Back to blog
Discover·Aug 4, 2026·5 min read

Your company's biggest AI power user isn't in engineering

On a Tuesday afternoon, a marketing manager exports your entire customer list — names, emails, deal sizes — and pastes it into ChatGPT to "clean up the formatting." It takes four minutes. No one signs off on it. No ticket is filed. That same afternoon, three floors up, your security team is busy locking down the developers' access to GitHub Copilot.

One of those two things is the real problem. It isn't the one being watched.

We model shadow AI on the people we understand

When security teams picture shadow AI, they picture themselves: technical people using technical tools. Developers pulling in Copilot. Engineers wiring an API key into a side project. So that's where the controls go — endpoint policies on dev machines, allowlists for known AI developer tools, a Slack reminder about approved models.

It's a reasonable instinct. It's also aimed at the wrong door.

Developers are, generally, the most security-aware people in the building. They know what a data processing agreement is. They've thought about where the data goes. The risk from an engineer using an unapproved model is real, but it's bounded — and it's visible, because it runs through systems you already monitor.

The volume, and the exposure, is somewhere else entirely.

The real power users

Rank AI usage not by who's technical, but by the three things that actually drive risk: how much they use it, how sensitive the data is, and how invisible it is to you. Do that, and a very different list appears.

  • Marketing runs customer lists, segment exports and campaign data through AI to draft and analyse — personal accounts, in a browser, all day.
  • Sales pastes CRM exports, deal notes and pricing into a chatbot to write follow-ups and summarise calls.
  • Legal drops contracts, NDAs and the facts of a live matter into a model to "just summarise this."
  • The executive team may be the single highest-stakes user — board decks, M&A memos, strategy — and the least monitored in the company.
  • HR processes employee records, performance notes and compensation: some of the most sensitive personal data you hold.
  • Finance runs forecasts and unpublished numbers through whatever tool is fastest.

None of these people are doing anything malicious. They're doing what a good employee does — finding the fastest way to a good result. But not one of them shows up on a scan of your engineering stack, because they never touched it. They opened a browser tab.

Why this quietly breaks your controls

The tooling most organisations rely on assumes a technical adversary. Network monitoring and EDR are tuned to flag connections to AI developer tools. Policies are written for people who understand the word "sub-processor."

Consumer AI used by a non-technical employee slips underneath all of it. It's a logged-in personal account, over HTTPS, in a normal browser, doing something that looks like normal work. There's no install to catch, no API key to find, no procurement trail to audit. And the higher up the org chart the user sits, the less likely anyone is watching at all.

So you can run a locked-down engineering environment and still leak your most sensitive material — customer records, contracts, board decks — every single day, through the people you weren't watching.

You can't govern what you can't see — and you're looking in the wrong place

Here's the part that matters for anyone building an AI governance programme: discovery has to come before policy, and it has to cover everyone. A framework that starts from "the tools IT already knows about" is describing a company that doesn't exist.

In practice:

  1. Discover actual usage across every department, not just the technical ones — before you decide what to do about it.
  2. Classify by data sensitivity, not seniority. A marketer handling the customer database is a higher-risk user than a developer using AI to refactor open-source code.
  3. Give people safe alternatives. Banning the tools doesn't remove the need that drove people to them — it pushes the usage further out of sight.
  4. Monitor continuously. New tools appear weekly; a one-time audit is out of date the month after you run it.

Where Grasp fits

This is what Grasp's Discover is built for: surface every AI tool actually in use across your organisation — regardless of who's using it or which department they sit in — and map each one to the risk it carries. From there you can classify, set policy, and produce the audit trail the EU AI Act and ISO 27001 will ask you for.

You can't secure a surface you can't see. And for most companies, the largest part of that surface has never been anywhere near engineering.

Want to know who your real power users are? Book a demo and we'll run a live discovery scan — most teams are surprised by what comes up.

FAQ

Who are the biggest shadow-AI users in a company?

Usually non-technical roles that handle sensitive data at volume — marketing, sales, legal, HR, finance and the executive team — using consumer AI tools like ChatGPT through personal accounts, outside IT's visibility.

Why don't security controls catch them?

Most monitoring is tuned to technical AI tools and developer workflows. Consumer AI used in a browser, on a personal login, by a non-technical employee leaves no install, API key or procurement trail to detect.

What should we do first?

Discovery. Map where AI is actually being used across every department before writing policy, then classify by data sensitivity and offer safe, approved alternatives.