Gather Synthetic
Pre-Research Intelligence
Custom Research

"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"

Persona Types
8
Projected N
150
Questions / Interview
5
Signal Confidence
Avg Sentiment

⚠ Synthetic pre-research — AI-generated directional signal. Not a substitute for real primary research. Validate findings with real respondents at Gather →

Quantitative Projections · 150n · ±35% margin of error

By the numbers

Projected from interview analyses using Bayesian scaling. Treat as directional estimates, not census measurements.

Feature Value
—/10
Perceived feature value
Positive Sentiment
18%
41% neutral · 91% negative
High Adoption Intent
0%
0% medium · 0% low
Pain Severity
—/10
How acute the problem is
Sentiment Distribution
18%
41%
91%
Positive 18%Neutral 41%Negative 91%
Theme Prevalence
Shadow AI visibility gap — near-zero observability into what data employees send to external LLMs
89%
Policy-to-behavior enforcement gap — written policies treated as compliance theater
84%
Approved tooling demand failure — sanctioned tools too slow or limited, driving shadow usage
78%
Build vs. buy paralysis — internal cloud tenancy vs. skepticism of rebranded DLP vendors
72%
Vendor distrust — resistance to platform lock-in and unverified enterprise security claims
69%
Business velocity vs. security enforcement tension — CEO or board AI-first mandates
74%
Persona Analysis

How each segment responded

Side-by-side comparison of sentiment, intent, buying stage, and decision role across all personas.

Interview Transcripts

Full interviews · 8 respondents

Complete question-by-question responses with per-persona analysis. Click any respondent to expand.

A
Alex R.
CTO · Series C SaaS · Seattle, WA
mixed94% conf
44 yrsB2B Tech$275kbuild vs buy mindset · security-first · vendor fatigue · API-obsessed

Alex is a technically sophisticated CTO caught between two failure modes: becoming the productivity-killing 'no AI' executive, or sleepwalking into a compliance breach he can't detect. His core problem is a near-total visibility gap into external LLM API calls from employee devices, despite having sanctioned Azure OpenAI infrastructure in place. He's skeptical of the Shadow AI vendor landscape, viewing most offerings as rebranded DLP tools with inflated positioning. His ideal state is a unified data plane with semantic understanding of LLM traffic and network-layer enforcement — not endpoint agents or honor systems. The most telling signal is his Q5 revelation: his own governance tooling has fragmented into three non-integrated point solutions purchased without coordination, creating less visibility than before intervention. He's not anti-AI; he's anti-ungovernable-AI, and he's frustrated that the industry hasn't given him verifiable trust mechanisms to close the build-vs-buy decision.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night is that we've got engineers and product folks using Claude, ChatGPT, Gemini — whatever — and they're just... pasting in customer data, internal architecture docs, proprietary stuff, without even thinking about it. It's not malicious, it's just the path of least resistance. The real tension I'm wrestling with is that I don't want to be the CTO who kneecaps productivity by going full prohibition mode — that's a losing battle and people will just route around you anyway — but I also can't have our SOC 2 compliance and customer data agreements getting blown up because someone fed a support ticket with PII into a free tier ChatGPT account. What I'm actually trying to figure out is whether to build internal tooling on top of Azure OpenAI or Bedrock where we control the tenancy, versus buying one of these CASB-adjacent "Shadow AI detection" vendors who are frankly all slapping AI governance labels on products that were just DLP tools six months ago. I've got serious vendor fatigue and the last thing I need is another agent sitting on my endpoints.

2

What's the most important thing you need to understand or solve here?

The number one thing keeping me up at night is that I have zero visibility into what my engineers and product managers are actually sending to these external LLM APIs. Like, someone on my team could be pasting customer PII, proprietary pricing models, or our authentication architecture into Claude or ChatGPT right now, and I'd have no idea until we're in a breach notification scenario. The fundamental problem is that the threat surface expanded overnight — we went from worrying about USB drives and email exfiltration to every employee having a direct pipe to a third-party model that explicitly trains on your data unless you've negotiated enterprise terms. I need to solve the detection and enforcement layer without becoming the "no AI" guy who kills productivity, because that's a losing political battle when the board is asking why we're not "AI-first" in every quarterly review.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like having a unified data plane where I can see every AI API call leaving my environment — who made it, what model, what data classification touched it — with policy enforcement happening at the network layer, not the honor system. Basically a CASB that actually understands LLM traffic semantics, not just URL categorization. Where am I today? Honestly, I'd say we're at maybe 40% of that vision. We've got Azure OpenAI deployed for the sanctioned use cases with private endpoints and no training data opt-out concerns, but I know there are engineers and PMs hitting ChatGPT, Claude, Perplexity directly from their laptops with customer data context in those prompts — and my current tooling is essentially blind to that. The gap between what I can see and what's actually happening is what keeps me up at night.

4

What would change your perspective on this entirely?

Honestly? If someone showed me a Shadow AI incident that caused material harm — like a real data breach traced back to an employee pasting customer PII into ChatGPT — that would accelerate my timeline significantly. Right now I'm treating this as a "when not if" problem, but the board doesn't feel urgency until there's a headline with a dollar figure attached to it. The other thing that would flip my thinking is if one of the major cloud providers — Azure, AWS, Google — actually built a genuinely trustworthy tenant isolation model with cryptographic proof and third-party audits I could actually read, because right now "we keep your data secure" in a ToS is basically meaningless to me. That would make the build-vs-buy calculus much harder, because right now I lean toward building internal tooling precisely because I don't trust vendor claims I can't verify.

5

What question are you not being asked that you wish someone would ask?

The question nobody's asking me is: "What happens when your AI governance stack itself becomes a shadow IT problem?" We've now got three different tools claiming to be the authoritative solution for monitoring AI usage — Nightfall, some Microsoft Purview configuration, and a point solution our security team bought without telling me — and none of them talk to each other, so I actually have *less* visibility than before we started "solving" this. The cure is metastasizing into the disease, and I'd love to have a real conversation about how you prevent your AI risk tooling from becoming the next layer of ungoverned sprawl.

"The cure is metastasizing into the disease — we've now got three different tools claiming to be the authoritative solution for monitoring AI usage and none of them talk to each other, so I actually have less visibility than before we started solving this."
Language Patterns for Copy
"path of least resistance""zero visibility into what my engineers are actually sending""direct pipe to a third-party model""honor system""unified data plane""CASB that actually understands LLM traffic semantics""cryptographic proof and third-party audits I could actually read""when not if""the cure is metastasizing into the disease""ungoverned sprawl""board doesn't feel urgency until there's a headline with a dollar figure""serious vendor fatigue"
A
Alex R.
CTO · Series C SaaS · Seattle, WA
mixed92% conf
44 yrsB2B Tech$275kbuild vs buy mindset · security-first · vendor fatigue · API-obsessed

Alex is a technically sophisticated CTO acutely aware that his official AI governance posture is decoupled from on-the-ground engineer behavior. His core anxiety is not external threat actors but well-intentioned senior engineers routinely exfiltrating customer data and proprietary IP through unsanctioned AI tools, invisible to his current DLP stack because prompt strings don't look like file transfers. He's at 60% visibility and 30% enforcement by his own estimate, with Azure OpenAI providing at least tenant-boundary control for sanctioned usage, but personal browser traffic to Claude or Perplexity is completely dark to him. He's leaning toward building on existing network observability rather than adding another vendor, but that instinct would shift fast for an API-first, inline policy enforcement tool that doesn't demand data plane ownership. His most underexplored and emotionally resonant pain point — the one he says nobody asks about — is the absence of a quantified blast radius model for governance failure: he's making risk investment decisions on vibes rather than expected loss calculations, which signals a high-value consultative wedge for any vendor who can help him model actual financial and reputational exposure.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night is the gap between what our policy says and what's actually happening on developer laptops at 11pm. We've got an official stance on approved AI tooling — Azure OpenAI, private endpoints, the whole nine yards — but I know engineers are piping customer data through Claude.ai or ChatGPT because it's just *faster* for them in the moment. The data exfiltration surface area has exploded and our DLP tooling was built for a world where the sensitive data moved in files, not in prompt strings that look like casual conversation to any inspection layer. What I'm genuinely wrestling with is: do I try to buy a Shadow AI detection product and add another vendor to my already bloated stack, or do I build something on top of our existing network observability that catches the API calls out to OpenAI endpoints? Either path has real tradeoffs and neither one fully solves the policy enforcement problem at the human behavior layer.

2

What's the most important thing you need to understand or solve here?

The honest answer? It's the visibility problem. I have zero idea what my engineers are actually sending to Claude or GPT-4 or whatever flavor-of-the-week model they've spun up this week. And these aren't junior people — they're senior engineers who know exactly how to route around controls they find inconvenient. They're pasting customer data, proprietary architecture docs, pricing models into these tools and genuinely believing "well OpenAI said they don't train on API calls" like that's a sufficient risk analysis. The thing that keeps me up at night isn't some external threat actor — it's my own team's well-intentioned sloppiness at scale. I need to know what's leaving my perimeter before I can even begin to have a policy conversation, and right now I'm essentially flying blind on that.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like a world where I have full observability into every AI API call leaving my environment — who made it, what data touched it, what model it went to — with policy enforcement happening at the network layer, not just a checkbox in an AUP that nobody reads. Basically a unified control plane for AI traffic the same way we have for network traffic. Today? We're probably 60% there on the visibility side, maybe 30% on enforcement. I've got decent logging on our sanctioned tools — we're Azure OpenAI for most things, which at least keeps data in our tenant — but the shadow usage is the nightmare. Someone's inevitably piping customer data into Claude or Perplexity through their personal browser, and I have no telemetry on that unless I'm doing full SSL inspection, which creates its own legal headaches in Washington state.

4

What would change your perspective on this entirely?

Honestly? If someone showed me a Shadow AI solution that was genuinely API-first, with clean webhooks and didn't require me to rip out half my existing security stack to deploy it, I'd reconsider a lot of my build-leaning instincts pretty quickly. Right now every vendor I talk to wants to be the platform, wants to own the data plane, wants me to route everything through their cloud — and that's a non-starter for us given where our customer data sensitivity sits. Show me a tool that operates more like a policy enforcement layer that sits inline without being another data silo, and I'm listening. The other thing that would shift me is if the regulatory environment crystallized — right now I'm making bets on what compliance frameworks are going to demand in 18 months, and if NIST or SOC 2 auditors got specific about Shadow AI controls, that would force my hand toward a commercial solution faster than any sales pitch ever could.

5

What question are you not being asked that you wish someone would ask?

The question nobody's asking me is: "What's your actual blast radius if your AI governance strategy fails?" Everyone wants to talk about policies and tools and frameworks, but nobody's pressure-testing the failure modes. Like, if one of my engineers has been piping customer data into some random AI wrapper for six months and we find out during a SOC 2 audit, what does that actually cost us in terms of customer contracts, regulatory exposure, and reputational damage with our enterprise buyers? That's the number I want someone to help me model, because right now I'm making risk investment decisions based on vibes and compliance checklists instead of actual expected loss calculations.

"The question nobody's asking me is: 'What's your actual blast radius if your AI governance strategy fails?' Everyone wants to talk about policies and tools and frameworks, but nobody's pressure-testing the failure modes. Right now I'm making risk investment decisions based on vibes and compliance checklists instead of actual expected loss calculations."
Language Patterns for Copy
"data exfiltration surface area has exploded""prompt strings that look like casual conversation to any inspection layer""senior engineers who know exactly how to route around controls they find inconvenient""genuinely believing 'well OpenAI said they don't train on API calls' like that's a sufficient risk analysis""my own team's well-intentioned sloppiness at scale""unified control plane for AI traffic""60% visibility, 30% enforcement""SSL inspection creates its own legal headaches in Washington state""every vendor wants to own the data plane — that's a non-starter""making bets on what compliance frameworks are going to demand in 18 months""blast radius if your AI governance strategy fails""risk investment decisions based on vibes and compliance checklists"
J
Jordan K.
Senior PM · Fintech Startup · Austin, TX
mixed91% conf
28 yrsFintech$130klean methodology · user research believer · rapid iteration · engineering-empathetic

Jordan is a fintech Senior PM acutely aware that his organization's AI security posture is performative — a Confluence policy nobody reads while engineers actively pipe customer transaction data, KYC info, and account metadata into ChatGPT under deadline pressure. He self-rates compliance maturity at 4/10 and is most troubled not by rogue junior employees but by his highest-performing engineers, who are sophisticated enough to circumvent controls and feel zero ownership over rules they had no input in creating. His core insight is that this is a demand-side failure: approved tooling is slower and worse, so the productivity delta drives shadow usage. He knows blanket bans backfire and is actively searching for a company-controlled inference layer — single-tenant infrastructure where data never hits third-party servers — but views the current vendor market as immature. He'd reconsider his threat model only if shown empirical breach data (vs. security team incentive-driven anecdote) or real retention and velocity data from a fintech that implemented tight AI controls without engineering exodus.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night is the gap between what our security policy *says* and what's actually happening on the ground. I know for a fact that engineers on my team are piping customer transaction data into ChatGPT to debug stuff or write summaries, and our "policy" is basically a Confluence page that nobody's read. In fintech, that's not just an embarrassing audit finding — that's a potential SOC 2 violation, that's customer PII, that's sensitive financial data hitting OpenAI's servers and we're just kind of... hoping their enterprise tier actually means what it says? What I'm wrestling with is how do you actually *enforce* this without killing the productivity gains that are genuinely real — like, I've seen what happens when you blanket-ban tools, people just get sneakier about it. I want the solution that's more like guardrails than a brick wall, but I haven't seen anything that actually solves that elegantly yet without being super heavy-handed IT overhead.

2

What's the most important thing you need to understand or solve here?

The thing that keeps me up at night is honestly the gap between what leadership *thinks* is happening with AI usage versus what's actually happening on the ground. Like, our compliance team put out this policy saying "don't paste customer data into ChatGPT," and meanwhile our ops folks are absolutely doing exactly that because it saves them two hours a day and no one's built them a better alternative. The real problem I need to solve is: how do we get visibility into that shadow usage without just becoming the AI police and destroying the productivity gains people have already discovered, because if I kill those workflows people will just get sneakier about it. In fintech especially, we're sitting on transaction data, KYC info, account details — the exposure risk isn't theoretical, it's genuinely one bad prompt away from a compliance nightmare that could tank us with regulators. What I actually want is some kind of middle-ground infrastructure — think company-controlled inference layer where our people get the AI capabilities they need but the data never touches OpenAI's servers directly — but building that is non-trivial and buying it feels like we're in very early vendor market where everyone's slapping "enterprise AI security" on something half-baked.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like having a clear, enforceable policy that doesn't just say "don't use unauthorized AI" but actually gives engineers and PMs a sanctioned set of tools that are fast enough and good enough that they don't feel the need to go rogue — like, you're solving the demand problem, not just the prohibition problem. Right now we're probably a 4 out of 10 on that scale — we have a policy document that legal drafted, we have Copilot approved for some teams, but I literally watched someone in our last sprint demo paste customer transaction metadata into vanilla ChatGPT because our approved tooling was too slow for what they needed. The gap between "what compliance says" and "what people actually do under deadline pressure" is enormous, and we're a fintech so that's not a theoretical risk, that's a potential regulatory incident. What I really want is something closer to what one person described in a procurement thread I saw — like, company-controlled infrastructure where we're the only tenant, so the productivity isn't sacrificed but the data boundary is real.

4

What would change your perspective on this entirely?

Honestly? If I saw solid empirical evidence that the actual breach risk from Shadow AI was significantly lower than the compliance and productivity cost of locking everything down, I'd completely reconsider my current stance. Right now I'm operating on vibes and anecdote from security teams who have every incentive to overstate the threat because that's how they justify headcount. The other thing that would shift me is if someone showed me a fintech that successfully implemented air-gapped or heavily controlled AI infrastructure without absolutely torching their engineering team's velocity — like actual retention data, shipping cadence before and after, not just a CISO blog post saying "we did it and it was fine." We're competing for talent with companies where engineers can use whatever tools they want, so the calculus isn't just security risk, it's also existential product risk if your best people walk.

5

What question are you not being asked that you wish someone would ask?

Honestly? Nobody's asking **"what happens to your security posture when your best engineers are actively incentivized to circumvent your AI policies?"** Like, that's the real tension nobody wants to touch. We've built this whole compliance framework around Shadow AI, but the engineers I work closest with — the ones I genuinely need shipping features — they're the most sophisticated about routing around restrictions, and they're doing it because our approved tooling is genuinely worse and slowing them down. So I'm sitting here thinking, are we optimizing for the audit trail or are we optimizing for actual risk reduction? Because right now it feels like we're just creating a compliance theater that our smartest people see straight through, and the real data leakage risk is actually higher because those folks don't feel ownership over rules they had zero input into building.

"The engineers I work closest with — the ones I genuinely need shipping features — they're the most sophisticated about routing around restrictions, and they're doing it because our approved tooling is genuinely worse and slowing them down. So I'm sitting here thinking, are we optimizing for the audit trail or are we optimizing for actual risk reduction?"
Language Patterns for Copy
"compliance theater our smartest people see straight through""one bad prompt away from a compliance nightmare""solving the demand problem, not just the prohibition problem""company-controlled inference layer""security risk plus existential product risk if your best people walk""operating on vibes and anecdote from security teams with every incentive to overstate""people just get sneakier about it""guardrails not a brick wall""zero input into building"
J
Jordan K.
Senior PM · Fintech Startup · Austin, TX
mixed91% conf
28 yrsFintech$130klean methodology · user research believer · rapid iteration · engineering-empathetic

Jordan is a fintech Senior PM with acute, well-reasoned anxiety about Shadow AI — not as a theoretical risk but as an active, unmonitored reality inside his org. He knows employees are already pasting customer PII and transaction data into ChatGPT and Claude to ship faster, and he has zero visibility into it. His core insight is that the 'just ban it' approach has already failed silently, and the real leverage point is provisioning sanctioned tools that are genuinely better than the shadow alternatives, combined with lightweight, non-punitive monitoring. His most provocative and underexplored position is that this is fundamentally a product failure — not a security one — because bad approved tooling creates the incentive to hide unauthorized usage. He also expresses healthy skepticism toward vendor-manufactured urgency, demanding real incident data over threat modeling before fully elevating it as a priority. His ownership framing is notably self-aware: PMs like him greenlit the workflows that created the risk, yet face no clear accountability model when things break.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night is that we're a fintech, so we're already under a microscope from a compliance standpoint — SOC 2, PCI, all that fun stuff — and then you've got engineers and PMs just casually pasting customer transaction data into ChatGPT to debug something or write a quick analysis. Like, nobody's being malicious, they're just trying to ship faster, which I totally get because I'm the same way. But the gap between "leadership says no unauthorized AI" and what's actually happening on people's laptops is enormous, and we have zero real visibility into it right now. I keep pushing for us to either provision something sanctioned that people actually *want* to use — because if the approved tool is garbage, they'll route around it every time — or at least get some kind of monitoring in place before we end up in a situation where customer PII has leaked into some third-party model's training data and we're explaining that to regulators.

2

What's the most important thing you need to understand or solve here?

The thing I keep coming back to is that we're building financial products, so the stakes around data leakage are genuinely existential for us — like, if a developer pastes customer transaction data into some random ChatGPT prompt, that's not just an IT slap on the wrist, that's a regulatory incident. So the core problem I'm trying to solve is: how do I give my team the AI productivity gains they're already taking anyway, through shadow usage, while actually controlling where the data goes. The "just ban it" approach is a non-starter because people are already using it and lying about it, which is worse. I'd much rather build a controlled on-ramp — whether that's a private Azure OpenAI deployment or something similar — than play whack-a-mole with browser extensions and personal ChatGPT accounts. The real unsolved piece for me is detection: I have no visibility right now into what's actually flowing out of our org to third-party AI services, and that gap feels like a ticking clock given we're handling PII and financial data under some pretty serious compliance obligations.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like having a clear, lightweight policy layer that doesn't block productivity but gives us visibility into what data is flowing where — like, I should be able to pull a dashboard and see "hey, three engineers pasted customer PII into Claude yesterday" without it being a whole investigation. We're probably 60-70% away from that honestly, because right now our "policy" is basically a Confluence page that nobody reads and a Slack message from our CISO that went out six months ago. The other piece of "good" that I think gets overlooked is that enforcement shouldn't feel punitive — it should feel like a guardrail that helps people do their jobs better, not a surveillance state. Right now we're in this awkward middle ground where leadership is screaming "AI everything" while simultaneously having zero infrastructure to actually govern what that means for our customer financial data, which in fintech is not a theoretical risk, that's a compliance catastrophe waiting to happen.

4

What would change your perspective on this entirely?

Honestly? If I saw real evidence that the risk was actually materializing in ways that hurt companies like ours — like a documented case where a fintech our size got hit with a regulatory fine or a major data breach specifically traced back to an engineer pasting customer PII into Claude or ChatGPT — that would shift my calculus pretty fast. Right now it still feels like a lot of the Shadow AI panic is coming from enterprise security vendors who have obvious incentives to sell you a platform to solve the problem. Show me the actual incident data, not the threat modeling, and I'll take it more seriously as a product priority versus just a compliance checkbox.

5

What question are you not being asked that you wish someone would ask?

Honestly? Nobody's asking about the **PM's role in Shadow AI risk** — like, everyone's treating this as purely a security or IT problem, and I'm sitting here thinking, we're the ones who greenlit half these workflows in the first place. When I'm doing user research and I see that my engineering team has built a feature pipeline that's quietly calling out to some third-party LLM because it was faster to ship, that's a product decision that has security implications — and right now there's no clear ownership model for who's accountable when that blows up in fintech, where we're talking about actual PII and transaction data going somewhere sketchy. I wish someone would ask: "How do you build a product culture where engineers feel safe telling you they're using an unauthorized AI tool instead of hiding it?" Because the real Shadow AI problem isn't the tool, it's the incentive structure — people are reaching for Claude or GPT-4 because the approved alternatives are slower and clunkier, and that's a product failure before it's a security failure.

"I wish someone would ask: 'How do you build a product culture where engineers feel safe telling you they're using an unauthorized AI tool instead of hiding it?' Because the real Shadow AI problem isn't the tool, it's the incentive structure — people are reaching for Claude or GPT-4 because the approved alternatives are slower and clunkier, and that's a product failure before it's a security failure."
Language Patterns for Copy
"gap between leadership says no and what's happening on people's laptops is enormous""if the approved tool is garbage they'll route around it every time""that's not just an IT slap on the wrist, that's a regulatory incident""people are already using it and lying about it, which is worse""ticking clock given we're handling PII and financial data""our policy is basically a Confluence page that nobody reads""enforcement shouldn't feel punitive — it should feel like a guardrail""leadership is screaming AI everything while having zero infrastructure to govern it""show me the actual incident data, not the threat modeling""a product failure before it's a security failure"
C
Chris W.
Head of Demand Gen · Series A Startup · Austin, TX
mixed94% conf
32 yrsB2B SaaS$135kpipeline-obsessed · channel tester · attribution headache · CAC-conscious

Chris is a Head of Demand Gen at a Series A B2B SaaS company caught in a genuine bind: his team's AI tool usage is driving real productivity gains, but he has zero visibility into what proprietary data — ICP profiles, CAC benchmarks, pipeline reports, messaging frameworks — is being fed into unsanctioned tools like ChatGPT, Claude, and Perplexity. Critically, he self-identifies as part of the problem, openly admitting he personally pastes prospect data and competitive intel into AI tools in ways that would alarm his CISO. He is skeptical of enterprise security vendor narratives, dismissing them as fear-mongering repackaged for budget cycles. His behavior would shift if he saw a concrete, peer-company breach story with a direct line to business consequence — not abstract risk. His sharpest insight is structural: the most productive, revenue-generating employees are also the highest Shadow AI risk, and policies restrictive enough to stop them just produce compliance theater while data leakage continues undetected.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, my biggest headache right now isn't even the security angle — it's that half my team is running campaigns and content through ChatGPT or Claude without any standardization, and I have zero visibility into what's getting pumped into those tools. Like, are they pasting in our ICP data? Our CAC benchmarks? Our pipeline reports? I genuinely don't know, and that keeps me up at night more than any formal security audit would. The other thing I'm wrestling with is that I'm trying to move fast — we're a Series A, pipeline is everything, and if AI tools are helping my demand gen folks move 2x faster on content and outreach, I can't just slam the brakes. But I also don't want to be the guy who accidentally leaks our go-to-market strategy into some third-party model's training data. It's a real tension between "ship fast" and "don't blow up the company."

2

What's the most important thing you need to understand or solve here?

Honestly? My biggest problem is that I have zero visibility into what my team is actually feeding into these AI tools on a day-to-day basis. Like, I know my content person is using Claude, my ops person is using ChatGPT, someone's probably got Perplexity running — and I have no idea if they're pasting in our ICP data, our pipeline numbers, our messaging frameworks that took us six months to build. From a CAC and competitive standpoint, that stuff is our actual moat, and if it's training some model or getting exposed somewhere, I've got a real problem. What I need to solve is basically: how do I get guardrails in place without killing the productivity gains that are genuinely moving pipeline for us?

3

What does 'good' look like to you — and how far are you from that today?

Good looks like me knowing exactly what tools my team is using, having some guardrails so nobody's pasting our ICP data or campaign performance numbers into a random ChatGPT session, and still letting people actually move fast — because if I lock everything down, my team just routes around it anyway. Like, I need the visibility without becoming the fun police. Where are we today? Honestly pretty far from that. We've got maybe four or five people on my demand gen team who are all using different AI tools — some sanctioned, some definitely not — and I have zero insight into what's getting fed into those prompts. Our CRM data, our competitive intel, our messaging frameworks... I'm just trusting that nobody's doing something dumb with it, which is not a great place to be at a Series A company trying to protect a differentiated go-to-market story.

4

What would change your perspective on this entirely?

Honestly? If I saw hard data showing that Shadow AI actually caused a material breach at a company our size — like a Series A B2B SaaS, not some Fortune 500 with a completely different threat surface — that would shift things for me fast. Right now it feels like a lot of the risk narrative is coming from enterprise security vendors who have every incentive to make me scared, and I'm already drowning in "omnichannel AI-powered synergistic" vendor pitches that are just repackaged fear. But if one of my reps pasted our pricing model or a prospect's contract terms into ChatGPT and that ended up somewhere it shouldn't, and I could see a direct line between that action and a real business consequence — lost deal, legal liability, whatever — I'd be in my CEO's office the next day asking what our actual policy is and why we don't have enforcement tooling in place.

5

What question are you not being asked that you wish someone would ask?

Honestly? Nobody ever asks me "what are *you* personally doing that your company's IT team would hate if they found out?" Because the answer is — a lot. I'm pasting prospect data into Claude to build better ICP models, I'm running competitive intel through ChatGPT, I'm doing stuff that would give our CISO a heart attack if they saw it. And I guarantee every demand gen person at every Series A company is doing the same thing, we're just not talking about it openly. The real question the security industry should be asking is why the most productive people in the company are also the biggest Shadow AI risk — because if your policies are so restrictive that your revenue-generating teams are routing around them, you haven't solved a security problem, you've just created a compliance theater problem while the actual data leakage keeps happening anyway. That tension is where all the interesting stuff lives and nobody wants to have that honest conversation.

"Nobody ever asks me 'what are *you* personally doing that your company's IT team would hate if they found out?' Because the answer is — a lot. I'm pasting prospect data into Claude to build better ICP models, I'm running competitive intel through ChatGPT, I'm doing stuff that would give our CISO a heart attack if they saw it."
Language Patterns for Copy
"zero visibility into what's getting pumped into those tools""don't be the guy who accidentally leaks our go-to-market strategy""our messaging frameworks that took us six months to build""trusting that nobody's doing something dumb with it""my team just routes around it anyway""repackaged fear""compliance theater problem while the actual data leakage keeps happening""most productive people in the company are also the biggest Shadow AI risk""give our CISO a heart attack""pipeline is everything"
C
Chris W.
Head of Demand Gen · Series A Startup · Austin, TX
mixed82% conf
32 yrsB2B SaaS$135kpipeline-obsessed · channel tester · attribution headache · CAC-conscious

Chris is a Series A Demand Gen leader acutely aware that his team is routinely exfiltrating sensitive prospect and pipeline data into consumer-tier LLMs — but he is caught between real pipeline pressure and theoretical (to him) security risk. His core fear isn't regulatory — it's a concrete enterprise sales scenario where a prospect due diligence question about internal data handling exposes his company's total lack of governance. He doesn't need convincing that the problem exists; he needs a credible financial or deal-loss case study to justify reprioritizing against a CEO-driven velocity mandate. He explicitly rejects the security-only framing and demands a 'value-preserving guardrails' narrative — signaling he'd champion a solution positioned as enabling safe AI adoption rather than restricting it. His self-assessed maturity score of 3/10 and 'honor system equals nothing' framing suggest he is close to a tipping point but waiting for external validation of the stakes.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night isn't even our own AI usage — it's the fact that half my team is running prospect data through ChatGPT or Claude without thinking twice about it. Like, I'll ask someone to build a target account list analysis and they're just... copy-pasting company revenue data, contact info, intent signals we paid good money for — straight into a free tier OpenAI account. That's our pipeline intelligence, our ICP data, potentially MNPI if we're targeting public companies. And I have zero visibility into it. The other piece is attribution and CAC — I'm already fighting that battle every quarter — but now I've got rogue AI experiments spinning up that are touching our CRM data, our ad platform connections, and I don't even know what's getting logged where. It's like I've got a shadow martech stack growing inside my shadow AI stack. Security hasn't really come to us yet with any real enforcement, just a vague "don't put sensitive stuff in AI tools" Slack message from IT six months ago, which, let's be real, nobody actually read.

2

What's the most important thing you need to understand or solve here?

Honestly, the thing keeping me up at night from a marketing ops perspective is that half my team is pasting prospect data, ICP firmographics, and campaign briefs into ChatGPT or Claude without even thinking twice about it. Like, we're a Series A SaaS company — our pipeline data and our customer segments are basically our competitive moat right now, and that stuff is just flying into third-party LLMs with zero visibility on my end. The real problem is I don't even know the blast radius. Is it happening once a week? Twenty times a day? I have no idea what's actually leaving our systems, and when I try to raise it with our one-person IT team, they look at me like I'm the fun police while the CEO is simultaneously telling everyone to "move fast with AI." The tension I'm trying to solve is: how do I let my team actually use these tools to hit pipeline targets — because they genuinely need them, I'm not going to pretend otherwise — without us accidentally leaking something that kills a deal or creates a compliance nightmare when we're trying to close enterprise accounts that ask us about our data handling practices. That's the kill shot right there — losing a deal because a prospect asks "how do you protect customer data internally" and we have no credible answer.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like a world where I can actually see what AI tools my team is using, have some guardrails so they're not pasting our ICP data or pipeline numbers into random ChatGPT sessions, and still move fast enough to compete. Like, I want visibility without being the fun police who kills productivity. Honestly we're pretty far from that today — I'd say we're at a 3 out of 10. Right now it's basically the honor system, which means it's basically nothing.

4

What would change your perspective on this entirely?

Honestly? If I saw hard evidence that Shadow AI was actually causing material pipeline damage or a real breach that got traced back to someone pasting prospect data into ChatGPT — like a documented, public case study that hit a company our size — that would wake me up. Right now it feels like the security team is selling me on risk that's theoretical while I'm sitting here with very real CAC targets and a board that wants 3x pipeline by Q3. If someone showed me the math that said "this Shadow AI incident cost us a deal or triggered a compliance fine that wiped out six months of demand gen budget," I'd realign my priorities fast — but I haven't seen that story told compellingly yet.

5

What question are you not being asked that you wish someone would ask?

Honestly? Nobody ever asks me how Shadow AI is actually *helping* my pipeline and whether that's worth the risk tradeoff. Everyone frames this whole conversation as purely a security and compliance problem, but from where I sit, half my team is moving faster because they're using tools IT hasn't blessed yet — and that velocity is showing up in our numbers. Like, I'm not saying we should ignore data leakage risk, especially when someone's pasting prospect data or pricing intel into a random ChatGPT session, but the conversation is always "how do we lock this down" and never "how do we get the legitimate value without the exposure." That nuance gets completely lost when security teams come in with a blanket ban mentality — they kill productivity and people just get sneakier about it, which actually makes the risk worse.

"That's the kill shot right there — losing a deal because a prospect asks 'how do you protect customer data internally' and we have no credible answer."
Language Patterns for Copy
"shadow martech stack growing inside my shadow AI stack""I have zero visibility into it""our pipeline data and customer segments are basically our competitive moat""I don't even know the blast radius""honor system, which means it's basically nothing""the fun police who kills productivity""theoretical risk vs. very real CAC targets""people just get sneakier about it, which actually makes the risk worse""the math that said this Shadow AI incident cost us a deal""how do we get the legitimate value without the exposure"
M
Marcus T.
VP of Marketing · Series B SaaS · San Francisco, CA
mixed91% conf
34 yrsB2B Tech$180kdata-driven · ROI-obsessed · skeptical of fluff · ex-agency

Marcus is a business leader caught between genuine security concern and relentless productivity pressure, who has rationalized inaction by framing data leakage risk as theoretical and unquantified. He has near-zero visibility into what sensitive data — competitive positioning, pipeline forecasts, customer segmentation — his team is feeding into personal AI accounts, and he knows it. Security's eight-month policy vacuum has effectively handed tacit permission to employees. His unlock is not education or policy: it's a concrete dollar-denominated breach case study or an enterprise customer inserting Shadow AI clauses into vendor contracts. Critically, he surfaces an underexplored counter-argument — the quantifiable productivity cost of AI restriction — which he believes is systematically ignored in security conversations and represents real competitive disadvantage.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night is that my team is using AI tools constantly — Claude, ChatGPT, Perplexity, whatever — and I have zero visibility into what's actually going into those prompts. We're talking competitive positioning docs, customer segmentation data, pricing strategy. That's not generic stuff, that's the crown jewels. The frustrating part is that security comes to me with this blanket "we're evaluating a policy" response that's been "in evaluation" for like eight months, while my team is just... doing the work. I'm not going to tell my content strategist to stop using AI when she's 3x more productive — that's a business decision that has a real ROI cost. But I also can't tell you with a straight face that I know our data isn't training some model somewhere.

2

What's the most important thing you need to understand or solve here?

Honestly, the thing keeping me up at night is the data leakage problem — specifically my team using personal ChatGPT or Claude accounts to process customer data, competitive intel, pipeline info, things that should never leave our walls. I'm not even sure how widespread it is because nobody's going to raise their hand and say "hey, I pasted our Q3 revenue forecast into a free LLM." The audit trail is essentially nonexistent right now, and that's a massive liability both from a compliance standpoint and a competitive standpoint.

3

What does 'good' look like to you — and how far are you from that today?

Honestly, "good" for me looks like having actual visibility into what tools my team is using and what data is flowing where — not a spreadsheet I maintain manually, but real-time telemetry. Like, I want to know if someone on my demand gen team just pasted our entire Q3 pipeline data into Claude or ChatGPT to generate a board deck. Right now I'm probably 60-70% blind to that, which is a problem I've kind of just accepted because the business pressure to move fast with AI is relentless. The gap between where I want to be and where I am is significant, but I'm not sure security is going to fix it before some new tool my team is already using makes the whole question moot.

4

What would change your perspective on this entirely?

Honestly? If someone showed me a documented, quantifiable data breach that was directly attributable to an employee using an unauthorized GenAI tool — with a clear dollar amount attached — that would change how seriously I push this up the chain. Right now it still feels theoretical in my world, like "someone *could* paste our customer segmentation data into ChatGPT and it *could* end up somewhere bad," but I haven't seen a concrete case study that hits close enough to home to make me stop treating this as IT's problem versus mine. The other thing that would shift my perspective is if one of our enterprise customers — we sell to mid-market and enterprise — started putting Shadow AI clauses into our vendor contracts, because then suddenly it becomes a revenue risk and that's a language I speak fluently. Show me the pipeline impact or the breach postmortem, and I'll care a lot more than I do today.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question nobody's asking me is "what's the actual dollar value of the productivity you're *losing* because your security team locked down AI tools?" Like, we spend all this time talking about Shadow AI risk and data leakage, but nobody's building a model for the cost of over-restriction — my team is burning hours on tasks that our competitors are doing in minutes because IT said no to half the tools we actually need. The risk calculus is completely one-sided in these conversations, and that asymmetry is costing companies real money that doesn't show up in any security audit. I'd love for someone to force both sides to put actual numbers on the table instead of security just defaulting to "no" because the downside is visible and the upside is diffuse.

"Nobody's building a model for the cost of over-restriction — my team is burning hours on tasks that our competitors are doing in minutes because IT said no to half the tools we actually need. The risk calculus is completely one-sided and that asymmetry is costing companies real money that doesn't show up in any security audit."
Language Patterns for Copy
"crown jewels""60-70% blind""audit trail is essentially nonexistent""cost of over-restriction""Shadow AI clauses in vendor contracts""show me the pipeline impact or the breach postmortem""IT's problem versus mine""security just defaulting to no because the downside is visible and the upside is diffuse"
M
Marcus T.
VP of Marketing · Series B SaaS · San Francisco, CA
mixed91% conf
34 yrsB2B Tech$180kdata-driven · ROI-obsessed · skeptical of fluff · ex-agency

Marcus is a pro-AI marketing leader at a Series B company who has stumbled into a shadow AI crisis by accident — not through audits or policy, but by seeing an employee's screen on a Zoom call. His core anxiety is the gap between having an AI policy and having any actual enforcement or detection capability. He knows sensitive data (CRM exports, competitive positioning, pipeline data) is leaving the environment through free-tier AI tools, but has zero visibility into it. Critically, he is not a buyer of fear-based security narratives — he explicitly demands documented breach case studies at his company's scale before reprioritizing budget. His most distinctive insight is inverting the risk framing: he argues the cost of AI prohibition is itself a quantifiable risk, because locked-down teams route around IT controls using personal devices, making the data exposure worse. He wants someone to model the probability-weighted cost of under-enablement versus the actual incident risk — a framing almost no security vendor is offering him.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night is that my team is just... using stuff. ChatGPT, Claude, Perplexity, whatever — they're pasting in customer data, competitive intel, campaign briefs with client names — and I only know about it because I happened to see someone's screen during a Zoom. There's no formal policy, IT doesn't have visibility, and when I brought it up to our CISO, she basically shrugged and said "we're working on it." The frustrating part is I'm not anti-AI — I'm probably the biggest AI advocate in our leadership team — but there's a real difference between "move fast" and "paste your entire CRM export into a free tier ChatGPT account." I don't actually know what's leaving our environment, and for a Series B company trying to close enterprise deals, that's a material risk to our contracts and our reputation.

2

What's the most important thing you need to understand or solve here?

Look, the thing keeping me up at night isn't whether my team is *using* AI — they absolutely are, I encourage it. It's that I have zero visibility into what's actually being pasted into ChatGPT or Claude on any given Tuesday. We're talking competitive positioning docs, pipeline data, customer personas built on actual CRM exports — that stuff is walking out the door through browser tabs and I don't have a dashboard that tells me it happened. The gap between "we have an AI policy" and "we can actually enforce or even detect violations of that policy" is enormous, and right now we're firmly in the former camp while pretending we're in the latter.

3

What does 'good' look like to you — and how far are you from that today?

Honestly, "good" to me looks like having full visibility into what AI tools my team is actually using, what data they're pushing into them, and being able to enforce guardrails without killing productivity. Like, I want a single pane of glass where I can see — okay, someone on my demand gen team just pasted our entire customer segmentation model into ChatGPT, that's a problem. We're nowhere near that today. Right now I'm essentially flying blind, running on trust and hoping nobody's feeding our pipeline data or competitive positioning docs into some random free tier tool that's training on our inputs.

4

What would change your perspective on this entirely?

Honestly? Show me the breach. Like, give me a concrete, documented case study where a company our size — Series B, 200-300 employees — had a material business outcome damaged specifically because someone on the marketing team pasted something into ChatGPT. Right now it feels like a lot of enterprise security vendors are selling fear without receipts, and I've been in enough agency pitches to recognize when someone's manufacturing urgency around a problem that's more theoretical than real. If I saw actual data — lost deal because competitive pricing leaked through an AI prompt, regulatory fine tied to Shadow AI specifically — then I'd reprioritize the budget conversation with our CISO immediately.

5

What question are you not being asked that you wish someone would ask?

Honestly? Nobody's asking about the **ROI of doing nothing** — like, what's the actual cost of being so locked down on AI that your team is just going rogue anyway, using personal Gmail accounts to pipe customer data into ChatGPT because IT blocked everything? That's the real shadow AI problem nobody wants to quantify. I've seen it firsthand — you implement a draconian policy, you think you've solved the risk, and meanwhile your SDRs are copy-pasting prospect data into free-tier Claude on their phones. The question I want someone to ask is: "What's the measurable productivity and retention cost of under-enabling your team versus the actual probability-weighted risk of a data incident?" Because right now every conversation is framed around the downside of AI usage, and nobody's modeling the downside of AI prohibition.

"You implement a draconian policy, you think you've solved the risk, and meanwhile your SDRs are copy-pasting prospect data into free-tier Claude on their phones."
Language Patterns for Copy
"paste your entire CRM export into a free tier ChatGPT account""I only know about it because I happened to see someone's screen during a Zoom""flying blind, running on trust""selling fear without receipts""ROI of doing nothing""draconian policy, you think you've solved the risk""single pane of glass""material risk to our contracts and our reputation""probability-weighted risk of a data incident""the downside of AI prohibition"
Methodology

How to interpret this report

What this is

Synthetic pre-research uses AI personas grounded in real buyer archetypes and (where available) Gather's interview corpus. It produces directional signal — hypotheses worth testing — not statistically valid measurements.

Statistical projection

Quantitative figures are projected from interview analyses using Bayesian scaling with a conservative ±35% margin of error. Treat as estimates, not census data.

Confidence scores

Reflect internal response consistency, not statistical power. A 90% confidence score means high AI coherence across interviews — not that 90% of real buyers would agree.

Recommended next step

Use this to build your screener, align on hypotheses, and brief stakeholders. Then run real AI-moderated interviews with Gather to validate findings against actual respondents.

Primary Research

Take these findings
from synthetic to real.

Your synthetic study identified the key signals. Now validate them with 150+ real respondents across 8 audience types — recruited, interviewed, and analyzed by Gather in 48–72 hours.

Validated interview guide built from your synthetic data
Real respondents matching your exact persona specs
AI-moderated interviews with qual depth + quant confidence
Board-ready report in 48–72 hours
Book a call with Gather →
Your Study
"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"
150
Respondents
8
Persona Types
48h
Turnaround
Gather Synthetic · synthetic.gatherhq.com · August 12, 2026
Run your own study →