No items found.
  • Platform
  • Pricing
  • About
  • Resource Hub
  • News
  • Blog
  • Help
  • Login
  • Book Now

Solutions

Explore everything you need to protect your workforce.

Ai security

Shadow SaaS
Data Leakage
Real-Time User Guidance
Phishing Protection

Browser security

Browser Observability
Authentication Governance
Back to Blog
Security

The Leaders Most Confident in Their AI Visibility Are the Ones Most Likely to Be Wrong

In a recent survey, Neon Cyber found most security leaders overestimate their AI visibility. 69.8% of security leaders claim event-level AI visibility. But 75% also believe employees use AI tools anonymously — always, often, or sometimes.

Neon Cyber
Published on: 
Sep 21, 2026
On This Page
TOC Element
Share:

28.4% of security leaders hold two beliefs at once that can't both be true: strong visibility into what data is going into AI tools, and frequent anonymous AI use they can't account for.

‍

Ask a security leader how confident they are in their AI visibility, and most will give you a number that sounds reassuring. Neon Cyber asked nearly 170 IT and security leaders, and 69.8% of them claim event-level visibility into AI tool use across their enterprises.

But that confidence and reality aren't the same thing.

What does event-level visibility into AI use mean?

Event-level visibility refers to the ability to see and log specific user actions inside an AI tool — which employee used which tool, when, and what they submitted — rather than just knowing that traffic to an AI application domain occurred.

69.8% of surveyed security leaders say they have this kind of visibility into the AI tools employees use. That's a majority claiming a fairly specific, technically demanding capability.

Do security leaders really have event-level visibility into AI use?

Among security leaders who strongly claim event-level visibility into AI tool use, 75% also believe employees use AI tools anonymously — always, often, or sometimes. But among the more restrictive group who strongly claim visibility into the data going into AI tools, that number climbs to 80%.

Across the full sample, nearly a third of surveyed leaders – 28.4% – were confident in their visibility into data flowing into AI tools yet also readily acknowledged that they believe there was rampant shadow AI use.

That's more than a quarter of the sample reporting confident visibility and an anonymous-use gap they can't account for, as though both could be true at the same time.

We’ve seen it: your internal dashboard with a green checkmark next to every sanctioned AI login, refreshed in real time. But two tabs over, in their browser window, an employee has a personal AI account open under a private email address — invisible to your dashboard, because nothing about that tab ever touched a corporate identity.

What most leaders describe as “event-level visibility into AI use” is visibility into sanctioned, authenticated AI use: the approved AI tool that your employees log into via SSO. Anonymous sessions carry no identity, so identity-based tooling has no event to record for them. A leader can have excellent visibility into AI activity running through their identity management tools or within approved AI apps, but have near-zero visibility into everything else.

How big is the anonymous-use blind spot?

Smaller than security leaders assume, but still real. Workers themselves report anonymous or not-logged-in AI use at 54.6%. But security leaders estimate it at 73.4%. That's an 18.8-point difference, and it tells us there's real anxiety around shadow AI use.

The difference in these figures also points to security teams operating on the assumption that three out of four AI sessions are invisible. Without clear evidence of shadow AI use, security responds with restriction or working to create never-ending block-lists to try to lock down application use. That's the kind of overcorrection that frustrates workers and, ultimately, leads them to expand shadow AI use in the first place.

The fix isn't a better guess. It's removing the need to guess — instrumenting the browser session directly, so "how much anonymous use do we actually have" stops being a number security estimates and starts being one it can look up.

What this means: Guessing high doesn't just create anxiety — it creates more shadow AI. Blanket restrictions push workers toward the exact anonymous, unsanctioned use they were meant to prevent.

Check your logs, not just vibes

Want to find out just how much visibility you have into AI use?

One way to check is to find out if your monitoring covers unauthenticated and personal-account sessions, or if you’re only logging sessions tied to a company identity. If it's the latter, consider that you may be seeing less than 50% of the AI use across your organization.

Where Neon Cyber fits

This isn't a case for throwing out identity-based tooling — SSO and identity governance do exactly what they were built to do, and they do it well for the sanctioned activity they can see. So how do you find accounts that sit outside corporate identities: personal accounts, incognito sessions, anonymous tool use, etc.? You need visibility and control that lives in the browser session itself to see the prompt and the paste regardless of which account submitted them.

If you want the fuller mechanism behind why identity-based visibility stops at the authenticated edge, we've written about that in "Why Identity Governance Can't See Shadow AI" and "Authentication Is a Moment. AI Risk Is Continuous."

‍

FAQs

How do I know if employees are using AI tools without IT approval?

Start reviewing the tools you already have in your IT and security stack. Pull secure web gateway or DNS logs and see if you can identify known AI domains that are unsanctioned. This will give you destination-only visibility, so you won’t know if an employee is just checking that site out or if they’re logging in, but this gives you some sense of the scope of unapproved AI use.

You can also check CASB or SSO logs for OAuth grants into third-party AI applications, audit browser extensions across managed devices, and scan expense reports for AI tool subscriptions that employees or departments are buying or getting reimbursed.

You could also run an anonymous, non-punitive employee survey. If you want to take this route and compare it with our research, we asked knowledge workers this question:

When you use AI tools for work, how often are you logged in with the following?
A) A corporate (work) account
B) A personal account
C) Not logged in / anonymous

None of these will give you full visibility, but they will help you piece together some of the risk around shadow AI for your enterprise.

If we require SSO across every browser tab, does that eliminate the blind spot?

It narrows it, but doesn't eliminate it. Forced SSO reduces anonymous use on managed devices, but it doesn't cover personal devices, browsers outside MDM enrollment, or an employee who logs out of a work account mid-session to open a personal one. Treat "requires SSO" as a control that shrinks exposure, not one that closes it.

How often should security teams re-audit their AI visibility claims?

Given how quickly workforce AI adoption is changing, a quarterly check against actual log data is a reasonable baseline — specifically asking whether logs show content or only destinations, and whether unauthenticated sessions are covered at all. Neon Cyber's report includes a five-question quiz (request the full PDF for the quiz) built for exactly this kind of quarterly check.

Protect the people that power your business

Subscribe to the Neon Glow-Up

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Follow Us

Company

Platform
About us
News
Blog

Platform

Browser Observability for SecOps & GRC
AI & Shadow SaaS Visibility and Control
AI Data Leakage & Insider Risk
AI Guardrails & Real-time User Guidance
AI-Powered Phishing & Social Engineering Defense
Authentication & Identity Hygiene
© {{year}} Copyright. All Rights Reserved.
Privacy Policy
Terms and Conditions