Artificial Intelligence | News | Insights | AiThority

How Enterprises Are Closing the Gap Between AI Adoption and AI Governance

For many organizations, the benefits of AI tools is being dwarfed by the risks, as adoption outpaces security capabilities.

According to a new study, 77% of organizations report that AI adoption is already outpacing their governance capabilities, and the same survey found an average of 54 agent-related security incidents in the past year.

Shadow AI is already widespread, and only one in ten C-level tech executives say they’re ready for the surge in AI agent deployment expected in the coming year. Security teams are looking for ways to close this gap between adoption and governance.

The natural place to start asserting AI governance is the network, because both sanctioned and shadow employee AI traffic has to pass through it. That’s the idea behind Check Point’s AI Network Firewall, which adds AI traffic monitoring onto firewall infrastructure that’s already in place, rather than requiring security teams to add another system. It’s a new type of firewall that’s built to protect AI systems from AI-specific threats, in contrast to familiar AI-powered firewalls which use AI to catch conventional threats.

But that’s not the only option. Governance can be applied in a number of other places to rein in shadow AI and put security teams back in control. Some approaches add governance at the platform level, while others monitor the person and/or agent behind each action. It’s the difference between tracking the tools, the user, and the traffic.

Also Read: AiThority Interview with Gou Rao, co-founder and CEO at NeuBird AI

Why Governance Keeps Falling Behind Adoption

Corporate IT governance frameworks are based on the assumption that every tool in use is visible to IT, has been approved by procurement, and is being monitored according to documented policy. AI breaks all three of those assumptions at once.

Employees who are eager to take advantage of AI-powered productivity are adopting AI tools and apps without waiting for evaluation, let alone permission, and using shadow AI through personal accounts that lie outside the IT team’s purview. New AI features appear inside SaaS platforms that had already been approved, enabling use without procurement’s knowledge or consent.

This is why 77% of CIOs and CTOs have lost control of their organizations’ AI usage. It’s every time an employee adopts a tool before procurement reviews it, or tries out the new AI feature that popped up in their workplace platform, or logs into an AI app using their personal account because they’re under time pressure and can’t wait for IT approval. Multiply that across an entire organization, and it’s clear why governance can’t keep up.

Governing the Platform Itself: Microsoft’s Approach

Microsoft is tackling the problem with a platform-level fix that spans two layers. Its Purview and Defender for Cloud Apps tools give security teams broader discovery and governance over third-party AI tools generally, the layer most relevant to the shadow AI problem itself.

Separately, Copilot has its own admin controls and usage analytics, enabling security teams to monitor and restrict how Copilot specifically is used across Microsoft 365.

Related Posts
1 of 22,396

It’s a good solution for organizations that need visibility into third-party AI tools generally. But Copilot’s own admin controls are narrower, only governing Copilot itself, so they don’t help with AI usage happening through other tools, even ones inside the Microsoft ecosystem.

Governing the Agent Itself: Zenity’s Approach

Zenity addresses AI governance from an agent-based perspective, making it one of the best tools for discovering shadow AI use across an enterprise.

It monitors environments where employees build and operate agents, including cloud AI platforms, SaaS platforms like Copilot and ChatGPT, and individual endpoints. Its AI Security Posture Management inventories agents and maps their owners, configurations, permissions, and connections at build time, while its AI Detection and Response monitors access and runtime actions once agents are live.

The advantage to this approach is that Zenity catches AI agents that employees build for themselves, not just third-party AI apps and tools. But the disadvantage is that it’s limited to AI agents and doesn’t notice other unsanctioned AI use.

Governing the Network the Traffic Already Crosses: Check Point’s Approach

Check Point’s AI Network Firewall uses a different strategy. It discovers, monitors, and controls employee AI traffic through the firewall infrastructure that enterprises already run, without new hardware or consoles. Its prompt-inspection capabilities are built on technology from Lakera, the AI security startup Check Point acquired in 2025.

By inspecting prompts and uploads for both shadow and sanctioned AI in real time, Check Point’s AI firewall actively prevents sensitive company data from leaking into public AI tools, rather than detecting it after the fact.

This network-level approach to AI governance is broader than Microsoft’s platform-level and Zenity’s agent-level methods. It doesn’t depend on which platform an employee uses, and it’s not restricted to agent frameworks. It manages all the AI traffic that crosses the network, no matter where it originated or where it’s heading.

Governance can occur in multiple locations

The idea that over three-quarters of organizations can’t govern their AI usage highlights the need for shadow AI security solutions. The best way to keep shadow AI under control depends on an organization’s operating reality, whether that’s employees on Microsoft platforms, unregulated agents, or a need for broad network protection. The strongest AI security posture will keep more than one tactic in mind.

Also Read: ​​AI and The Future of Work: Artificial Intelligence Is Expanding Organizational Intelligence Beyond Human Limits

[To share your insights with us, please write to psen@itechseries.com]

Comments are closed.