Zakaria Haltout, Group Vice President for the Middle East, Turkey and Africa at Workday, explains that employees are increasingly relying on unsanctioned AI tools, creating rising “shadow AI” risks. With stronger governance, better visibility, and secure AI alternatives, UAE businesses can turn these risks into safe, productive innovation.
Designed to make your life easier and ultimately more productive, AI-powered apps are rapidly proliferating our lives and becoming increasingly common use in the workplace. It’s a familiar scene in offices everywhere: someone discovers a cool new app or tool — maybe it’s an online AI writing assistant that polishes emails, or a smart chatbot that helps brainstorm ideas for a presentation. But what happens when these helpful tools aren’t officially approved by the company’s official IT policy?
In the UAE, this behaviour is even more pronounced. The country’s tech-savvy population, combined with progressive digital government policies, has created fertile ground for rapid AI experimentation. A recent KPMG survey found that an extraordinary 97% of UAE respondents are using AI for work, study, or personal tasks. Employees pick up these tools to automate everyday tasks, create content, or help with decision-making, often without realizing they’re stepping outside of official company policies or security frameworks.
This phenomenon is reflected globally as well. According to a recent report by data security company Varonis, 98% of employees are using applications that aren’t officially sanctioned by their employer, and that includes AI. This is what is commonly referred to as “shadow IT” or more specifically, “shadow AI”. While often well-intentioned, this unsanctioned usage poses substantial risks for organizations.
Data confidentiality is one of the most immediate concerns. Some AI services, especially free versions, may use the data they process to train their underlying models. When sensitive company information—like strategic plans, customer data, unreleased financial figures, or even proprietary source code—is entered into an unapproved AI tool, that data can end up in publicly accessible or poorly secured AI models. This creates a huge blind spot for IT and security teams, who suddenly lack clarity on which tools are being used or where sensitive information may be flowing.
The recently published Data Security Landscape report from cybersecurity firm Proofpoint confirms how the rapid adoption of AI-driven productivity tools and autonomous agents is compounding risk. Based on a survey of 1,000 security professionals, the findings revealed that 38% of organizations in the UAE cite data loss via public or enterprise GenAI tools as a top concern. Another 46% worry about sensitive data being used in AI training, while 48% of organizations report insufficient visibility and controls over GenAI tools.
Despite these risks, simply banning AI tools is not a viable option. As adoption becomes ubiquitous, employees’ will inevitably find workarounds to boost their productivity. Organizations therefore need a structured, two-pronged strategy: robust IT governance and active employee empowerment. Together, these approaches allow companies to reduce risk, increase visibility, and unlock AI’s potential safely, ultimately empowering their workforce.
The first step is gaining a clear picture of AI usage across the business. Shadow AI tools often operate quietly within daily workflows, making them difficult to detect through traditional monitoring. Conducting regular audits helps identify unsanctioned tools, assess their security profile, and determine whether they should be removed, restricted, or formally approved. Over time, these audits also reveal how employees are using AI, offering valuable insights to refine enterprise AI policies.
Once shadow usage is understood, IT can implement the right protection systems. Automated detection systems can flag unauthorized tools in real time. Organizations can deploy secure, enterprise-grade AI models, manage access or integrate approved AI systems directly into internal infrastructure. Controlled access to external AI platforms may be appropriate for low-risk use cases, whereas high-sensitivity tasks require AI solutions that ensure data never leaves the organization’s ecosystem.
With visibility and governance in place, leaders can then transform shadow AI into a valuable capability. What was once hidden becomes measurable: companies can track usage patterns, understand which models are preferred, determine what data is being fed into them, and even monitor spending at the team level. This allows IT to tighten compliance while enabling employees to innovate within safe boundaries.
At the same time, human behaviour remains central to managing shadow AI. Employees explore new tools because they are motivated to work smarter, not because they intend to create risk. When organizations fail to provide guidance or refuse to adopt modern tools, employees naturally seek their own solutions. Clear policies, practical training, and transparent communication empower employees to use AI responsibly and confidently.
Ultimately, the rise of shadow AI is not a signal to slow down—it is a signal to accelerate responsibly. In a market like the UAE, where digital transformation is a national priority and AI readiness continues to outpace global averages, businesses cannot afford to let innovation operate in the dark. By building strong governance, offering secure AI alternatives, and giving employees the clarity they need to experiment safely, organizations can turn shadow AI from a hidden vulnerability into a driver of innovation, productivity, and operational excellence in the modern UAE workplace.