Security Teams Have the Worst Shadow AI Problem in the Building
September 28, 2026
Jillian, CMO— AI-assisted and reviewed prior to publication.

Security professionals use unapproved AI tools more than almost anyone else in the building, and that habit is starting to work against them. It signals to employers that the people responsible for AI governance cannot yet govern their own AI use, which undercuts the very credibility that gets security staff promoted, trusted with bigger programs, or hired into AI-adjacent roles.
Why are security professionals the biggest shadow AI users?
The honest answer is speed and access. Security staff have the technical comfort and system permissions to adopt new tools fast, and they feel the workload pressure most acutely, so they reach for whatever gets a task done. A late-2025 report from cyber risk monitoring vendor UpGuard found that more than 80% of workers, including nearly 90% of security professionals, use unapproved AI tools in their jobs, and that security leaders were more likely than the average employee to report using unapproved tools and far more likely to say they did so regularly.
That is not an isolated finding. A separate survey of more than 500 practitioners at RSA Conference and InfoSecurity Europe in 2025 found that security professionals using generative AI tools without approval, a trend known as Shadow AI, is a growing and often overlooked risk. The people whose job is to reduce unmanaged risk in the enterprise are, by their own admission, a meaningful source of it.
What does this cost a security career, specifically?
It costs trust, and trust is the currency that determines who gets handed AI governance work versus who gets managed more closely. An employer who discovers that a security analyst has been running incident data through a personal AI account has no way to know what else that analyst has exposed, and no paper trail to show a regulator or auditor that the decision was ever reviewed.
That absence of a paper trail matters more than the tool use itself. Analysts at the Cloud Security Alliance point out that Gartner predicts that by 2030, more than 40% of companies will fall foul of incidents caused by shadow AI, and regulatory violations from tools you never approved are still your regulatory violations. If that liability traces back to your account, your name is the one attached to the incident report, not just your employer's.
The gap between using AI and being able to prove you use it responsibly
Plenty of security professionals can talk fluently about prompting a model for faster log triage or drafting a report. Far fewer can explain, in terms an auditor or a hiring manager would accept, how that use was scoped, logged, and reviewed. That second skill, not the first, is what separates someone who dabbles in AI from someone an organization trusts to own AI risk.
The NIST AI Risk Management Framework draws this line explicitly through its Govern function, which NIST describes as the function that is designed to be a cross-cutting function to inform and be infused throughout the other three functions of mapping, measuring, and managing AI risk. It sits above the mechanics of using a tool and asks a different question: who is accountable, what is logged, and how does the organization know if something went wrong. Security professionals who can answer that question for their own AI use are the ones employers hand bigger AI programs to.
ISC2's 2025 Cybersecurity Workforce Study, based on responses from more than 16,000 practitioners, found that AI-related skill shortages now outrank every other technical gap, with governance close behind. Infosecurity Magazine's coverage of the study reported that AI topped the list of skill shortages at 41%, followed by cloud security at 36%, risk assessment at 29%, and application security at 28%, with governance, risk and compliance close behind at 27%. Read together, those numbers describe a workforce that has adopted AI faster than it has learned to govern it, and security professionals are living that gap personally every time they open a chat window without asking first.
Turning a quiet habit into a documented skill
You do not fix this by pretending you have never used an unsanctioned tool. You fix it by building the governance vocabulary and process discipline that makes your AI use defensible, and then making that skill visible on paper. A few things separate someone who has done this from someone who has not:
- They can name the approval, logging, and review steps their organization requires before an AI tool touches sensitive data, not just the productivity gain the tool provides.
- They can point to a credential or coursework that covers AI risk frameworks, not just a list of tools they have tried.
- They document their own AI-assisted work the way they would document any other control, with a record of what was reviewed and by whom.
Building that record is exactly what a credential like the ISACA AAISM certification is designed to prove. It is built around the governance, risk, and oversight work that separates AI adoption from AI accountability, which is the distinction employers are now screening for when they promote from within a security team. If you are weighing which certification actually maps to the governance skills gap your organization is worried about, the curriculum overview and FAQ in the resources section is a reasonable place to compare options before committing time to one path.
What employers are actually asking in interviews now
Hiring managers have stopped asking whether candidates use AI tools, because the answer is almost always yes. What they ask now is how you would govern AI use across a team, what you would do when someone routes sensitive data through an unapproved tool, and how you would prove to an auditor that your organization's AI use is under control.
Those questions reward people who have studied AI governance formally, not people who have simply used more tools than their peers. ISC2's own read on this shift is direct: the organization's leadership noted that many cybersecurity professionals see AI as an opportunity for career advancement, using AI tools to automate tasks while investing time to learn more and demonstrate their expertise in using and securing AI systems. Demonstrating expertise is the operative phrase. Nobody demonstrates a skill by keeping it off the record.
A realistic starting point
You do not need to overhaul your entire AI practice in a week. Start by mapping which AI tools you currently use for work, which of them your employer has actually approved, and where the gap sits. That mapping exercise mirrors the same discipline the NIST framework asks of entire organizations, just scaled down to one person's workflow, and it is the kind of practical exercise you can build into a broader study plan.
If you want a study plan built around AI governance rather than just AI tool use, you can start training whenever you are ready. The point is not to memorize a framework for an exam and set it aside. It is to walk into your next performance review or job interview able to describe your AI use the same way you would describe any other control you own, with a clear account of what you did, why you did it, and how you can prove it held up.
The shift underway in security hiring is not really about AI at all. It is about accountability catching up to adoption, and the professionals who get ahead of that shift are the ones who can show their work.