The UAE has emerged as one of the world’s most active adopters of artificial intelligence. Research conducted by CPX and MarketsandMarkets highlights the scale of that adoption: in 2025, 59.4% of the UAE’s working-age population reported using AI tools in their daily work, the highest rate globally. Yet another figure reveals the visibility gap behind that progress: 33% of UAE organizations lack confidence in detecting unsanctioned AI deployments, commonly known as shadow AI.

As AI adoption accelerates, it becomes harder for organizations to route every tool, account and data flow through formal security review. The question is no longer whether an organization has an AI policy. It is whether the organization knows what its people are actually using.

When data leaves through a browser tab

Organizations around the world have already seen how easily sensitive information can find its way into externally hosted AI tools. Employees often turn to AI to solve immediate business problems, uploading documents, source code, customer information, or internal discussions without fully understanding where that data goes or how it may be used.

It is easy to dismiss this as an employee mistake. But that overlooks a more important reality. Someone had a problem. They found a tool that could solve it. They used it. There was no malicious intent, just a faster way to get work done.

That is precisely what makes shadow AI difficult to control. The risky action often looks identical to a productive one.

A chatbot quietly becomes part of an employee’s daily workflow. A coding assistant finds its way into the software development lifecycle. An AI capability embedded inside a familiar business application may not be visible to the security team as a distinct AI capability.

Unlike traditional shadow IT, AI does not simply store or move information. It can interpret that information, transform it, and generate new outputs from it.

Banning AI can make the problem worse

When organizations discover unsanctioned AI, the instinct is understandable: block the tool. But if employees are turning to it because the approved alternative is unavailable, too restrictive or simply not useful enough, blocking the tool does not remove the underlying need.

The employee may move to a personal account, find another service, use an AI feature embedded in software that security teams have not classified as an AI tool, or simply find a workaround.

The organization has not necessarily reduced AI risk. It may have reduced visibility into it.

Recent research points in the same direction. A 2026 Thomson Reuters Institute report found that 34% of professionals across industries reported using AI tools their organizations had not sanctioned. 

That is why I believe the more effective approach isnot simply to restrict the demand for AI. Organizations also need to manage the supply of trusted AI.

The sequence is straightforward:

  • Discover what people are actually using—not just what procurement has approved.
  • Classify those tools based on the data they access, the permissions they require, the decisions they influence and the risks they introduce.
  • Then offer governed alternatives that people genuinely want to use. If the secure option is also the useful option, employees are far less likely to look elsewhere.
  • Enforce stronger controls where the risk warrants them.
  • And measure continuously. AI usage will change as quickly as the technology itself.

This is not a one-time cleanup. It is an operating model.

The consumer is now part of the security perimeter

Our work with MarketsandMarkets on Operationalizing AI Security in Business led us to a broader conclusion: AI risk cannot be understood through technology alone. It has to be understood through how AI is being used across the enterprise.

We identify three core user personas: AI Consumers, AI Deployers and Model Developers.

The Consumer is particularly important because this is where adoption is expanding fastest, and where security controls can be least visible. Consumers interact with copilots, chat interfaces and coding tools. Their risks include data leakage, over-reliance on outputs and shadow AI. 

That makes the employee’s AI interaction a security boundary in its own right.

But treating every consumer the same would also be a mistake. Someone drafting an internal email with AI does not present the same exposure as an engineer using an AI coding assistant with access to proprietary repositories.

The answer, therefore, is not more policy. It is more context. Security controls should reflect what the person is doing, what data they can access, what AI capability they are using and what could happen if that interaction goes wrong.

Make secure AI the easier choice

For the UAE, this matters because AI is already becoming part of government services, financial institutions, healthcare, telecommunications and everyday enterprise work.

Trying to put AI back behind a wall is neither realistic nor particularly useful. The organizations that navigate this well will provide AI tools employees want to use, make the boundaries clear, build visibility into actual usage, and apply controls where they matter most.

The goal is not only to find unauthorized tools and shut them down. It is to make people less interested in using unauthorized tools in the first place. That means moving from policing AI usage to designing an environment where secure adoption is the natural choice.

The most dangerous AI in your organization may not be the one you deployed. It may be the one nobody told you about.