> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Shadow AI Isn’t Employee Rebellion. It’s an AI Governance and Leadership Problem
- URL: https://www.cybrsecmedia.com/shadow-ai-isnt-employee-rebellion-its-an-ai-governance-and-leadership-problem/
- Published: 2026-10-08T11:05:48.000Z
- Updated: 2026-10-08T11:06:12.000Z
- Description: Employees aren’t necessarily ignoring AI governance when they use unapproved tools. Olivia Rose argues that conflicting messages, weak training and poor leadership are fueling shadow AI — and policies alone won’t fix it.
- Author: Bill Brenner
- Tags: Shadow AI, Human Risk Management, Article

Organizations scrambling to govern artificial intelligence may be focusing too much on policies and not enough on the people expected to follow them.

That was a central theme of the latest CYBR.Minded, where host Dr. Dustin Sachs spoke with Olivia Rose, co-founder and principal of Williams Rose AI Cyber Advisory, about why AI governance often breaks down once it leaves the boardroom and enters everyday workflows.

**Full episode:**

[AI or Bust with Olivia RoseIn this episode of CYBR.Minded, Dr. Dustin Sachs sits down with Olivia Rose, Co-Founder of Williams Rose AI Cyber Advisory to discuss why shadow AI isn’t simply employee rebellion, why leadership has to own AI adoption, and what it takes to build governance that actually works when![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-c740efea-57ad-4948-99cd-a7867eda7faf.jpg)CYBR.SEC.Media, and CYBR.SEC.Media![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Olivia-Rose_Ghost-dee88240-3a61-43e3-8189-fa02595955f5.png)](https://www.cybrsecmedia.com/ai-or-bust-with-olivia-rose/)

For Rose, the problem starts with a disconnect inside the executive suite.

Some executives — particularly CISOs, legal leaders and technology executives — see AI governance as a way to understand risk and establish appropriate controls. Other business leaders are focused on speed, innovation and revenue.

“Give me guardrails” is often as far as that second group wants governance to go, Rose said.

That tension leaves security leaders trying to secure a technology that organizations are simultaneously racing to deploy. And Rose cautioned against making the CISO responsible for the success of the entire AI program.

“The AI rollout really should be coming from the CEO,” she said. If leadership wants employees using AI, executives should clearly articulate that strategy and demonstrate the behavior themselves. The CISO’s job is to secure that adoption as effectively as possible — not carry the entire transformation.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## Shadow AI is a symptom, not the disease

That leadership responsibility becomes particularly important around shadow AI.

Organizations often portray employees using unauthorized AI tools as careless rule-breakers. Rose believes that interpretation misses what is actually happening.

Employees are being told that AI is transformative. They’re encouraged to experiment, innovate and become more productive. Then organizations are surprised when workers independently try new models and applications without involving security.

That isn’t necessarily rebellion.

“People are very curious, they’re excited,” Rose said. “They want to download ChatGPT and create a bobblehead of themselves and send it to their kids.”

The problem arises when organizations encourage experimentation without clearly defining where and how that experimentation should happen.

Rose places more responsibility on leadership when employees receive conflicting messages about AI while receiving inadequate training on its responsible use.

Sachs argued that organizations can address some of that tension by creating safe environments where employees can experiment with AI without exposing corporate systems or sensitive data. Sandboxes can give workers room to learn while giving security teams greater visibility into how AI is actually being used.

Simply banning AI may produce the opposite result.

Rose recalled attending an event where someone claimed his organization had 100% visibility into AI usage because it prohibited AI entirely. The assumption stunned her. Sachs compared it to the old cybersecurity maxim about breached organizations: Some companies know employees are using AI outside their visibility, while others simply don’t know it yet.

## Measure behavior, not paperwork

Effective AI governance also requires organizations to rethink what success looks like.

Publishing policies, approving tools and completing risk assessments demonstrate activity. They don’t necessarily show whether employees are making better decisions.

Rose said leaders should examine whether AI is producing useful outcomes — saving time or generating business value — while simultaneously measuring whether its use creates additional vulnerabilities or security problems. Governance requires balancing those two sides rather than treating security and business value as separate exercises.

She also pointed to security awareness as an important indicator of AI readiness. Before handing powerful AI capabilities to employees, organizations need confidence that workers understand risk, accept responsibility and can make sound decisions when rules collide with business pressure.

That may require more than another annual training course.

The larger lesson from the discussion is that organizations cannot govern AI simply by writing policies around it.

AI governance happens when an employee faces a deadline, discovers a useful new model and has to decide whether to paste company data into it. It happens when an executive demands faster AI adoption while security is still determining the risks. And it happens when employees must translate abstract corporate rules into decisions made under real-world pressure.

Policies matter. But governance ultimately succeeds or fails in those moments.

[![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/2026/10/2027-Events-Banner-16.png)](https://www.cybrsecmedia.com/conference/)