Legal News

Enterprise AI Governance: Addressing Shadow AI Risks and Compliance

South Africa·Wire Summary⏱️ 4 min read

Employees are using AI-powered solutions without waiting for security approval. (Image source: iStock) Enterprise security teams have long battled to keep shadow IT under control, but now they face a greater challenge in shadow AI. Many employees are using AI-powered solutions without waiting for security approval, and cyber security professionals are struggling to keep up. While no single solution can squash shadow AI on its own, these tools complement each other to build layered protection. No one wants to miss out on the massive productivity and efficiency gains that AI tools deliver, so employees often start using AI without checking with security teams first. A recent study on shadow AI from Wakefield Research found that 66% of office workers use AI tools at work despite believing that those tools are not permitted under company policy. It might give them an edge in the workplace, but AI brings security threats as well as work benefits. When two-thirds of employees are knowingly evading company policy regarding AI, it’s clear that awareness alone isn’t solving the problem. What’s needed is better governance that gives security teams visibility into AI use they currently can’t see. Existing security tools aren’t designed to deal with AI’s unique workflows and risks. They were built to watch traffic, guard endpoints and monitor known applications, not to assess an AI prompt and decide whether it contains sensitive data, or to distinguish between permitted and shadow AI use. Since employees keep using AI tools regardless of policy, a new category of security platforms built specifically to govern AI use has emerged, with the recently released Check Point AI Network Firewall among them. Today’s AI firewalls were designed specifically to protect AI tools, not to add AI features to a firewall that defends against conventional threats. The five platforms profiled here work together to cover different parts of that gap, from the browser to the network to the firewall. Shadow AI isn’t a harmless phenomenon. It has direct and significant consequences to enterprise security. These include: Check Point’s AI Network Firewall layers on top of its conventional firewall infrastructure, with its AI application defences built on technology from Lakera, the AI security company Check Point acquired in 2025. The AI Network Firewall monitors and inspects traffic that passes through the network to AI applications and tools, bringing visibility to on-network employee AI use. As a network-level appliance, it can’t scrutinise off-network traffic like personal device and personal account usage. Check Point recommends pairing it with the Check Point Workforce AI Security module, which adds endpoint monitoring to managed devices. Check Point key features: How Check Point contributes to shadow AI governance: Netskope has extended its Security Service Edge platform to discover and manage use of over 370 GenAI apps via its Cloud Confidence Index, which also tracks more than 82 000 SaaS applications. It requires client deployment so it can cover on-network and off-network devices, giving it a broader reach than a pure-play AI firewall, but it still misses custom-built AI systems, personal devices and unmanaged hardware. Netskope key features: How Netskope contributes to shadow AI governance: Microsoft broadens its Purview and Defender capabilities to include shadow AI monitoring in its existing data-loss prevention and CASB tools. Like Netskope, Microsoft Purview and Defender include any managed devices that clients add to their deployment, providing off-network and on-network supervision but missing personal and unenrolled hardware. Microsoft key features: How Microsoft contributes to shadow AI governance: AI Access Security is a dedicated product within Palo Alto’s Secure AI by Design portfolio, distinct from Prisma AIRS, which secures Palo Alto customers’ own AI applications, agents, and models rather than discovering workforce access to outside AI to

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Get The Latest Legal & Regulatory intelligence in South Africa

Finish Reading the Full Story and the Expert Analysis.

No Credit Card Required.Enter Email to Subscribe

Already have an account? Log in

Wansom is AI and can make mistakes.