by Giles Douglas, CISOWhat if your biggest security risk isn’t malicious hackers but well-meaning employees trying to keep pace with modern work?Superhuman’s Human + Technology Experience Index found that nearly 75% of employees use unsanctioned tools at work, and 65% go looking for unofficial
by Giles Douglas, CISO
What if your biggest security risk isn’t malicious hackers but well-meaning employees trying to keep pace with modern work?
Superhuman’s Human + Technology Experience Index found that nearly 75% of employees use unsanctioned tools at work, and 65% go looking for unofficial AI on their own. It’s easy to read these stats as employee rebellion, but I read it as a support gap.
People are trying to do good work but lack the tools and guidance to do it safely. The Ponemon Institute’s 2026 Cost of Insider Risks report confirms this and gives us a real cost. Negligent insiders are responsible for most incidents, costing organizations collectively over $10 million annually.
So, alongside strengthening our risk postures, we also need to reevaluate what the human side of security means as our programs evolve to keep up with AI.
Assume good intent and recognize the power of fearTake a step back and consider what motivates employee behavior. People want to be good at their jobs. They want to be more productive, produce better work, and be seen as contributors to their companies’ success. The overwhelming majority have never made a technology choice out of malice.
The AI hype cycle plays on exactly that good intent, manufacturing fear for anyone who hasn’t yet unlocked hyperbolic efficiency with AI. Every ad reminds employees that they could be doing more, faster. That they need to click, download, and start now, before being left behind.
Good intent creates risk when employees aren’t equipped to evaluate their choices. Fear-driven intent accelerates it. Preserving and guiding good intent is core to the future of AI security.
Here are three steps I have in mind.
Pave the road, then send employees down itAI mandates are multiplying. “Every employee should be using AI by the end of the quarter.” “Start every task with AI.” The mandates are fine when they fit the business, but a mandate without direction fuels employee anxiety. And anxious people go looking for AI wherever they can find it.
The solution here isn’t a taller fence. It’s a smoother road. In engineering, a “paved road” is the well-supported, sanctioned way to get something done. The route is so easy and well lit that straying feels like more work, not less. AI mandates should give people that road, not just point at the horizon and say go.
Here’s what it takes:
When the sanctioned path is also the fastest one, shadow AI stops being a temptation and becomes the harder option. Employees are rarely trying to break the rules. They’re trying to get to work. Build the road that gets them there.
Educate—don’t just offer educational opportunitiesAsk an IT team whether they’ve trained employees on AI and security policy, and they’ll send you a bunch of links to knowledge base articles and video recordings. (I practically have a keyboard shortcut for sending them.) Ask employees the same question, and they’ll tell you nothing exists.
We have to provide training that is accurate and resonant.
Think about how far we’ve come in cybersecurity. Fifteen years ago, almost no one could define phishing. Today, most employees can spot a phishing email, a smishing text, or a sketchy link on sight. We didn’t scare them into vigilance; we made the risk understandable and easy to recognize.
We have to make AI risk real for employees in the same way. This starts by giving people a shared vocabulary, specifically for the moment an employee is about to connect a new AI tool to company data.
Here are terms all employees should understand:
When an employee gets “caught” using an unapproved tool, treat it as a learning moment—for both of you.
First, assume good intent. Second, explain why unapproved tools create risk and how this particular tool does so. Your goal isn’t to shut down one tool for one person; it’s to prevent the next misuse and, ideally, turn that employee into an ambassador who spreads the word. Third, find out why they reached for the tool in the first place. Does it do something your approved stack can’t? This is the color commentary to all your telemetry data. Does it do something you already offer? Either answer is useful: You’ve found a gap to fill or a tool that needs more visibility.
I’ve had the pleasure of working with many chief information security officers and IT professionals. They are all genuinely excellent at the technical side of risk management. The people-enablement side is usually the harder, less-practiced skill for most security teams. It’s also the piece AI is forcing us to get better at. The organizations that get AI security right won’t just have big fences. They’ll be the ones whose people understand the risk, trust the paved road, and know it’s safe to ask for help. Build for the humans, and the security follows.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Cognitive Load Is the Metric No One’s Tracking | 0 | 13.52 | 18-08-2026 |
| 2 | AI Blind Spots: Advice From Superhuman’s VP of Product, CISO, and CFO | 0 | 8.28 | 04-08-2026 |
| 3 | In a World Full of AI Tools, Where Does the Work Actually Live? | 0 | 9.69 | 06-08-2026 |
| 4 | New Threats Demand New Approaches: How Superhuman Security Engineers Use AI | 0 | 8.79 | 18-08-2026 |
| 5 | Survey reveals 78% of enterprises are reporting AI-related security incidents | 0 | 7 | 07-07-2026 |
| 6 | Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges | 0 | 5.62 | 19-03-2026 |
| 7 | Shadow AI is becoming enterprise security’s biggest blind spot | 0 | 10.21 | 23-07-2026 |
| 8 | The Hidden Cost of AI Security Scanners | 0 | 7 | 20-05-2026 |
| 9 | AI-powered workplace tools keep tabs on employees | 0 | 5 | 17-03-2026 |
| 10 | Using AI to build a more resilient network — from the inside out | 0 | 6.54 | 08-07-2026 |