O
OOMeta
← Back to Insights

August 7, 2026 · 7 min read

Okta Survey: Shadow AI
Outpaces Governance

Okta Survey: Shadow AI Outpaces Governance

Key Definitions

Shadow AI AI tools and agents that employees use without IT or security approval, often through personal accounts. Unmanaged by the enterprise, they bypass existing security and governance boundaries, creating data-leak and compliance risk.

Non-Human Identity Software-based entities such as AI agents and service accounts that can authenticate and execute actions autonomously. They need their own identity lifecycle and least-privilege management rather than reusing human-centric controls.

Software used to be deterministic, doing what it was told predictably and transparently. Now, anyone can spin up an AI agent, agents can spawn more agents, and each one connects across apps, APIs, SaaS tools, and data systems. The result is thousands of new black-box entities operating at machine speed, often with privileged access and frequently outside human-centric security controls. Okta's 2026 survey exposes a dangerous disconnect between executive confidence and how employees actually use AI.

Methodology and Key Numbers

Okta commissioned Apprize360 to run an online double-blinded survey of 292 executives and 492 knowledge workers. Executive recruitment focused on CEOs, CIOs, CTOs, and vice presidents with authority over IT, security, data, and engineering; 91% led or oversaw teams responsible for AI implementation, governance, security, or strategy. Knowledge workers spanned technical, sales, customer service, marketing, communications, business operations, and accounting roles; 100% had worked with AI in the three months before the survey. Respondents came from the US (23%), UK (22%), Australia (12%), Canada (12%), Japan (11%), France (10%), and Germany (10%). The survey was fielded in March 2026.

The numbers are unsettling: 92% of executives said autonomous AI agents are already in widespread (58%) or moderate (35%) use; nearly two-thirds (64%) of knowledge workers use an AI tool at least daily; 68% of workers use AI agents and 62% use LLMs or chatbots.

Executive Overconfidence, Widespread Shadow AI

90% of executives are confident in their organization's visibility into AI tools, and 95% are confident employees use AI responsibly. Yet 52% of employees admit to using AI tools without approval, often via personal accounts. This is the most ironic governance gap: executives believe everything is under control while employees already operate AI at scale outside enterprise oversight.

And that confidence is misplaced. Of those using unapproved AI tools, 54% share internal messages and emails, 45% share HR-related information, and 39% share confidential company documents including financials and contracts. Over 20% also share login credentials and passwords, and 28% share banking and payment information. Data use has slipped from an efficiency tool into identity and financial risk.

Governance Gaps Have Become Real Incidents

Governance gaps are already producing real-world consequences: 58% of executives reported that their organization experienced an AI-related security incident or close call in the past 12 months. More than half of enterprises have already paid the price of shadow AI and governance gaps — not potentially, but in fact.

Policy clarity shows an equally stark gap: 65% of executives believe their AI usage policies are very clear, but more than half (57%) of knowledge workers disagree, finding policies unclear, hard to find, or non-existent. Executives and frontline workers hold almost opposite views of the same policy — which directly explains why policy does not translate into compliant employee behavior.

The Identity Double Standard

Only 34% of organizations apply the same security controls to their agentic labor force as to their human labor force. That means nearly two-thirds of enterprises let AI agents run under weaker controls than human employees — a dangerous double standard and a structural reason AI agents become privileged-insider attack surfaces.

Building a secure agentic enterprise requires answering three questions: Where are my agents? What can they connect to? What can they do? These three questions form the governance foundation of visibility, access control, and accountability — and the first step toward closing the gap between confidence and reality.

A Path Forward for Enterprises

Okta offers four recommendations. First, define a governance strategy now rather than waiting for a crisis — most executives already report AI-related incidents, and delay only raises the cost. Second, make the secure path the easiest path — employees choose unsanctioned tools because they are faster and easier; a stricter policy will be ignored if it hinders productivity, so remove friction from approved tools via standard protocols such as cross-app access. Third, define your AI governance strategy and use it to scale. Fourth, treat every AI agent as a first-class identity with its own lifecycle and least-privilege permissions.

References:

Frequently Asked Questions

What are the core findings of Okta's 2026 survey?+

The survey, commissioned by Okta and run by Apprize360, covered 292 executives and 492 knowledge workers across seven countries. The core finding: 90% of executives are confident in their organization's visibility into AI tools and 95% are confident employees use AI responsibly — yet 52% of employees admit to using AI tools without approval, often via personal accounts. 58% of organizations reported an AI-related security incident or close call in the past year. Governance gaps have already translated into real-world consequences.

What sensitive information do employees share with unapproved AI tools?+

Of those using unapproved AI tools, 54% share internal messages and emails, 45% share HR-related information, and 39% share confidential company documents including financials and contracts. Over 20% also share login credentials and passwords, and 28% share banking and payment information. This extends well beyond general data leakage into direct identity and financial risk.

How large is the AI policy clarity gap?+

65% of executives believe their organization's AI usage policies are very clear, but more than half (57%) of knowledge workers disagree — finding policies unclear, hard to find, or non-existent. Executives and frontline workers hold almost opposite views of the same policy, which directly explains why policy fails to translate into compliant behavior.

Do enterprises apply the same controls to AI agents as to humans?+

Only 34% of organizations apply the same security controls to their agentic labor force as to their human labor force. Nearly two-thirds (roughly 66%) of enterprises let AI agents run under weaker controls than human employees — a dangerous double standard and a structural reason AI agents become privileged-insider attack surfaces.

How should enterprises close this governance gap?+

Okta offers four recommendations: define a governance strategy now rather than waiting for a crisis; make the secure path the easiest path (remove friction from approved tools); define your AI governance strategy and use it to scale; and treat every AI agent as a first-class identity with its own lifecycle and least-privilege permissions. Agent identity governance solutions can help manage AI agents.