Skip to content

Leadership1 publisher3 min readPublished

Unsanctioned AI use outruns monitoring by better than two to one in Mindgard's survey

A Microsoft education partner argues the evaluation window is itself the exposure window, citing a survey in which most security professionals knew or suspected unapproved AI use. The test he proposes is one conversation with the CIO or CISO and four document requests.

The Board Room · Leadership desk

Illustration accompanying Unsanctioned AI use outruns monitoring by better than two to one in Mindgard's survey

What happened

  • A 2025 Mindgard survey of more than 500 cybersecurity professionals found 56% knew employees were using AI without approval, and another 22% suspected it.
  • Husein Sharaf of Cloudforce wrote that nearly every institution he talks to describes its AI governance posture the same way: "It's a work in progress."
  • He proposes asking the CIO or CISO which AI services staff use most, then requesting four items per service: the terms, the training and retention provisions, the access controls, and the usage records.
  • Blocking public AI sites cuts visible usage from managed devices while leaving personal smartphones, home computers, browser extensions and off-network accounts available.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure On Sharaf's account the exposure lasts exactly as long as the evaluation does, and it concentrates in the highest-value material, because staff reach for AI on the work that takes the most thought.
  • decision The choice in front of a board this quarter is sequencing: provision sanctioned access while the review runs, or accept the review period as a period of unlogged use.
  • constraint A network block leaves security teams with less to measure the remaining usage by, so it also weakens the evidence the eventual procurement decision would rest on.
  • contradiction The case for buying enterprise AI terms is made here by a firm that sells them, and the one independent number under it comes from a survey reported secondhand.

Add the two halves of Mindgard's finding together and 78% of respondents had either evidence or a suspicion that their own staff were using AI without approval [1]. Set that against the share whose organisations actively monitored usage, and reported suspicion runs about two and a half times ahead of measurement [2]. Sharaf's column does not describe how the sample was drawn, so the figures describe that survey's respondents and nothing wider [1].

Husein Sharaf wrote that staff use public tools to draft grant proposals, summarize constituent correspondence, review procurement language and sharpen negotiation memos [4]. The same habit reaches a curriculum refined over several years or research data held back ahead of publication [5]. The material at risk, in other words, is the material people think hardest about. Much of that activity sits outside the institution's contracts, identity controls and audit logs [14].

Public and consumer AI services can give providers broad rights to use prompts or outputs, depending on the product, the account type and the settings, while enterprise agreements commonly provide stronger confidentiality and data-use protections [6]. An employee working from a personal account may therefore place institutional information under terms leadership never reviewed [18]. A written policy leaves that gap open: it "cannot provide the tool employees need at 4:45 p.m., when a council briefing, grant submission or board packet is due," Sharaf wrote [16].

Sharaf leads Cloudforce, a firm in the DC metro area recently named Microsoft's global Education Partner of the Year [7]. What he recommends is broad access to approved AI services inside an environment covered by enterprise terms, with identity management, usage review and documented provider handling of prompts and retained data [8]. The commercial interest is plain, and the diagnostic is separable from it: anything that comes back missing from the four requests identifies a specific governance gap [10].

Blocking changes what security teams can see before it changes what staff do. Usage shifts into places where those teams have fewer logs and fewer practical controls, according to Sharaf [12]. He keeps a role for bans on specific high-risk services, and says a ban works best when employees already have a useful, approved option [13].

Provisioning early carries its own cost: the institution signs enterprise terms before the review that was meant to test them, and standardises on a provider picked against a deadline. Sharaf's claim is that the alternative cost is already being paid, because an institution without approved, enterprise-wide AI access "remains exposed while its evaluation continues" [15]. Of the staff doing it, he wrote: "They are doing their jobs with the tools available to them. Leadership decides which tools are available." [5]

What to watch

  • Whether Mindgard publishes the sampling method behind the 56/22/32 split, or a later wave showing monitoring catching up.
  • Whether consumer AI providers change default training and retention terms on personal accounts, which would narrow the gap between personal and enterprise use.
  • Whether any institution that runs the four-document request publishes which of the four came back missing.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories