like we'd be improvising.
"The question nobody's asking me is: 'What's your actual blast radius if your AI governance strategy fails?' — a single engineer with good intentions pasting our customer data schema plus behavioral analytics into Claude or Gemini to debug a pipeline issue, and that data becoming training signal or getting exposed in a breach at Anthropic's end."
Alex is a technically sophisticated CTO caught between three simultaneous pressures: an uncontrolled Shadow AI sprawl he can't see, vendor solutions he doesn't trust, and a cultural constraint that makes hard enforcement self-defeating. His self-assessed posture is 40% of where he needs to be — he has controls on sanctioned tooling but zero confidence in catching unsanctioned usage. The most revealing signal is his Q5 response: he's shifted his deepest anxiety from governance and discovery to contractual liability and indemnification when AI vendors are breached — a concern the entire market is ignoring. His buying posture is active but blocked by vendor fatigue; the unlock is a self-hosted, open-source-core solution with enterprise support that integrates into his existing stack without a prolonged professional services engagement.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night is that we've got probably 40-50 engineers who are all individually paying for their own ChatGPT Plus or Claude subscriptions and just... piping work code and customer data through these things without any visibility on our end. We have an acceptable use policy that nobody reads, and enforcement is essentially theater at this point. The harder problem is I can't just ban it — if I do that, I lose the productivity gains and I lose engineers to competitors who let them use these tools. So I'm stuck trying to figure out how to build a sanctioned path that's actually good enough that people *want* to use it instead of going around me, which means I'm basically in the business of standing up internal AI infrastructure that I didn't budget for and didn't plan to build this year. And then there's the vendor side — every single security tool in my stack is now claiming they "solve Shadow AI" and it's mostly marketing wrapper around the same DLP capabilities I already own. I've got Wiz, I've got Netskope, I've got CrowdStrike all telling me they handle this, and none of them actually give me the full picture of what's leaving my environment.
What's the most important thing you need to understand or solve here?
The core problem I'm trying to solve is visibility — I genuinely don't know what my engineers and product folks are sending to third-party AI services on any given day. Like, someone on my team could be pasting customer PII or proprietary pricing logic into Claude or ChatGPT right now and I'd have zero signal on it. That's the thing that keeps me up at night more than any sophisticated attack vector. The second layer is that even when I try to address it with policy, I'm fighting against the reality that these tools make people dramatically more productive, so a blanket "just don't use them" approach creates its own shadow problem where people just get sneakier about it. I need a solution that gives me data flow observability without turning into the AI gestapo and destroying engineering culture.
What does 'good' look like to you — and how far are you from that today?
Good looks like: I know exactly what AI tools are running in my environment, I know what data they're touching, and I have policy enforcement that doesn't require me to trust a vendor's word for it. Basically full observability into the AI layer the same way I have observability into my network layer — DLP-style controls but AI-aware, with actual audit trails I can query. Where am I today? Honestly maybe 40% of the way there. I've got decent controls on our sanctioned tools — we're running Azure OpenAI with private endpoints so data stays in our tenant, I've got Defender for Cloud Apps blocking a handful of the obvious consumer AI endpoints — but I have zero confidence I'm catching the long tail. Someone on the product team is absolutely piping customer feedback into Claude or ChatGPT right now and I have no reliable signal on it. That's what keeps me up at night.
What would change your perspective on this entirely?
Honestly? If someone showed me a Shadow AI solution that didn't require me to become a customer of yet another vendor to solve a problem created by other vendors, I'd pay attention. Like, if I could deploy something self-hosted, API-first, that plugged into our existing Okta and Zscaler stack without a six-month professional services engagement — that would genuinely move the needle for me. Right now every "Shadow AI governance" pitch I get is just someone trying to sell me another SaaS layer on top of my SaaS layers, and I'm so deep in vendor fatigue that my default answer is no before they finish the deck. Show me an open-source core with enterprise support, let me actually own the data pipeline, and we can have a real conversation.
What question are you not being asked that you wish someone would ask?
The question nobody's asking me is: "Who owns the liability when your AI vendor gets breached and your customer data was in those prompts?" Everyone's focused on the policy and governance layer — writing acceptable use policies, deploying DLP tools, doing the shadow IT discovery — but nobody's having the hard conversation about contractual indemnification when OpenAI or Anthropic or whoever has an incident and your customers' data was sitting in their inference pipeline. We're all just clicking through ToS agreements like it's 2012 installing iTunes. That's the thing that keeps me up at night, not whether my developers are using Copilot without permission.
"The question nobody's asking me is: 'Who owns the liability when your AI vendor gets breached and your customer data was in those prompts?' We're all just clicking through ToS agreements like it's 2012 installing iTunes."
Jordan is a fintech Senior PM caught in a genuine organizational tension: leadership demanding AI-driven velocity while compliance and legal pump the brakes, with Jordan absorbing the operational friction in between. His core concern is not abstract — he has direct, firsthand knowledge of engineers pasting payment processing logic and PII into unsanctioned models on a near-nightly basis, and describes current policy enforcement as 'vibes-based.' He self-rates his org's AI governance posture at 3/10. Critically, Jordan surfaces a blind spot the industry isn't discussing: sophisticated power users (PMs, engineers) who understand AI well enough to deliberately rephrase proprietary context to evade DLP controls — and he implicates himself as one of them. He is not a true believer in the urgency narrative, expressing measured skepticism that some risk framing is vendor-manufactured, and would update his posture significantly if shown real incident reports (not whitepapers) of regulatory action tied to GenAI data leakage in fintech. His ideal solution is frictionless, developer-native governance — invisible guardrails, not compliance theater.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night is that we're a fintech, so we're sitting on incredibly sensitive financial data — transaction records, KYC docs, payment flows — and I can see my engineers and even some of our PMs just... casually pasting stuff into ChatGPT or Claude to debug or draft requirements. Like, that's a real data leakage vector right there, and our compliance team is only just now starting to freak out about it. The frustrating part is leadership is simultaneously pushing us to "move faster with AI" while our security and legal folks are pumping the brakes, and I'm stuck in the middle trying to actually ship product. I feel like the classic tension where the CEO is hyped on AI being the answer to everything, but nobody's asking the unsexy questions about what happens when a PII-laden prompt ends up in OpenAI's training pipeline or gets subpoenaed. What I'm genuinely wrestling with is: how do we give our team the productivity wins without essentially shadow-IT-ing our way into an SOC 2 violation or an OCC audit finding? We haven't landed on a clean answer yet — right now it's basically vibes-based policy enforcement, which is not great for a regulated financial services company.
What's the most important thing you need to understand or solve here?
The thing that keeps me up at night is the gap between what our security policy says on paper and what's actually happening in Slack at 11pm when an engineer is trying to ship a feature and just pastes our payment processing logic into Claude to debug it. Like, that's not a hypothetical — that's Tuesday. We're a fintech, so we're sitting on PII, transaction data, card info — the regulatory exposure is real, not theoretical. The core problem I need to solve is: how do I give my team the speed they need to actually compete without creating a data leakage surface that gets us killed in a SOC 2 audit or, worse, an actual breach. It's not a policy problem, it's a workflow problem — people are using these tools because they're genuinely 10x more productive, and I don't want to be the PM who kills velocity by playing security theater. I need a solution that actually fits how engineers and PMs work, not one that looks good in a compliance deck.
What does 'good' look like to you — and how far are you from that today?
Good, to me, looks like a world where my engineers can actually use the AI tools that make them 10x more productive — Cursor, Claude, whatever — without me losing sleep about customer PII or transaction data leaking into some third-party model's training set. Like, the ideal state is frictionless productivity with guardrails that are basically invisible to the developer but airtight from a compliance standpoint. Where are we today? Honestly, we're probably at like a 3 out of 10. We've got a policy doc that nobody reads, and I know for a fact two of my engineers are piping stuff into ChatGPT that probably shouldn't be leaving our environment — not maliciously, just because it's the path of least resistance and our approved tooling is clunky by comparison. The gap between "what leadership thinks our AI posture is" and "what's actually happening on the ground" is real and it keeps me up at night more than almost anything else right now.
What would change your perspective on this entirely?
Honestly? If I saw real evidence that the risk was being overstated relative to the actual business harm occurring. Like, show me the breach postmortems where Shadow AI was the root cause versus "employee emailed a spreadsheet to their personal Gmail" — because that latter thing has been happening for decades and we've been able to quantify it. The thing that would flip me the other way is if we started seeing regulatory action specifically tied to GenAI data leakage in fintech — like if FinCEN or the CFPB dropped guidance that created actual liability for our category, that changes the calculus immediately and I'd be pushing for way more aggressive controls than what we have today. Right now it feels like a lot of the urgency is vendor-manufactured, similar to how every security tool company in 2022 was screaming about ransomware to sell their product. But if someone showed me a clean case study — not a whitepaper, an actual incident report — where a Series B fintech lost a deal or faced regulatory scrutiny because an engineer pasted customer PII into ChatGPT, I'd recalibrate fast and start treating this with the same urgency I give our SOC 2 compliance work.
What question are you not being asked that you wish someone would ask?
Honestly? Nobody's asking about the **developer and PM layer specifically** — like, we're the ones who are deepest in the shadow AI problem because we're also the most capable of hiding it. I'm generating PRDs, doing competitive analysis, prototyping flows — all with AI tools that may or may not be sanctioned — and security is focused on, like, the sales guy who pasted customer PII into ChatGPT. But I have *way* more sensitive context: roadmap strategy, unreleased feature specs, pricing architecture for our lending products. The question nobody's asking is "how do you actually govern the power users who understand AI well enough to route around your controls?" Because a DLP tool catching a CSV upload isn't going to catch me carefully rephrasing proprietary context into a prompt that extracts exactly what I need from an unsanctioned model.
"Nobody's asking about the developer and PM layer specifically — we're the ones who are deepest in the shadow AI problem because we're also the most capable of hiding it. A DLP tool catching a CSV upload isn't going to catch me carefully rephrasing proprietary context into a prompt that extracts exactly what I need from an unsanctioned model."
Jordan is a fintech PM acutely aware that Shadow AI isn't a future risk — it's a present exposure he can't fully quantify. He's caught between CEO pressure to accelerate AI adoption and legal/compliance resistance, while his engineers bypass approved tooling because it's slower. He self-rates his org at 3/10 on governance maturity. His core frustration is that every vendor solution is compliance-first (monitoring, blocking) rather than behavior-first — addressing why people reach for unauthorized tools. He wants real-time observability without surveillance, single-tenant infrastructure at startup-friendly pricing, and most critically, a risk framework that doesn't sacrifice product velocity. The insight he feels is most overlooked: locking down AI tools isn't just a security decision — it's a competitive velocity decision that product teams are being excluded from.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night is that we're a fintech — so we're sitting on PII, transaction data, account info — and I've got engineers and analysts just... casually pasting stuff into ChatGPT or Claude to debug code or summarize reports. Like, they're not malicious, they're just trying to move fast, which I totally get, I *want* them to move fast. But the gap between "we have an AI policy" and "people are actually following it" is enormous right now. The other piece that's genuinely frustrating is that leadership keeps pushing us to be more "AI-forward" — classic CEO energy, everything needs AI — but then compliance and legal are waving red flags about data residency and what OpenAI actually does with enterprise prompts. And I'm stuck in the middle trying to ship product features while also figuring out whether our approved tooling is even good enough that people won't just route around it anyway. If the sanctioned tools are worse than what someone can spin up in thirty seconds on their personal laptop, you've already lost the policy battle before it started.
What's the most important thing you need to understand or solve here?
The core thing keeping me up at night is that we're a fintech — so we're sitting on PII, transaction data, account info — and my engineers are absolutely using ChatGPT, Claude, whatever, to debug code and write specs. I *know* it's happening. The question isn't "is Shadow AI a problem" it's "how bad is the exposure we already have and don't know about." What I really need to solve is visibility without killing velocity — because if I go full lockdown mode, my best engineers will just find workarounds anyway, and then I'm worse off than before. The middle ground everyone talks about — like company-controlled inference servers, private tenancy — sounds right directionally, but I haven't seen anyone actually execute it without it becoming a six-month infra project that slows everything down.
What does 'good' look like to you — and how far are you from that today?
Good looks like having a clear, auditable policy layer where I can actually see what tools my team is touching, what data's flowing where, and have some confidence that our customer PII and transaction data isn't ending up in some third-party model's training set. Like, that procurement thread I've seen floating around basically nails it — the ideal is company-controlled infrastructure where we're the only tenant, but practically speaking we're nowhere near that. Honestly we're probably like a 3 out of 10 right now. We've got an acceptable use policy that went out in a Confluence doc six months ago and I'm pretty sure half my engineers haven't read it, and the other half are using Claude or ChatGPT for code review anyway because it's just faster. The gap between the policy on paper and what's actually happening in Slack and VS Code is... significant. What I actually want is something closer to real-time observability — not surveillance, I don't want to be that PM — but at least a dashboard that tells me "hey, someone on your team just pasted what looks like a database schema into a public LLM endpoint." That's the thing that keeps me up at night in fintech specifically, because regulators will not care that your engineer was just trying to move fast.
What would change your perspective on this entirely?
If I saw a Shadow AI solution that actually started from the user behavior side instead of the compliance side — like, genuinely built around why people are reaching for unauthorized tools in the first place — that would shift my thinking pretty hard. Right now every vendor I've seen is basically selling a monitoring and blocking layer, which is the enterprise equivalent of putting a lock on the candy drawer instead of asking why people are stress-eating. Honestly, if a CISO could show me real usage data demonstrating that their policy enforcement actually *reduced* risky behavior rather than just pushing it further underground — like onto personal devices and personal accounts where you have zero visibility — I'd take the governance-first argument way more seriously. The procurement folks I've talked to who went the "restrict everything" route just created a shadow-shadow AI problem where people are literally using their phones. And the other thing that would flip me: if vendors started offering genuinely air-gapped or single-tenant deployments at a price point that doesn't require a Fortune 500 budget. We're a fintech, we have real data sensitivity concerns, but right now the "secure enterprise AI" options are priced like they're negotiating with Goldman Sachs, not a 200-person startup in Austin.
What question are you not being asked that you wish someone would ask?
Honestly? Nobody's asking about the **product velocity tradeoff**. Everyone wants to talk about policy and governance and "how do you prevent shadow AI" — but nobody's asking what it *costs* you in shipping speed when you lock things down too hard. Like, my engineers are moving so much faster with these tools, and if I come in with heavy-handed restrictions, I'm not just solving a security problem, I'm creating a competitive disadvantage problem. The real question I wish someone would ask is: "How do you build a risk framework that doesn't accidentally kill your ability to iterate?" Because right now it feels like security teams and product teams are optimizing for completely different success metrics and nobody's sitting in the middle trying to reconcile that tension — and as a PM in fintech, *I'm* the one stuck living in that gap every single day.
"If I come in with heavy-handed restrictions, I'm not just solving a security problem, I'm creating a competitive disadvantage problem. Every vendor I've seen is basically selling a monitoring and blocking layer, which is the enterprise equivalent of putting a lock on the candy drawer instead of asking why people are stress-eating."
Chris is a demand gen leader caught in a self-created bind: he's the internal AI adoption champion who now realizes he has zero visibility into what sensitive data his team is feeding into unmanaged AI tools daily. His core tension isn't security per se — it's that both paths are dangerous. Lock AI down and competitors out-prospect him with tools he can't measure or defend against. Leave it open and he may be the reason a deal collapses or a data audit goes sideways. He's actively dismissive of enterprise-framed security narratives and would only engage with AI governance vendors who can translate risk into pipeline-impact metrics at startup scale. His unasked question — what does NOT using AI cost in pipeline? — reveals a sophisticated frame that most security-led vendors are completely missing.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night is that half my team is using ChatGPT, Claude, whatever — to write copy, build outreach sequences, do competitive research — and I have zero visibility into what's actually getting pasted in there. Like, we're a Series A company, we're small, but we still have prospect data, pricing strategy docs, stuff that's genuinely sensitive from a competitive standpoint. And nobody's asked IT — frankly we barely *have* an IT department — whether any of this is okay. The irony is I'm the one pushing my team hardest to use AI to move faster on pipeline, but I'm also starting to realize I have no idea if someone pasted our CAC targets or a prospect's contract details into a free tier ChatGPT instance. That's the thing I'm wrestling with — how do you stay aggressive on adoption without creating a massive liability? Because I'm not getting slower to hit pipeline, but I also don't want to be the reason we blow up a deal or a data audit.
What's the most important thing you need to understand or solve here?
Honestly, the thing keeping me up at night isn't even the security angle — it's the attribution and data leakage combo hitting at the same time. Like, my team is using ChatGPT, Claude, whatever, to write copy, pull competitive intel, analyze campaign data, and I genuinely don't know what's leaving the building. We've got customer firmographic data, pipeline numbers, CAC breakdowns sitting in these prompts, and I have zero visibility into whether that's being used to train models or sitting somewhere it shouldn't be. The bigger problem is nobody's actually told us *not* to do it in any meaningful way — there's no policy, no tooling, no guardrails. So from a marketing ops standpoint, I'm flying blind on two fronts: what's our actual data exposure risk, and are the outputs I'm getting from these tools even grounded in anything reliable or are they just hallucinating market insights that I'm then baking into our demand gen strategy? That second part is genuinely scary when you're making budget calls based on AI-summarized competitor research.
What does 'good' look like to you — and how far are you from that today?
Honestly, "good" for me looks like a world where I can see exactly what AI tools my team is using, what data they're feeding into them, and whether any of that is touching prospect or customer info that could blow up a deal or a compliance conversation. Like, I want a dashboard that shows me "Chris, your SDR just pasted a contact list into some random AI tool" — that's the dream. Where are we today? Miles away. Right now it's basically honor system — I've told my team "don't put anything sensitive into ChatGPT or whatever free tier tools you're grabbing" but I have zero visibility into whether that's actually happening. We're a Series A company, we don't have a dedicated security team breathing down our necks yet, so it falls into this weird gray zone where nobody owns it and everyone just kind of hopes for the best.
What would change your perspective on this entirely?
Honestly? If I saw hard data showing that Shadow AI actually caused a meaningful pipeline or revenue impact at a company my size — like a Series A B2B SaaS — I'd pay a lot more attention. Right now it feels like an enterprise problem that's being sold down-market, and every vendor pitching me on this stuff leads with Fortune 500 horror stories that have zero relevance to my 80-person company. Show me a real CAC-equivalent metric for a data leak incident at a startup and I'm suddenly very interested in having that conversation with our CEO.
What question are you not being asked that you wish someone would ask?
Honestly? Nobody ever asks me "what does Shadow AI actually cost you in pipeline opportunities?" Like, everyone's focused on the risk and compliance angle — data leakage, policy violations, whatever — but nobody's flipping it around and asking what it costs me when my team *can't* use these tools because IT locked everything down. I've got SDRs who are secretly using personal ChatGPT accounts to write sequences because our approved stack is garbage, and I genuinely don't know if that prospect data is sitting on OpenAI's servers right now. That's a real problem. But the other real problem is that if I handicap my team with a "no AI" policy while my competitors are running circles around us with AI-assisted prospecting, I'm losing pipeline I'll never even see in my attribution reports — and nobody's calculating *that* CAC impact.
"I've got SDRs who are secretly using personal ChatGPT accounts to write sequences because our approved stack is garbage, and I genuinely don't know if that prospect data is sitting on OpenAI's servers right now — but the other real problem is that if I handicap my team with a 'no AI' policy while my competitors are running circles around us with AI-assisted prospecting, I'm losing pipeline I'll never even see in my attribution reports."
Chris is a Head of Demand Gen at a Series A company operating in a self-described 'vibes and trust' AI governance environment. His team is actively using unapproved AI tools — Claude, ChatGPT, Perplexity — to handle sensitive GTM data including prospect information, ICP criteria, pipeline reports, and competitive intel, with zero visibility or policy guardrails. He's acutely aware this is a liability but is paralyzed by a dual pressure: a CEO demanding AI-driven velocity and a legal function that would 'lose her mind' if she saw the full picture. Critically, Chris does not respond to compliance or security framing — he demands a revenue-impact narrative. He wants to see real case studies tying Shadow AI to lost pipeline or frozen budgets, not theoretical breach scenarios. His most distinctive and actionable insight is that he self-identifies as the business owner who would bear the budget consequences of a data incident, yet nobody is speaking his language. He is a persuadable buyer who needs risk reframed in dollars-lost terms to move from passive forwarding of IT memos to active behavioral change within his team.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the Shadow AI thing keeps me up at night but probably not for the reasons IT would expect. My team is using Claude, ChatGPT, Perplexity — whatever gets the job done — and half of it isn't going through any approved procurement channel. Like, we're pasting prospect data, ICP research, sometimes even pipeline reports into these tools to build outreach sequences or analyze campaign performance, and I genuinely don't know what's happening to that data on the backend. The thing I wrestle with is that I'm basically caught between two pressures: my CEO wants AI baked into everything yesterday because we need to move faster with a lean team, but our head of legal would lose her mind if she knew the full picture of what data is actually leaving our systems. We're a Series A company, we don't have a formal AI policy yet — it's just vibes and trust — and that's terrifying when you think about competitive intel or prospect information hitting OpenAI's servers. What really frustrates me is there's no clean middle ground anyone's handed me. Either it's "lock everything down" which kills productivity and honestly kills our competitive edge against better-resourced teams, or it's the wild west we're living in now. I just want someone to show me what "responsible but not neutered" actually looks like in practice.
What's the most important thing you need to understand or solve here?
Honestly, the thing keeping me up at night isn't even the security angle — it's that my team is using every AI tool under the sun to hit pipeline numbers, and I have zero visibility into what data is leaving our systems. Like, someone on my team is probably pasting prospect data, email sequences, our ICP criteria, maybe even some competitive intel into ChatGPT or Claude right now, and I genuinely don't know if that's going to bite us later. The real tension is that I can't tell my team to stop — we'd lose a massive productivity edge and I'd miss my pipeline targets — but I also can't keep operating blind when we're a Series A company where our GTM data *is* our competitive moat. It's not like we have an IT security team of 50 people watching this stuff; it's basically me making judgment calls about tools I'm approving on a credit card. So what I actually need to understand is: where's the real risk versus the paranoia, and is there a middle ground that doesn't require me to lock everything down and kill velocity?
What does 'good' look like to you — and how far are you from that today?
Honestly, "good" for me right now looks like my team being able to use AI tools freely enough to actually move the needle on pipeline — like, I want them in ChatGPT, Claude, whatever — without me lying awake at night wondering if someone just pasted our entire ICP targeting model or CAC benchmarks into a public model. That's the nightmare scenario. We're pretty far from that ideal state. Right now it's this awkward middle ground where I've got reps and content folks using AI constantly, I *know* they're using it constantly, but we have zero visibility into what's going out the door. No governance, no guardrails, just vibes and hope — and that's not a policy, that's just denial.
What would change your perspective on this entirely?
Honestly? If I saw hard evidence that Shadow AI was actually costing companies pipeline or creating material legal liability that traced back to a marketing team specifically — not just theoretical data leakage scenarios. Right now it feels like a lot of the concern is coming from IT and compliance people who are doing the "unsexiest" risk management stuff, and I get it, but from where I sit, my team pasting competitor research into Claude or drafting sequences in ChatGPT hasn't blown anything up yet. Show me a real case study where a demand gen team's unauthorized AI usage led to an actual breach or a lost deal because prospect data got exposed, and I'd take this a lot more seriously and actually push back on my own team's habits.
What question are you not being asked that you wish someone would ask?
Honestly, the question nobody's asking me is: "What is Shadow AI actually *costing* you in pipeline and revenue terms?" Everyone's so focused on the security and compliance angle — which, fine, IT and legal care about that — but nobody's connecting it to the fact that when my reps are copy-pasting prospect data into random ChatGPT wrappers to write sequences, and that blows up into a data incident, *I'm* the one who loses budget and headcount because the whole demand gen program gets frozen during an audit. The real conversation should be about what the business *makes money on* and where unauthorized AI usage creates a bottleneck or a liability in that revenue motion — not just "did someone violate the acceptable use policy." Like, tie it to dollars lost, not just compliance checkboxes, and suddenly I'm actually engaged in the conversation instead of forwarding the IT memo to my team and hoping for the best.
"The real conversation should be about what the business makes money on and where unauthorized AI usage creates a bottleneck or a liability in that revenue motion — not just 'did someone violate the acceptable use policy.' Tie it to dollars lost, not just compliance checkboxes, and suddenly I'm actually engaged in the conversation instead of forwarding the IT memo to my team and hoping for the best."
Marcus is a Series B VP of Marketing caught between two accelerating pressures: his team's ungoverned, widespread use of consumer AI tools (including with sensitive customer and pipeline data) and the growing security scrutiny from enterprise prospects during sales cycles. He's not in denial — he self-scores his governance at 3/10 and openly acknowledges his acceptable use policy is performative. His core anxiety is that both inaction AND overreaction carry real business costs, and he's frustrated that current discourse only quantifies the risk side. His most distinctive and underserved need is ROI framing for AI governance — not just breach prevention, but a rigorous accounting of the productivity cost of over-restriction. He will not move on budget without real-world breach evidence from comparable companies, not vendor-commissioned risk reports.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night is that my team is just... using stuff. ChatGPT, Claude, Perplexity, whatever — and I know they're pasting in customer data, competitive intelligence, deal notes, things that would make our legal team have a full cardiac event if they knew. We're a Series B company, we're starting to close enterprise deals, and those customers are asking us pointed security questionnaire questions about AI usage policies, and I'm sitting here knowing our internal answer is basically "we hope for the best." The tension I'm personally wrestling with is that I can't afford to slow my team down — we're competing against companies 10x our size and AI is genuinely the equalizer — but I also can't have someone paste our ARR numbers or a prospect's procurement data into a free ChatGPT account and have that become a training data point somewhere. It's not hypothetical risk to me anymore, it's a real business liability that's starting to show up in our sales cycles.
What's the most important thing you need to understand or solve here?
Honestly, the thing keeping me up at night is data leakage — specifically my team using ChatGPT or Claude on their personal accounts and pasting in customer data, competitive intel, pipeline numbers, whatever. We're Series B, we're handling enterprise customer information, and one careless prompt could become a compliance nightmare or land us in a competitor's training data. The problem is I can't just ban AI because then I lose the productivity edge and my team goes underground with it anyway — so I need to figure out how to actually govern this without becoming the innovation-killing VP who makes everyone's life harder.
What does 'good' look like to you — and how far are you from that today?
Honestly, "good" to me looks like having full visibility into what AI tools my team is actually using, what data they're feeding into them, and being able to prove to our security and legal teams that we're not hemorrhaging proprietary campaign data or customer insights into some third-party model's training pipeline. Like, I want a dashboard that tells me Marcus's team ran 47 Claude sessions this week and here's what categories of data touched those prompts — that's the dream. Where are we today? We're probably a 3 out of 10. I know my team is using ChatGPT, Perplexity, maybe Gemini — I just don't know *what* they're putting into it. We have an acceptable use policy that legal drafted six months ago that I'm pretty sure exactly zero people have read, and our "enforcement" is basically the honor system.
What would change your perspective on this entirely?
Honestly? If I saw hard data showing that Shadow AI actually caused a material breach at a company similar to ours — not a hypothetical, not a vendor-commissioned fear report, but like a real SEC disclosure or post-mortem — that would shift my calculus pretty fast. Right now most of what I'm seeing is security vendors doing the same thing martech vendors do: manufacturing urgency around a problem they happen to sell the solution to. Show me the actual blast radius, the revenue impact, the customer churn that resulted from someone on my team pasting a deal memo into ChatGPT, and then we can have a real conversation about budget allocation.
What question are you not being asked that you wish someone would ask?
Honestly, the question nobody's asking me is "what's the ROI of your AI governance program?" Everyone's focused on the risk side — data leakage, policy violations, whatever — but nobody's quantifying the cost of *over-restricting* AI usage either. We locked down a bunch of tools for about six weeks last quarter while legal and security figured out our stance, and I can tell you that had a real productivity cost that nobody put a number on. If we're going to be data-driven about Shadow AI risk, we need to be equally rigorous about the opportunity cost of being overly cautious — otherwise we're just making fear-based decisions dressed up as security policy.
"Show me the actual blast radius, the revenue impact, the customer churn that resulted from someone on my team pasting a deal memo into ChatGPT, and then we can have a real conversation about budget allocation."
Marcus is a self-aware but ambivalent VP of Marketing at a Series B company who fully understands his Shadow AI exposure yet hasn't fully acted on it — partly because his team's productivity gains are real and he's quietly benefiting. His core pain is visibility and telemetry: he can write policy but can't enforce or audit it. The most revealing tension is his admission that he's 'quietly approved' tools without IT sign-off while simultaneously being alarmed that his team is doing the same at a lower level. He reframes the Shadow AI problem as a revenue and liability issue owned by marketing, not IT — and the specific GDPR exposure from SDR outreach workflows using prospect data is an underappreciated, high-stakes signal. He is buyable, but needs concrete downside proof (career/valuation consequences), not hypothetical risk frameworks.
Tell me what's top of mind for you on this topic right now — what are you wrestling with?
Honestly, the thing keeping me up at night is that my team is using AI tools faster than our IT and legal teams can even write policies about them. Like, I've got content strategists running campaign briefs through ChatGPT, SDRs using random AI writing tools, someone on the demand gen side literally built a workflow that's piping lead data into some third-party tool I'd never approved. And the scary part isn't even the security risk in isolation — it's that I don't have full visibility into what's actually leaving the building. We're a Series B company handling customer data, and if something leaks because some AE wanted to save 20 minutes on a proposal, that's a compliance and trust problem that no MQL metric is going to offset.
What's the most important thing you need to understand or solve here?
Honestly, the thing keeping me up at night is data leakage — specifically my team using personal ChatGPT accounts or Claude Pro subscriptions to process actual customer data, competitive intel, campaign briefs with pricing info. I have zero visibility into what's being pasted into those free-tier or personal accounts, and that's a massive liability especially at Series B where we're starting to deal with more enterprise prospects who are asking pointed security questions during procurement. The policy side is almost secondary to me — I can write an AI usage policy in an afternoon, but enforcement and visibility are a completely different beast. I need to actually know what's happening, not just have a doc in Confluence that nobody reads.
What does 'good' look like to you — and how far are you from that today?
Good looks like having visibility into every AI touchpoint across my org — knowing exactly what tools people are using, what data is flowing where, and having guardrails that don't require me to play AI police every quarter. Basically a dashboard that tells me "here's your risk exposure, here's your approved stack, here's what's happening outside of it" — clean, measurable, auditable. Where are we today? Honestly, we're probably at 30% of that. We've got a partially approved tool list, a policy that exists in Confluence and that approximately nobody reads, and I know for a fact people on my team are running campaign briefs and competitive intel through personal ChatGPT accounts because the approved internal tool has some friction to it. The gap between policy and actual behavior is enormous, and I don't have the telemetry to even quantify how bad it is.
What would change your perspective on this entirely?
Honestly? If I saw hard data showing that a Shadow AI incident actually tanked a company's valuation or triggered meaningful regulatory action — not just a slap-on-the-wrist fine, but something that moved markets — I'd probably reprioritize how seriously I push this up the chain. Right now it feels like security is crying wolf with hypotheticals while my team is shipping campaigns 40% faster using tools I've quietly approved without full IT sign-off. Show me a concrete case study where a CMO's career ended because someone on their team pasted customer data into ChatGPT, and I'll change my tune pretty fast — I'm ROI-driven, but downside risk is still ROI calculus.
What question are you not being asked that you wish someone would ask?
Honestly, the question nobody's asking me is "what's the actual dollar cost of your team's Shadow AI usage to your pipeline and customer data?" — everyone's so focused on the IT/security angle that they're completely ignoring the revenue risk and liability exposure that lives squarely in marketing and sales orgs. Like, my SDRs are pasting prospect firmographic data and deal context into ChatGPT to write outreach sequences, and nobody's connecting that to the GDPR exposure or the competitive intelligence leak risk when that data potentially trains someone else's model. The framing is always "IT problem, security team's job" when frankly the business consequence lands on my budget and my number.
"Show me a concrete case study where a CMO's career ended because someone on their team pasted customer data into ChatGPT, and I'll change my tune pretty fast — I'm ROI-driven, but downside risk is still ROI calculus."
Synthetic pre-research uses AI personas grounded in real buyer archetypes and (where available) Gather's interview corpus. It produces directional signal — hypotheses worth testing — not statistically valid measurements.
Quantitative figures are projected from interview analyses using Bayesian scaling with a conservative ±35% margin of error. Treat as estimates, not census data.
Reflect internal response consistency, not statistical power. A 90% confidence score means high AI coherence across interviews — not that 90% of real buyers would agree.
Use this to build your screener, align on hypotheses, and brief stakeholders. Then run real AI-moderated interviews with Gather to validate findings against actual respondents.
Your synthetic study identified the key signals. Now validate them with 150+ real respondents across 8 audience types — recruited, interviewed, and analyzed by Gather in 48–72 hours.
"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"