Gather Synthetic
Pre-Research Intelligence
Custom Research

"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"

Persona Types
8
Projected N
150
Questions / Interview
5
Signal Confidence
Avg Sentiment

⚠ Synthetic pre-research — AI-generated directional signal. Not a substitute for real primary research. Validate findings with real respondents at Gather →

Quantitative Projections · 150n · ±35% margin of error

By the numbers

Projected from interview analyses using Bayesian scaling. Treat as directional estimates, not census measurements.

Feature Value
—/10
Perceived feature value
Positive Sentiment
18%
74% neutral · 58% negative
High Adoption Intent
0%
0% medium · 0% low
Pain Severity
—/10
How acute the problem is
Sentiment Distribution
18%
74%
58%
Positive 18%Neutral 74%Negative 58%
Theme Prevalence
Shadow AI visibility gap
89%
Policy-enforcement disconnect
84%
Data leakage via AI prompts as novel DLP problem
76%
Productivity vs. security tension
71%
Reactive rather than proactive detection
68%
Vendor trust and third-party audit credibility
62%
Persona Analysis

How each segment responded

Side-by-side comparison of sentiment, intent, buying stage, and decision role across all personas.

Interview Transcripts

Full interviews · 8 respondents

Complete question-by-question responses with per-persona analysis. Click any respondent to expand.

A
Alex R.
CTO · Series C SaaS · Seattle, WA
mixed92% conf
44 yrsB2B Tech$275kbuild vs buy mindset · security-first · vendor fatigue · API-obsessed

Alex is a technically sophisticated CTO operating in a state of informed concern rather than crisis or panic. His primary pain is lack of visibility into shadow AI usage — specifically the gap between written policy and actual enforcement at the network and API layer. He has made partial progress (~60-70% on sanctioned tooling) but acknowledges the unsanctioned usage problem remains genuinely unsolved. He frames the challenge in two distinct layers: detection (knowing what tools are in use) and remediation (deciding what to do once you know). He is actively evaluating CASB-type and proxy-based solutions but describes the situation as 'still pretty messy.' His perspective would shift if major AI providers offered independently auditable tenant isolation, and if DLP tooling matured enough to provide real visibility without surveillance-culture backlash. He also surfaces a structural concern that is often overlooked: if sanctioned tools offer a worse user experience than shadow alternatives, monitoring alone cannot close the compliance gap.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing keeping me up at night right now is that we've got employees using whatever AI tools they want, and I have no systematic visibility into it. Someone on the engineering team is probably pasting code snippets into Claude, someone in sales is dumping customer data into ChatGPT to write follow-ups, and I only find out about it when something surfaces accidentally. The policy side is almost the easier problem — we've written the policy, people nominally agree to it. But enforcement is a different story entirely. We don't have great tooling to actually see where data is flowing at the egress layer in a way that's specific to AI services versus general web traffic. The other thing I'm wrestling with is the vendor angle. Every SaaS tool we already have is now claiming they've added AI, so the attack surface is expanding through tools we thought we'd already vetted. Our CRM, our support platform, our documentation tools — they've all shipped AI features in the last year, and half of them have data retention or training clauses buried in updated ToS that we didn't catch in real time. I don't have a clean answer to any of it yet. We're evaluating some CASB-type solutions and looking at whether we can route AI traffic through a controlled proxy, but it's still pretty messy operationally.

2

What's the most important thing you need to understand or solve here?

The core problem for us right now is visibility. I genuinely don't have a complete picture of what AI tools my engineers and product folks are actually using day-to-day. Someone's pasting customer data into ChatGPT, someone else is using a browser extension that's routing prompts god-knows-where — and our standard SaaS discovery tooling wasn't built to catch that pattern. The second layer is that even when I do know about a tool, I don't always know what data is leaving the building. The prompt itself is the data exfiltration vector, and that's a fundamentally different problem than traditional DLP. So the question I'm trying to answer is: how do I get instrumentation at the API and network layer that actually tells me what's going out, without turning into a surveillance state that kills productivity and drives people to use their phones instead.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having a clear inventory of every AI tool touching our environment — sanctioned or not — with data classification policies that actually enforce at the API layer, not just in an acceptable use policy PDF nobody reads. And ideally we're running inference on models we control, either self-hosted or through a private tenant arrangement, so customer data and proprietary business logic isn't transiting some third-party's infrastructure. How far are we from that? Honestly, we're probably 60-70% of the way on the sanctioned tooling side. We've got guardrails on the approved stack. Where it gets murky is the unsanctioned stuff — engineers spinning up their own API keys, someone on the sales team pasting customer context into a consumer ChatGPT interface. That's the gap that keeps me up at night more than the tools I can actually see. The harder problem is that enforcement at the identity and network layer is technically tractable, but getting the business to slow down long enough to implement it properly is the real friction. There's constant pressure to move fast on AI adoption, and the risk management conversation feels like it's always playing catch-up to the enthusiasm.

4

What would change your perspective on this entirely?

That's a good question. Honestly, what would shift my thinking most is if I saw consistent, credible evidence that the major AI providers — OpenAI, Anthropic, whoever — had genuinely solved the tenant isolation problem in a way that's independently auditable, not just their word for it. Right now a lot of the "your data is safe with us" messaging feels like marketing copy. If third-party security audits became standard and transparent, that would move the needle for me on how aggressively we route sensitive data through external APIs. The other thing that would change my perspective is if the tooling for detecting shadow AI usage matured to the point where enforcement was actually tractable. Right now it feels like a whack-a-mole problem — you block ChatGPT on corporate devices and someone's just using their phone. If DLP and network monitoring got to a place where you had real visibility without creating a surveillance culture that tanks morale, that would change how I think about policy enforcement versus just trying to build sanctioned internal alternatives.

5

What question are you not being asked that you wish someone would ask?

Honestly, I don't have some dramatic "the question nobody asks" framing ready. But if I think about what's missing from most of these conversations... I think people focus a lot on the *detection* side of shadow AI — like, how do you find out what tools employees are using — and not enough on the *remediation* path. Okay, you found out someone in finance is pasting supplier pricing into ChatGPT. Now what? Do you block them? Educate them? Build an internal alternative? That whole decision tree is where the real operational complexity lives, and I don't hear it discussed much in a structured way. The other thing, and this is more specific to my build-versus-buy instincts, is whether your approved AI tooling is actually good enough that people feel like they *want* to use it. Because if the sanctioned path is clunky and slow and the shadow path is three times faster, you've got a policy problem that no amount of monitoring solves. You have to close that experience gap, not just the compliance gap.

"The prompt itself is the data exfiltration vector, and that's a fundamentally different problem than traditional DLP."
Language Patterns for Copy
"no systematic visibility""enforcement is a different story entirely""attack surface is expanding through tools we thought we'd already vetted""data retention or training clauses buried in updated ToS""prompt itself is the data exfiltration vector""without turning into a surveillance state that kills productivity""60-70% of the way on the sanctioned tooling side""risk management conversation feels like it's always playing catch-up""independently auditable, not just their word for it""whack-a-mole problem""close that experience gap, not just the compliance gap"
A
Alex R.
CTO · Series C SaaS · Seattle, WA
mixed92% conf
44 yrsB2B Tech$275kbuild vs buy mindset · security-first · vendor fatigue · API-obsessed

Alex is a CTO at a mid-sized B2B SaaS company who is actively wrestling with the gap between documented AI acceptable use policy and actual developer behavior. His core concern is that employees — not maliciously, but for convenience — are pasting proprietary code and customer data into consumer AI tools, creating both security and contractual risk. He currently estimates he has visibility into roughly 40% of AI usage (sanctioned tools only), with shadow usage remaining largely opaque and remediation workflows being manual. His definition of 'good' is a near-real-time, automated detect-classify-enforce-log loop with data classification context. He is skeptical of provider-side security assurances as an auditable control and frustrated that organizational pressure consistently favors adoption speed over risk discipline. His primary unmet need is infrastructure- and API-layer enforcement visibility, not policy documentation — a distinction he feels is underappreciated in most external research.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep coming back to is the gap between what our policy says and what's actually happening on developer laptops day to day. We've got an acceptable use policy for AI tools, we've documented it, we've communicated it — and I still have reasonable confidence that engineers are pasting proprietary code or customer data into ChatGPT or Claude or whatever they've spun up on their own. Not maliciously, just because it's frictionless and fast. The harder problem is that I can't just block it at the network level without creating enough friction that I slow down legitimate productivity. So there's this constant tension between enforcement and not becoming the team that's seen as standing in the way of people doing their jobs. The other piece is third-party data exposure. We're a B2B SaaS company, so our systems touch customer data. When someone pastes a snippet that has a customer identifier or a config value in it — even if they think it's harmless — that's potentially a contractual issue for us, not just a security issue. And most of the people doing it aren't thinking about that at all. So that's the thing I'm wrestling with most right now: how do you build guardrails that are actually enforceable without just saying "air gap everything," because that's not realistic either.

2

What's the most important thing you need to understand or solve here?

The core thing for us right now is visibility. We're a mid-sized SaaS company, and I genuinely don't have a complete picture of what AI tools my engineers and product folks are actually using day-to-day. Someone's pasting customer data into ChatGPT, someone else is using a browser extension with an LLM backend — I don't always know about it until after the fact. The second piece is that once I have visibility, I need a policy framework that's actually enforceable rather than just a document that sits in Confluence. The challenge is balancing that with not killing productivity — my team is going to find workarounds if I'm too restrictive, and then I've got the same shadow IT problem I always had, just with AI on top of it. So really it's: detect what's happening, decide what's acceptable, and enforce that in a way that doesn't create more friction than it's worth.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having a single pane of glass where I can see every AI API call leaving my environment, who made it, what data classification touched it, and whether it violated policy — all in near real-time. And then automated enforcement, not just alerting. Where are we today? Honestly, maybe 40% of the way there. We've got decent visibility on sanctioned tools — things we've actually procured and integrated through our own infrastructure. But the long tail of shadow usage, someone spinning up a personal ChatGPT account and pasting in customer data, or a developer quietly wiring a side project to an external model endpoint — that's still pretty opaque to us. We catch things reactively more than proactively. The other gap is that even when we detect something, the remediation workflow is manual and slow. Policy exists, but enforcement isn't automated. So "good" also means closing that loop — detect, classify, enforce, log — without requiring a human in the middle of every incident.

4

What would change your perspective on this entirely?

Honestly, the thing that would shift my thinking the most is if we got reliable, transparent data routing guarantees from the major model providers. Right now the fundamental problem is that when an employee pastes something into ChatGPT or Claude, I have no verifiable audit trail of where that data actually goes — the providers say it's secure, but "they say" isn't a control I can put in a SOC 2 report. If Microsoft or Anthropic or whoever could give me cryptographically verifiable proof that my tenant's data never touched shared infrastructure or training pipelines, that changes the conversation significantly. The single-tenant hosted model is closer to what I'd want, but the cost and operational overhead is still rough. The other thing — and this is more organizational than technical — is if I saw executive leadership actually willing to slow down adoption when a use case doesn't clear the risk bar. Right now the pressure is almost always in the other direction. Finance wants the efficiency gains yesterday, and risk management becomes the obstacle. If that dynamic shifted, we could build something more coherent instead of playing whack-a-mole with shadow usage.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I'd want someone to ask is: "How are you actually enforcing your AI policy at the API and network layer, not just in your employee handbook?" Because most of the conversation I see is about policy documents and training — "did your employees sign the acceptable use policy" — and that's almost theater at this point. The real enforcement question is whether you have visibility into where data is actually going at the infrastructure level. That's where I spend a lot of my time thinking, and I feel like most of the research I come across doesn't go that deep technically.

"We catch things reactively more than proactively. The other gap is that even when we detect something, the remediation workflow is manual and slow. Policy exists, but enforcement isn't automated."
Language Patterns for Copy
"gap between what our policy says and what's actually happening""not maliciously, just because it's frictionless and fast""that's potentially a contractual issue for us, not just a security issue""visibility""a policy framework that's actually enforceable rather than just a document that sits in Confluence""single pane of glass""maybe 40% of the way there""catch things reactively more than proactively""detect, classify, enforce, log — without requiring a human in the middle of every incident""cryptographically verifiable proof""'they say' isn't a control I can put in a SOC 2 report""playing whack-a-mole with shadow usage""that's almost theater at this point""where data is actually going at the infrastructure level"
J
Jordan K.
Senior PM · Fintech Startup · Austin, TX
mixed91% conf
28 yrsFintech$130klean methodology · user research believer · rapid iteration · engineering-empathetic

Jordan is a Senior PM at a fintech startup navigating a well-articulated but unresolved tension: leadership is pushing AI adoption while security and compliance teams are not yet comfortable with the data risks. His core concern is not philosophical — it is operational. He lacks visibility into what AI tools employees are actually using and what data is touching them, and he considers this observability gap more urgent than policy refinement. He is not alarmist; he explicitly pushes back on vendor-driven risk framing and wants empirical data before committing to aggressive lockdown approaches. His preferred end state is 'guardrails, not a wall' — lightweight, auditable controls that don't push behavior underground. He also identifies a governance gap that he sees as underexplored: no single team owns the Shadow AI risk problem, and it falls between security, engineering, and product. His tone throughout is measured, pragmatic, and self-aware about the limits of his current knowledge.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Yeah, so the thing I keep coming back to is that we have this really wide gap between what leadership wants — which is basically "AI everything, ship fast" — and what our security and compliance folks are actually comfortable with. And in fintech, that tension is especially acute because we're dealing with customer financial data, and the regulatory exposure is real. What I'm personally wrestling with is the data boundary question. Like, people on my team are using ChatGPT, Claude, whatever, to draft PRDs, analyze user research outputs — and some of that research contains verbatim customer feedback or internal pricing logic. I don't have a clean answer for where that data goes. Vendors say it's secure, but I've seen enough incidents in the industry to be skeptical of "trust us." The other thing is just the policy enforcement gap. We have an acceptable use policy that nobody's read, and no real tooling to know when someone's pasted something sensitive into a third-party model. It's mostly honor system right now, which feels pretty fragile for a regulated environment. I don't have a strong view yet on the right technical solution — whether that's a private deployment, some kind of API proxy with DLP controls, whatever. We're still pretty early in figuring that out.

2

What's the most important thing you need to understand or solve here?

The biggest thing for us right now is just getting visibility into what's actually happening. Like, we're a fintech startup — we have compliance obligations, we're handling financial data, and I genuinely don't have a clean picture of what tools engineers or analysts are spinning up on their own. Someone could be pasting customer transaction data into a third-party LLM and I wouldn't necessarily know about it. The policy side is almost secondary to that. We can write all the policies we want, but if we don't have observability into where data is going, it's kind of performative. So the core problem I'm trying to solve is: how do we get that signal without creating so much friction that people just route around the controls entirely — because they will, and honestly I get why they do it.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like having a clear, auditable picture of what AI tools people are actually using, what data is touching those tools, and a lightweight policy layer that doesn't completely kill productivity. Like, I want guardrails, not a wall. Where we are today is... pretty far from that, honestly. We have a policy that says "don't paste customer PII into external AI tools," but enforcement is basically on the honor system. I don't have visibility into whether that's actually happening. The gap between the policy document and actual observed behavior is significant, and that's the part that keeps me up a bit — especially in fintech where we have regulatory obligations around data handling. The middle ground I keep coming back to is something like a company-controlled environment where we're the only tenant — so the data question becomes more manageable — but standing that up properly takes real infrastructure investment that we haven't prioritized yet. So right now we're somewhere between "aspirational policy" and "meaningful enforcement," and I'd say that's probably true for a lot of companies our size.

4

What would change your perspective on this entirely?

Honestly, the thing that would shift my thinking the most is if I started seeing real evidence that the risk is being systematically overstated — like if we got actual incident data showing that shadow AI usage at companies like ours is resulting in meaningful breaches at a rate that justifies the compliance overhead being proposed. Right now a lot of the framing feels like it's coming from vendors and security consultants who have something to sell. I'd want to see more neutral, empirical data — what's actually leaking, how often, what was the real damage — before I'd fully buy into the more aggressive lockdown approaches. The other thing that could shift me is if we found a lightweight enforcement mechanism that didn't just push people toward workarounds. Because right now when you over-restrict, you just drive behavior underground further — people use personal devices, personal accounts. That's worse than the original problem. If someone showed me a model where guardrails genuinely improved behavior rather than just relocating it, I'd take that seriously.

5

What question are you not being asked that you wish someone would ask?

Honestly, I think the question that gets skipped is: "Who actually owns this problem inside your org?" Like, everyone talks about the technical controls — DLP, SSO integration, whatever — but nobody asks about the governance gap between security, IT, and product teams. In our case, I'm a PM, so I'm kind of sitting in the middle. Security wants to lock everything down, engineering wants to ship fast, and leadership is saying everything needs to have AI in it. And nobody's explicitly accountable for the Shadow AI risk piece. It just kind of falls through the cracks between those three groups. I don't have a strong view on whether that's unique to fintech or more universal, but I'd be curious if that ownership ambiguity shows up consistently in your research.

"The policy side is almost secondary to that. We can write all the policies we want, but if we don't have observability into where data is going, it's kind of performative."
Language Patterns for Copy
"gap between what leadership wants and what compliance is comfortable with""I don't have a clean answer for where that data goes""honor system right now, which feels pretty fragile""get that signal without creating so much friction that people route around the controls""guardrails, not a wall""somewhere between aspirational policy and meaningful enforcement""framing feels like it's coming from vendors who have something to sell""when you over-restrict, you just drive behavior underground""nobody's explicitly accountable for the Shadow AI risk piece"
J
Jordan K.
Senior PM · Fintech Startup · Austin, TX
mixed91% conf
28 yrsFintech$130klean methodology · user research believer · rapid iteration · engineering-empathetic

Jordan is a measured, analytically grounded senior PM grappling with a real and active governance gap: GenAI tool adoption among engineers and analysts is outpacing the organization's policy and visibility infrastructure. The core concern is data leakage risk — particularly around customer financial data and PII being pasted into consumer AI tools — in a regulated fintech environment. Jordan is not alarmist but is genuinely frustrated by the structural tension between leadership's 'AI-first' posture and the slower-moving compliance conversation. The immediate priority is observability: understanding what is actually happening before trying to enforce policy. Jordan's vision of 'good' is pragmatic — lightweight, followable guardrails backed by real enforcement, not theater. The most distinctive insight is Jordan's framing of the governance gap as a team-level problem, not just a CISO-level one: individual teams are making daily data judgment calls without a consistent framework, and that delta between policy and practice is where the real risk lives.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Yeah, so the thing I keep coming back to is — we're a fintech, right, so we have actual regulatory exposure. PCI, SOC 2, some state-level privacy stuff. And the pace at which our engineers and our analysts are just... reaching for whatever GenAI tool is convenient is kind of outrunning our ability to have a coherent policy around it. Like, it's not malicious. Nobody's trying to create a problem. But when someone pastes customer transaction data into a prompt because they're trying to debug something quickly, that's a real data leakage risk, and we don't always have visibility into when that's happening. The other piece I'm wrestling with is that leadership is very much in "we need to be AI-forward" mode — which I get — but the risk management conversation feels like it's lagging behind. It's the unsexy stuff, compliance, data residency, who's actually the tenant on these third-party services — that tends to get deprioritized when everyone's excited about productivity gains. So I'm genuinely trying to figure out what a lightweight, non-obstructive policy looks like that gives us guardrails without making people feel like we're blocking them from doing their jobs.

2

What's the most important thing you need to understand or solve here?

The biggest thing for us right now is honestly just getting visibility. Like, I can't solve a problem I can't see. People on the team are using ChatGPT, Claude, whatever — for legitimate productivity reasons — but I have no real line of sight into what's going into those prompts. And in fintech, that's not a hypothetical concern. We're dealing with user financial data, transaction records, sometimes PII adjacent stuff. So before we even get to policy enforcement, the question is: what's actually happening day to day? That's the gap I want to close first. Once I have that picture, then I can have a real conversation with engineering and security about where the actual risk is versus where people are just being productive in ways that happen to make compliance nervous.

3

What does 'good' look like to you — and how far are you from that today?

Good looks like a state where we have visibility into what tools people are actually using, some sensible guardrails around data classification, and policies that people can realistically follow without just routing around them. Like, if your policy is so restrictive that engineers are spinning up personal accounts to get work done anyway, that's not good security — that's just theater. How far are we from that? Honestly, moderately far. We have an approved toolset, we've done some work on data classification, but the enforcement layer is pretty thin. And the pressure from leadership to "be AI-first" makes it harder, not easier — because when the CEO is excited about something, the risk conversation gets a shorter window. I don't have a strong view on exactly how to quantify that gap, but I feel it operationally pretty regularly.

4

What would change your perspective on this entirely?

That's a good question to sit with for a second. Honestly, if I saw solid evidence that the data leakage risks I'm worried about were actually being overstated — like, if there were real, transparent audit trails showing that enterprise AI vendors are genuinely segregating data the way they claim — that would shift things for me. Right now a lot of it feels like "trust us," and we don't have great visibility into what's actually happening on the other side of those API calls. The other thing that would change my thinking is if policy enforcement tooling got good enough that security teams could actually detect and respond to shadow AI usage without it becoming a massive compliance overhead. Because right now the monitoring story feels pretty immature — it's either very heavy-handed or basically nonexistent. If someone showed me a lightweight approach that actually worked at scale without slowing down legitimate usage, I'd be genuinely interested in that.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I keep waiting for is something like: "How are you actually governing AI usage at the team level, not just the org level?" Like, everyone's focused on top-down policy — what's allowed, what's blocked at the network layer — but the real gap I see is that individual teams are making judgment calls every day about what data goes into which tool, and there's no consistent framework for that. In fintech especially, the delta between what a policy document says and what actually happens when an engineer is trying to hit a sprint deadline is... significant. I don't have a dramatic story about a breach or anything, but I do think the governance conversation is almost entirely happening at the CISO level when it probably needs to be embedded at the team lead level too.

"If your policy is so restrictive that engineers are spinning up personal accounts to get work done anyway, that's not good security — that's just theater."
Language Patterns for Copy
"outrunning our ability to have a coherent policy""I can't solve a problem I can't see""the enforcement layer is pretty thin""trust us — and we don't have great visibility""the monitoring story feels pretty immature""governance conversation is almost entirely happening at the CISO level""the delta between what a policy document says and what actually happens"
C
Chris W.
Head of Demand Gen · Series A Startup · Austin, TX
mixed88% conf
32 yrsB2B SaaS$135kpipeline-obsessed · channel tester · attribution headache · CAC-conscious

Chris is a Demand Gen leader at a Series A company who is genuinely concerned but not alarmed about Shadow AI use on his team. His primary problem is visibility — he cannot account for what data has left the organization via unsanctioned or personal AI tool usage. He acknowledges the behavior is happening (CRM exports, prospect lists, campaign data pasted into ChatGPT), has no formal policy or audit capability, and describes his company's current posture as 'hoping nothing bad happens.' His concern is compounded by the irony of selling into enterprises who ask about his company's own data handling. He sees the risk as real but still somewhat theoretical — a concrete incident or compliance mandate would shift him to action. His unprompted insight is that marketing teams are an overlooked Shadow AI risk vector relative to the attention paid to engineering or finance.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing that keeps coming up for me is that our team is just... using stuff. Like, someone's pasting prospect data into ChatGPT to help write sequences, someone else is running competitive research through one of these tools, and I'm not even fully sure what's going into those prompts. The question I keep coming back to is — where does that data actually go? We're a Series A company, so we don't have a dedicated security team breathing down our neck yet, but we're starting to sell into larger enterprises and they're asking us about our own data handling practices, which then makes me think about what we're doing internally. It feels a little hypocritical. I don't have strong visibility into what IT or leadership is actually doing about it policy-wise. There's no formal playbook that I've seen. So right now it's mostly just people using whatever's available and being sort of self-governing about it, which I don't love.

2

What's the most important thing you need to understand or solve here?

Honestly, the thing I keep running into is that I don't fully know what my team is doing with AI day-to-day. Like, I can see the tools we've officially procured and paid for, but the free tier stuff, the personal ChatGPT accounts people are using to draft copy or analyze campaign data — that's a blind spot for me. And some of that campaign data has competitive intel, customer segments, stuff I wouldn't want sitting in a third-party model's training pipeline. So the core problem for me isn't really a policy question — it's a visibility question. I don't have a clean answer to "what data has left the building through an AI tool this quarter." And that makes me a little uncomfortable, honestly.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, would be having clear visibility into what AI tools my team is actually using, with some confidence that customer data and pipeline data isn't being passed into third-party models without guardrails. Like, we use a bunch of things — HubSpot, some AI writing tools, Clay, whatever someone on the team found that week — and honestly I don't have a clean picture of all of it. The ideal state is probably something where there's a lightweight policy that people actually follow, tooling that gives IT or whoever some audit capability without becoming a bureaucratic nightmare, and enough flexibility that my team isn't going around the approved stack just to get work done. Because that workaround behavior is real — if the approved tools are too slow or too limited, people just use whatever works. How far are we from that? Pretty far, honestly. We're a Series A company, so security infrastructure is pretty lean. There's no formal Shadow AI policy that I'm aware of. I'd say we're in the "hoping nothing bad happens" phase, which I know isn't great.

4

What would change your perspective on this entirely?

Honestly, the thing that would change my perspective the most is if I started seeing real data leakage incidents tied back to specific GenAI tool usage — like an actual post-mortem where someone at a company similar to ours pasted prospect data or pricing info into ChatGPT and it created a measurable business problem. Right now for me it feels a bit theoretical. The other thing would be if our legal or compliance team came to me with a hard requirement — like "you can't use these tools for anything touching customer data, full stop." That would force a real process change. But right now it's more of a loose policy than an enforced one, and I'm not sure how different that is from most Series A companies.

5

What question are you not being asked that you wish someone would ask?

Honestly, I don't know if there's some burning question nobody's asking. But if I had to pick something... I'd say people aren't asking enough about the *marketing team specifically* as a Shadow AI risk vector. Like, everyone frames this as an IT or security problem, and sure, that's fair. But my team is probably the fastest-moving group when it comes to adopting new tools — AI for content, AI for data analysis, AI baked into every piece of ad tech we use. And we're not always thinking carefully about what customer data or campaign data is flowing into these third-party services. We're just trying to hit pipeline numbers. Security teams are worried about engineers or finance people, but demand gen folks are pasting prospect lists, CRM exports, intent data into these tools constantly. I don't think that's on anyone's radar the way it should be.

"I don't have a clean answer to 'what data has left the building through an AI tool this quarter.' And that makes me a little uncomfortable, honestly."
Language Patterns for Copy
"visibility question, not a policy question""blind spot — free tier stuff, personal ChatGPT accounts""hoping nothing bad happens phase""workaround behavior is real""marketing team as Shadow AI risk vector""feels a little hypocritical""lightweight policy that people actually follow""still feels theoretical to me"
C
Chris W.
Head of Demand Gen · Series A Startup · Austin, TX
mixed88% conf
32 yrsB2B SaaS$135kpipeline-obsessed · channel tester · attribution headache · CAC-conscious

Chris is a pragmatic, AI-positive demand gen leader who has identified a real governance gap but is not in crisis mode about it. His team is actively using a range of AI tools with no formal policy, and semi-proprietary marketing data — pipeline numbers, channel spend, segment conversion data — is routinely going into third-party models with no audit trail. He is self-policing by instinct, not by design, and he acknowledges this is a gap. His primary concern is not security per se but operational risk and lack of visibility. He is moderately concerned today but would escalate internally if shown evidence of material breaches at comparable-stage companies. He is skeptical of vague vendor security claims and would respond positively to concrete architecture documentation showing data segregation and tenant control. He also raises an underappreciated counterpoint: over-restriction has a real productivity cost that rarely gets modeled, and any solution needs to preserve his team's go-to-market velocity to be viable.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep running into is that my team is using AI tools constantly — Claude, ChatGPT, whatever gets the job done — and I have no real visibility into what's going into those prompts. Like, we're pasting in campaign performance data, sometimes prospect intel, occasionally things that touch on our ICP segmentation that I'd consider semi-proprietary. And nobody's really stopped to ask whether that's okay from a data standpoint. It's not like we're being reckless — everyone's just trying to move faster. But I've started wondering what would happen if someone on my team pasted the wrong thing into the wrong tool and it ended up somewhere it shouldn't. I don't have a strong view on how our security team is actually monitoring for that, if at all. My suspicion is they're not, at least not in any systematic way. The other thing is there's no real policy from above. I got a vague "use AI responsibly" memo sometime last year and that was basically it. So we're operating in this gray zone where I'm kind of self-policing my team based on my own judgment, which feels like a gap.

2

What's the most important thing you need to understand or solve here?

Honestly, for me it's less about the security angle per se and more about the operational risk that comes from my team using tools I don't have visibility into. Like, someone on my demand gen team is probably pasting campaign performance data or prospect lists into some free AI tool, and I have no idea what's happening to that data downstream. The attribution and CAC tracking work we do — that stuff has competitive intelligence baked into it. Pipeline numbers, channel spend breakdowns, conversion data by segment. If that's going into a third-party model that's training on it, that's a real problem, and I genuinely don't know how to audit for it right now. So the core thing I need to solve is: how do I get visibility into what my team is actually using without becoming the person who shuts everything down and kills productivity? Because the tools are genuinely useful — I'm not anti-AI at all. It's just the data governance piece that feels really underdeveloped at our stage.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, is being able to use AI tools freely across the team without constantly worrying that someone pasted a prospect list or campaign data into a random free ChatGPT session. Like, we want the productivity gains — everyone's using these tools for copy, for data analysis, for campaign briefs — but I want some reasonable assurance that our pipeline data and customer info isn't being used to train some third-party model. Honestly we're pretty far from that today. We don't have a formal Shadow AI policy. I know people on my team are using whatever tools they find useful, and I'm probably guilty of the same thing. The "good" state would be having something company-approved with clear guardrails — ideally where we control the data tenancy — but right now it's pretty ad hoc. Security hasn't really come knocking on marketing's door about it yet, which is either fine or a warning sign depending on how you look at it.

4

What would change your perspective on this entirely?

Honestly, if I saw data showing that Shadow AI incidents were actually leading to material breaches or significant pipeline-level damage at companies similar to ours — Series A, lean team, maybe 50-80 people — that would shift how seriously I'm pushing this internally. Right now it feels like a concern that's more relevant to enterprises with thousands of endpoints and sensitive regulated data, not where we are. The other thing that would move me is if a vendor could show me a clean architecture diagram — like, literally diagram out how my team's prompts and data are segregated from other tenants, what content monitoring looks like, how they're preventing leakage. Right now most of the conversations I've had are pretty hand-wavy on that. If someone could make that concrete and tie it to something I actually control as a buyer, rather than just saying "we're enterprise-grade and secure," that would change the conversation pretty fast.

5

What question are you not being asked that you wish someone would ask?

Honestly, the thing nobody really digs into is the productivity cost of over-restriction. Like, everyone's focused on "how do we stop Shadow AI" but nobody's asking "what happens to your team's output when you lock everything down?" On my team, if IT blanket-blocks access to the tools people are already using to get work done, they just find workarounds anyway — or they slow down significantly. And that has a real pipeline impact for a demand gen function that's moving fast. So I'd love someone to ask: how do you actually balance the risk management side with not grinding your go-to-market motion to a halt? Because right now that conversation feels pretty one-sided toward compliance, and the business cost of over-restriction isn't really getting modeled out.

"How do I get visibility into what my team is actually using without becoming the person who shuts everything down and kills productivity? Because the tools are genuinely useful — I'm not anti-AI at all. It's just the data governance piece that feels really underdeveloped at our stage."
Language Patterns for Copy
"no real visibility into what's going into those prompts""operating in this gray zone""self-policing my team based on my own judgment""competitive intelligence baked into it""Shadow AI incidents leading to material breaches""clean architecture diagram""hand-wavy on that""productivity cost of over-restriction""they just find workarounds anyway""pretty ad hoc"
M
Marcus T.
VP of Marketing · Series B SaaS · San Francisco, CA
mixed91% conf
34 yrsB2B Tech$180kdata-driven · ROI-obsessed · skeptical of fluff · ex-agency

Marcus is a marketing VP caught between organizational pressure to adopt AI rapidly and legitimate concern about uncontrolled data exposure through his team's everyday use of consumer AI tools. He is not alarmed or in crisis — his tone is measured and analytical — but he has a genuine, unresolved problem: no scalable enforcement mechanism, policy that amounts to informal guidance, and partial visibility through existing tooling. He frames his primary need as visibility into what data is actually entering third-party models, not tool-blocking. He is skeptical that current vendor solutions can deliver both enforcement and productivity without tradeoffs, and he wants proof via architecture walkthroughs and enforcement data, not marketing materials. His unprompted concern about the cost of over-restriction is a meaningful signal: he is equally worried about driving shadow AI underground as he is about the exposure itself.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep coming back to is that my team is using AI tools constantly — ChatGPT, Claude, whatever — and I have no real visibility into what's actually being pasted into those prompts. We're talking about campaign strategies, competitive positioning, pricing intel from sales calls. That stuff is genuinely sensitive, and the informal understanding is basically "don't put anything confidential in there," but that's not a policy, that's a hope. The harder part is that security and IT want tighter controls, but the business pressure is "use AI everywhere, go faster." So I'm sort of caught in the middle — I'm not going to slow my team down in ways that hurt pipeline, but I also don't want to be the VP whose team leaked something material. I don't have a clean answer to that tension right now.

2

What's the most important thing you need to understand or solve here?

Honestly, the biggest thing for me is understanding where the actual exposure is. Like, we know people on my team are using ChatGPT, Claude, whatever — that's just a given at this point. The question is what's going into those prompts. Are they pasting in customer data, pricing strategy, unreleased campaign briefs? That's the real risk. It's less about blocking tools and more about having visibility. I don't have a strong view on the technical enforcement side — that's more of an IT and security problem — but from a marketing leadership perspective, I need to know if my team is inadvertently leaking competitive or customer information to a third-party model. That's the thing that keeps me up at night, not the productivity angle.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like visibility plus proportionality. I want to know what tools my team is actually using, have a clear policy that's enforced without being so restrictive that people just route around it, and have some confidence that customer data or proprietary campaign strategy isn't sitting in a third-party model's training pipeline somewhere. How far are we from that? Honestly, closer on visibility than on enforcement. We can see a lot of the traffic through our SSE layer, but the policy side is still pretty manual — someone spots something, flags it, we have a conversation. That's not scalable. The data leakage piece is where I feel least comfortable. We've had internal discussions about proprietary GTM strategy, competitive positioning documents — stuff that would be genuinely sensitive if it ended up in a shared model context. We don't have great controls there today beyond telling people "be thoughtful," which is not a security posture. So I'd say we're maybe 40-50% of the way to what I'd consider good. The awareness is there, the tooling is partial, the enforcement is reactive.

4

What would change your perspective on this entirely?

Honestly, the thing that would move me most is seeing actual enforcement data — not just policy documentation, but evidence that organizations are successfully detecting and acting on Shadow AI violations at scale without grinding productivity to a halt. Right now I'm pretty skeptical that most tools in this space can do both simultaneously. The other thing that would shift my view is if a vendor could show me a clear, auditable diagram of how my company's data is actually segregated from other tenants and from model training pipelines. Not a sales deck, not a trust page — a real architecture walkthrough. That conversation almost never happens cleanly when you push on it.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I'd want more people to ask is: "What's the actual cost of over-restricting AI access versus under-restricting it?" Everyone's focused on the risk of data leakage — and that's real — but nobody's measuring the productivity drag when you lock things down so hard that your team just uses their personal devices on personal accounts anyway. You've just moved the shadow AI problem somewhere harder to see. I don't have a precise number to put on it, but anecdotally, when IT gets too heavy-handed, people route around it. That's not a security win.

"The informal understanding is basically 'don't put anything confidential in there,' but that's not a policy, that's a hope."
Language Patterns for Copy
"that's not a policy, that's a hope""visibility plus proportionality""40-50% of the way to what I'd consider good""enforcement is reactive""the thing that keeps me up at night""a real architecture walkthrough — that conversation almost never happens cleanly""you've just moved the shadow AI problem somewhere harder to see""be thoughtful — which is not a security posture"
M
Marcus T.
VP of Marketing · Series B SaaS · San Francisco, CA
mixed88% conf
34 yrsB2B Tech$180kdata-driven · ROI-obsessed · skeptical of fluff · ex-agency

Marcus is a pragmatic, self-aware VP of Marketing at a Series B company who recognizes a real and specific problem — lack of visibility into what proprietary data his team is sending through consumer AI tools — but is not in acute crisis mode about it. He has accepted a state of 'managed ambiguity': he knows the policy is largely unenforced, the IT team is stretched, and budget isn't there yet. He is not anti-AI; in fact, he values productivity gains and explicitly doesn't want to restrict tool usage. His primary need is visibility and lightweight data classification enforcement, not comprehensive lockdown. He is skeptical of monitoring tools that produce audit logs no one reads and wants to see evidence of actual behavior change. A secondary but notable theme is his frustration that security conversations focus only on risk without quantifying the cost of over-restriction. He is not urgently in market but would accelerate if he saw a credible, same-stage company breach traced to AI tool misuse.

1

Tell me what's top of mind for you on this topic right now — what are you wrestling with?

Honestly, the thing I keep coming back to is that my team is using AI tools constantly — ChatGPT, Claude, various writing assistants — and I have no real visibility into what's actually being sent out. Like, someone could be pasting a competitive positioning doc or pricing strategy into one of these tools and I wouldn't know. That's the part that keeps me up at night more than anything theoretical about "shadow AI." The policy side is almost secondary at this point. We have an acceptable use policy on paper, but enforcement is basically nonexistent. And I get why — these tools are genuinely useful for campaign copy, research synthesis, competitive analysis — so I'm not going to tell my team to stop. But there's a real gap between "we said don't put confidential data in there" and actually knowing whether that's happening. I don't have a strong view yet on what the right solution looks like. I've heard people talk about private deployments, dedicated tenancy, that kind of thing — but for a Series B company, the cost and complexity of that feels heavy. So right now it's mostly just... managed ambiguity, I guess.

2

What's the most important thing you need to understand or solve here?

Honestly, the most pressing thing for us right now is just getting visibility into what's actually happening. People on my team are using ChatGPT, Claude, whatever — for copywriting, campaign briefs, competitive research — and I have limited insight into what data is leaving the building through those tools. It's less about banning things and more about understanding the exposure. Like, are people pasting in customer data? Pricing strategies? Deal notes? That's the stuff that keeps me up at night, not someone using AI to draft a blog post.

3

What does 'good' look like to you — and how far are you from that today?

Good, to me, looks like having visibility into what tools my team is actually using, with guardrails that don't kill productivity. So if someone's using Claude or ChatGPT for copy drafts or competitive research, I want to know that's happening, I want some basic data classification in place so proprietary stuff — pricing, unreleased product details, customer data — isn't getting pasted into a consumer-grade interface, and I want that enforced without me having to play AI police every week. Where are we today? Honestly, we're probably at a 4 out of 10. We have an acceptable use policy that went out in a company-wide email, and I think most people read it once and moved on. We don't have great visibility into what's actually flowing through third-party tools, and the IT and security teams are stretched thin trying to manage bigger fires. So the gap between what "good" looks like and where we are is real — it's just not loud enough yet to get prioritized budget.

4

What would change your perspective on this entirely?

Honestly, if I saw a well-documented case where a company our size — Series B, maybe 200-400 employees — actually had a material data breach traced directly to an employee using an unauthorized AI tool, and there was a clear causal chain, that would shift how seriously I treat this day-to-day. Right now it feels more like a compliance and legal concern than something I personally lose sleep over. The other thing that would move me is if a vendor could show me — not in a sales deck, but in actual implementation data — that their policy enforcement tooling meaningfully changed employee behavior rather than just creating audit logs nobody reads. Most of what I've seen is monitoring infrastructure, not behavior change.

5

What question are you not being asked that you wish someone would ask?

Honestly, the question I'd want someone to ask is: "How are you actually measuring the cost of doing nothing on Shadow AI?" Everyone's focused on the risk side — data leakage, compliance exposure — but nobody's quantifying what it costs when your team is using unsanctioned tools inefficiently, or worse, when you block them entirely and lose productivity ground to competitors who aren't being as cautious. It's a real tradeoff and I don't think most security conversations are structured to capture both sides of that equation.

"We have an acceptable use policy that went out in a company-wide email, and I think most people read it once and moved on. We don't have great visibility into what's actually flowing through third-party tools, and the IT and security teams are stretched thin trying to manage bigger fires. So the gap between what 'good' looks like and where we are is real — it's just not loud enough yet to get prioritized budget."
Language Patterns for Copy
"managed ambiguity""visibility into what's actually happening""it's just not loud enough yet to get prioritized budget""guardrails that don't kill productivity""monitoring infrastructure, not behavior change""cost of doing nothing on Shadow AI""4 out of 10""consumer-grade interface""stretched thin trying to manage bigger fires"
Methodology

How to interpret this report

What this is

Synthetic pre-research uses AI personas grounded in real buyer archetypes and (where available) Gather's interview corpus. It produces directional signal — hypotheses worth testing — not statistically valid measurements.

Statistical projection

Quantitative figures are projected from interview analyses using Bayesian scaling with a conservative ±35% margin of error. Treat as estimates, not census data.

Confidence scores

Reflect internal response consistency, not statistical power. A 90% confidence score means high AI coherence across interviews — not that 90% of real buyers would agree.

Recommended next step

Use this to build your screener, align on hypotheses, and brief stakeholders. Then run real AI-moderated interviews with Gather to validate findings against actual respondents.

Primary Research

Take these findings
from synthetic to real.

Your synthetic study identified the key signals. Now validate them with 150+ real respondents across 8 audience types — recruited, interviewed, and analyzed by Gather in 48–72 hours.

Validated interview guide built from your synthetic data
Real respondents matching your exact persona specs
AI-moderated interviews with qual depth + quant confidence
Board-ready report in 48–72 hours
Book a call with Gather →
Your Study
"How are enterprise security teams handling Shadow AI risk, unauthorized GenAI usage, data leakage, and policy enforcement in 2026?"
150
Respondents
8
Persona Types
48h
Turnaround
Gather Synthetic · synthetic.gatherhq.com · August 12, 2026
Run your own study →