A WatchGuard survey of 684 SMB employees across the US, UK, Germany, France and Spain found 64% use unauthorized AI tools at work, and fewer than 3 in 10 employers can accurately track what software staff actually run.
Why It Matters
This is not a US problem. Germany, France and Spain were in the same sample, and nearly 40% of the companies surveyed admitted they have no full visibility into which apps their own staff use. If employees are pasting client data into AI tools nobody vetted, there is no audit trail for exactly the kind of processing the EU AI Act's transparency duties and GDPR expect you to account for.
What To Do About It
Pull a week of firewall or DNS logs and check for traffic to AI tool domains your team was never issued (ChatGPT, Gemini, DeepSeek, or a Copilot Studio agent nobody registered). If you cannot produce that list in fifteen minutes, the visibility gap is the finding, not whatever tool turns up.
Sources
Related Signals
Microsoft cut AI agent security out of standard Defender licenses on 1 July.
30 Jul 2026CoreView's July 2026 governance report finds two-thirds of organizations have delayed or cancelled Microsoft Copilot rollouts over fear it will surface overshared SharePoint files.
29 Jul 2026A Cloud Security Alliance survey found 58% of executives suffered an AI-agent security incident in the past year, while only 34% apply the same controls to agents as to human staff.
27 Jul 2026