This report draws on patterns observed across GovernAI's enterprise deployments and conversations with security and IT leaders throughout 2025. It's not a scientific survey — treat the figures as directional signal about where enterprise AI governance is heading, not precise industry-wide statistics.
Four trends we're watching
1. Shadow AI usage is still the norm, not the exception
Despite two years of enterprise AI purchasing, the majority of organizations we talk with still find AI tool usage happening outside any centrally managed account when they first get real visibility into it — personal API keys used in scripts, individual subscriptions expensed as software, browser extensions installed without IT review. The gap between "AI is officially rolled out" and "AI usage is fully visible" remains wide.
2. Connector-based data exposure is the fastest-growing risk category
As AI tools gained the ability to read connected documents, calendars, and internal wikis, the risk profile shifted from "what does the user type into the chat box" to "what does the AI have access to read on the user's behalf." Indirect prompt injection via retrieved content, and simple over-broad connector permissions, are now a larger share of reported incidents than direct prompt manipulation.
3. Human approval gates are moving from "nice to have" to a baseline expectation
As AI agents gained the ability to take actions — not just draft text — a pause-for-human-review step on consequential actions has gone from a differentiator to something security teams ask about by default during vendor evaluation. The organizations furthest along treat this as non-negotiable for any action that writes to a system of record.
4. Budget ownership is consolidating under IT and finance jointly
Early AI spend was scattered across departmental budgets with little central visibility. That's changing — more organizations are establishing a single AI budget owner who can see spend across every team and model provider, mirroring how cloud infrastructure spend consolidated under FinOps practices a decade earlier.
What this means for security and IT leaders
- checkAssume shadow AI usage exists in your organization today, and prioritize visibility over restriction as the first step — you can't govern what you can't see.
- checkAudit connector permissions with the same rigor you'd apply to any other data access grant, not as an afterthought to chat security.
- checkBuild the human-approval gate into your AI rollout plan from day one — retrofitting it after agents already have write access is a much harder migration.
- checkPut a single owner on AI budget before your next fiscal year planning cycle, even if full technical consolidation takes longer.