Shadow AI and AI attacks: Two sides of enterprise risk
- Last updated 08/11/2026
-
Shadow AI and AI-powered attacks are usually treated as two separate security problems, but they're really the same risk, approached from opposite directions. Security teams are racing to harden their perimeters against attackers armed with powerful AI tools, while a quieter risk grows inside those same perimeters: employees feeding company data into unsanctioned AI tools that IT never approved. Most don't mean to create risk, but the effect is the same: sensitive data leaving the organization with no firewall ever breached.
The reality is that these aren’t two separate problems. They’re like the yin and yang: an inside-out threat and an outside-in threat, fueled by the same AI technologies and converging on the same target: your data. Both are accelerating. Both must be addressed together.
Key takeaways
- Shadow AI adoption grew nearly 1,000% year-over-year in 2025, with employee-installed tools like ChatGPT and Gemini running on enterprise devices as often as IT-sanctioned ones, according to Omnissa State of the Digital Workspace 2026 Report.
- AI-generated phishing now converts at 4.5 times the rate of traditional phishing, and phishing volume has risen over 1,000% since ChatGPT's public launch, according to the 2025 Microsoft Digital Defense Report.
- Both threats share a root cause (widespread AI adoption) and a target (your data) and treating them as separate problems leaves half the exposure unaddressed.
- A single platform and telemetry layer—app inventory, sensors and scripts, conditional access, and automated response—can close both gaps at once.
The inside-out threat: Shadow AI
Shadow AI is what happens when productivity outruns governance. Employees rarely set out to create risk with ill intentions — they just want faster answers! So, they paste a contract into ChatGPT or ask a browser copilot to summarize a spreadsheet of customer data. The data leaves the organization without a single firewall being breached. To wit:
- Usage of AI assistant apps across enterprise devices grew nearly 1,000% year-over-year in 2025. While Microsoft Copilot was deployed on 97.5% of enterprise-managed mobile devices, employee-installed alternatives were just as prevalent: ChatGPT on 91% of enterprise iOS systems and Gemini on 61% of enterprise Android devices. This showcases a clear gap between what IT sanctions and what employees actually use, per the Omnissa State of Digital Workspace 2026 Report.
- 57% of enterprise employees have entered confidential company data—like customer records, financials, and internal strategy—into public AI tools like ChatGPT, Gemini, and Copilot, according to a survey by TELUS Digital.
- Breaches involving shadow AI cost organizations $4.63 million on average—$670,000 more than other breaches, according to IBM’s Cost of a Data Breach Report 2025. Additionally, only 37% of organizations have policies in place to manage or detect shadow AI use.
The outside-in threat: AI-powered attacks
While employees are unintentionally opening doors, attackers are using the same generative AI to kick them down faster than ever by writing more convincing phishing lures, reverse-engineering vulnerabilities, and automating intrusions at a scale human analysts can’t match.
- AI-generated phishing emails now achieve a 54% click-through rate—4.5 times higher than traditional phishing attempts, according to the 2025 Microsoft Digital Defense Report.
- Phishing volume rose 1,265%, with credential phishing up 967%, in the year following ChatGPT’s public launch—the first clear signal of AI-fueled cybercrime at scale, the 2023 State of Phishing Report from SlashNext found.
- 86% of organizations are already increasing their own use of AI in security operations just to keep pace, according to Deep Instinct’s 6th edition of Voice of SecOps Report, and half of critical infrastructure organizations report having faced an AI-powered attack in the past year.
Two sides, one coin
Shadow AI and AI-powered attacks look like opposite problems—one originates inside the organization, one outside. But they share a root cause: widespread AI adoption on both sides of the firewall. And they share a target: the same sensitive data.
A well-meaning employee’s shadow AI habit can hand attackers exactly the reconnaissance they need for a more convincing AI-generated phishing lure. Defend only the perimeter, and the data still walks out the front door. Defend only the endpoint from misuse, and a faster attacker still gets in. Treating either threat in isolation leaves half the exposure unaddressed.
How Omnissa protects customers against both
Omnissa’s AI-driven digital work platform allows customers the insights and automation to close both gaps at once—through the same fleet-wide telemetry and control that surfaced these very shadow AI trends in Omnissa’s own 2026 research.
Against the inside-out threat
The Omnissa Platform addresses shadow AI-related data leakage through a few connected capabilities:
- Inventory both sanctioned and unsanctioned apps: Omnissa Workspace ONE Unified Endpoint Management (UEM) discovers both sanctioned and unsanctioned (shadow AI) apps running across device fleets, including mobile devices and Windows and macOS desktops, as well as virtual desktops. It also provides allow/deny-listing and open-in controls that keep sensitive data out of unsanctioned apps and boundaries.
- Find non-app binary AI services running: Omnissa Workspace ONE “sensors” run shell scripts on specified managed devices to detect AI tools that do not install traditional application binaries, such as Python processes (like allama serve, llama.cpp), Node.js servers, CLI binaries, and background daemons. These sensors then return structured values to Omnissa Intelligence.
- Observability of devices with unsanctioned AI apps and services: Omnissa Intelligence turns device, user, app, and other AI tools telemetry into fleet-wide visibility, the same observability that powers Omnissa’s own State of Digital Workspace research.
- Securely access only sanctioned apps with zero trust conditional access: Omnissa Workspace ONE Intelligent Hub and Omnissa Access gives employees a single, password-less catalog of approved apps, including IT-sanctioned AI apps, so choosing the sanctioned tool is easier than going around IT.
- Enforcing compliance with workflow orchestration: Omnissa Freestyle Orchestrator enables low code/no code automation and orchestration of simple to complex tasks that require specific sequencing. Freestyle can automatically tag unsanctioned devices identified by UEM and/or reported by Intelligence and can then take actions to enforce responses in support of IT policy. For example, email alerts can be sent to users who are out of compliance with instructions on how to get back into compliance by removing unsanctioned apps. Ultimately enforcement actions can be automated, including ultimately removing device management profiles and ending network access.
- Secure AI apps and agents within virtual desktops: Omnissa Horizon is an ideal security container within which to allow AI apps to run. Within a Horizon virtual desktop, strict security controls can be enforced. For example, locally stored data may be restricted from uploading to, or pasting into, an AI app. Horizon provides rich data protection, effectively containerizing AI usage. For regulated industries accessing regulated data in virtual apps such as healthcare information systems or proprietary financial applications, data can be restricted from leaving the applications and fed to an AI. Lastly, Horizon is great security for AI agents as well, as the agent can only run as the user, with only the network, application, and data access that the user has, but coupled with the security policies and authentication requirements of the user.
- Extend security at the network layer with per-app or device virtual private network (VPN) services: Omnissa Tunnel provides applications per-app tunnelling to only approved AI domains and blocks connections to unapproved domains. All AI traffic can be routed through an organization’s security tools for deeper inspection.
- Secure web access to public AI services with complete data protection by requiring enterprise browser: Omnissa Secure Access Suite (OSAS) delivers secure, browser-based access to enterprise apps. Users can launch OSAS from Intelligent Hub with the only connections allowed by policy being to IT-designated AI sites with all other AI sites being blocked. OSAS enables advanced data protection in browser sessions including upload and copy/paste controls to AI web sites, eliminating data leakage.
Against the outside-in threat
The Omnissa Platform can help IT teams more quickly respond to external threats with rich enterprise controls and automated patch workflow.
- Desktop OS and app updates at AI speed and scale: Omnissa Workspace ONE provides cloud-native patching across operating systems and apps with the ability to get granular by deploying only specific patches. It also includes an Enterprise App Repository with over 13,000 application packages vetted and ready-to-deploy if a critical app vulnerability is announced. In addition, new Omnissa Vulnerability Defense provides vulnerability assessment leveraging NVD, EUVD and third-party providers like CrowdStrike to identify vulnerabilities impacting your device fleet. Vulnerable devices can be remediated with turnkey automated workflows from Workspace ONE UEM for apps, OS patches, and configurations.
- Protect the mobile endpoint: Omnissa Workspace ONE Mobile Threat Defense detects device, network, and app-based attacks—including AI-generated phishing and malware—and feeds a real-time risk score into Access, so a compromised device or risky session is automatically restricted before attackers reach company data.
- Containerize critical applications with regulated or confidential data within virtual desktops: Omnissa Horizon keeps sensitive apps and data inside managed virtual sessions rather than on the endpoint itself, limiting what an attacker can reach even after an initial compromise. For regulated industries, Horizon keeps the restricted or proprietary data off the physical end user devices and contained where the application data resides.
One platform, one set of telemetry, both threat vectors covered.
The bottom line
AI isn’t waiting for security and data protections to catch up on either side of the firewall. Organizations that treat shadow AI and AI-powered attacks as one connected risk will be the ones positioned to use AI safely.
And Omnissa customers have a broad set of tools to address both external and internal AI-powered threats all while empowering their workforces to make transformative gains leveraging modern AI productivity.