Published on June 25, 2026 by David Marshall on vmblog.
Neon Cyber published Quantifying Shadow AI Risk in the Browser, a research report based on a survey of more than 200 U.S. knowledge workers.
The central finding rejects the most common path forward in enterprise AI governance: that an AI policy alone can reduce enterprise risk. Neon found that 63% of survey respondents reported having a clear AI policy that they understood. However, of that 63%, nearly 50% knowingly violated it by using unapproved AI tools anyway — because most organizations have no visibility into what their workforce is doing in the browser, and no controls that operate where the risk is actually created.
...
“It’s not surprising to us how many workers rely on AI now. The research shows that blocking access outright is not a viable answer,” stated Mark St. John, COO and Co-Founder of Neon Cyber. “This isn’t surprising given the proliferation of shadow IT. Shadow AI is just a new wave of that. The organizations that are actually closing the enforcement gap are doing it with controls that operate where work actually happens, without slowing down the employees who depend on these tools.”
Read the full story on vmblog.