The rise of “shadow AI” is expanding enterprise attack surfaces across devices, endpoints, and data flows, according to new research from Lenovo, with uncontrolled AI already impacting business performance.
The tech giant’s latest Work Reborn Report, based on a survey of 6,000 enterprise employees worldwide, found that more than 70% of workers now report using AI weekly, with up to a third operating beyond IT oversight.
Almost a third of these AI users (31%) said they have received no formal training on how to use the tech at work, while 22% have no employer-provided AI tools. Even among those receiving training, more than half say it is irregular, while 42% complain it is not effective.
This shows that while employees might want to work within secure environments, they are relying on whatever tools they can access to stay productive, creating what Lenovo calls a “two-speed workforce” that slows enterprise-wide AI adoption – a gap threatening to grow as 80% of all workers expect their AI use to increase over the next year.
Without visibility or governance, this unmanaged AI rollout is already affecting cost, security posture, and the ability to scale AI successfully across the business.
Lenovo said that firms without strict frameworks in place are experiencing fragmented ROI from AI initiatives, duplicated spend as systems work against each other, and widening attack surfaces as unsanctioned tools gain access to company data.
But businesses are not doing a good enough job at communicating these threats. For instance, while 61% of IT leaders report a rise in cybersecurity threats linked to AI, just 23% of employees are highly concerned about cybercriminals attacking firms’ AI systems, and only 43% are worried about AI being used to develop cyber-attacks against their company.
Lenovo also found that workers are falling short on basic AI‑related cyber hygiene, with only 43% highly concerned about leaking sensitive data into public tools like ChatGPT, and just 40% recognising the risk of AI‑powered scams such as deepfake phishing.
Recommended reading
- Critical Blindspots in GenAI Adoption CIOs Must Address
- 69% of C-Suite Leaders Choose Fast AI Over Secure AI
- ‘Shadow AI’ Use Is Threatening Enterprise Data Security
However, the firm said that adding more tools or policies cannot solve these problems, likely only increasing complexity and making it difficult to enforce consistent control across the environment.
Instead, firms should focus more on building AI skills from the ground up. Almost three-quarters of employees stated that better cybersecurity training on AI-related risks would reassure them, while 70% said they would like stricter, clearer policies on how employees can use AI.
“AI adoption is no longer the challenge. Execution is,” said Rakshit Ghura, VP and general manager for digital workplace solutions at Lenovo.
“Usage is growing faster than organisations can control or secure it. Without that control, AI introduces as much risk and cost as it does opportunity.”





