# The CISO Who Says Yes Is the CISO Who Gets a Seat at the Table
The most dangerous question in enterprise security right now is not "are our employees using AI tools?" McKinsey's latest State of AI report answers that one already: 76 percent are, up from 55 percent the year prior. The dangerous question is whether your security team knows about it.
That distinction is where CISO careers are being made and broken in 2026.
## We Have Been Here Before
Cast your mind back to 2010. The iPhone was two years old, Android was catching up fast, and IT departments across the Fortune 500 were writing policies that said "no personal devices on the corporate network." Those policies failed within eighteen months — not because security teams lacked authority, but because the productivity delta was too large to ignore. Executives started reading email on iPhones. Sales teams stopped using their BlackBerrys. The policy didn't stop BYOD; it just made BYOD invisible.
The organizations that came out ahead were the ones that pivoted fast. They built mobile device management infrastructure, defined acceptable use, and got visibility into a category of endpoints that was going to exist regardless of what the policy said. The ones that held the line the longest ended up with the worst posture — employees deeply practiced at working around IT, with no audit trail and no protection.
AI adoption in the enterprise is playing out the same way, with one critical difference: the speed is roughly five times faster and the surface area is orders of magnitude larger.
## What "Shadow AI" Actually Looks Like
When an employee pastes a customer contract into ChatGPT to get a summary, that data has left the building. When a developer uses a coding assistant with a default free-tier account — not the enterprise-licensed version with data controls — proprietary code is training somebody else's model. When a finance analyst asks an unapproved AI tool to help draft a board presentation, the competitive intelligence in that deck just hit a third-party server with unknown retention policies.
None of this requires malicious intent. It requires only a seven-second workflow optimization that nobody thought to ask permission for.
The McKinsey number — 76 percent of workers using AI in some capacity — does not mean 76 percent are using sanctioned tools on approved data. It means 76 percent have found some way to integrate AI into their work, sanctioned or not. The split between those two categories is where the actual risk lives, and most security teams have no visibility into it.
## The Governance Play That Actually Works
Security leaders who are winning right now are not the ones writing stricter acceptable-use policies. They are the ones building fast, visible paths to approved AI tools — and making themselves the person who unlocks that capability rather than the person who blocks it.
The mechanics of this are not complicated. An AI governance program that actually functions has three components:
Visibility first. You cannot govern what you cannot see. That means browser-level telemetry, DLP rules tuned for AI traffic patterns, and a clear inventory of which AI tools are in active enterprise use — including the ones nobody approved. The discovery phase usually produces an uncomfortable number. Security teams that have run this exercise typically find employees are using three to six times more AI tools than IT is aware of.
A fast lane for approval. The reason shadow AI proliferates is friction. If getting an AI tool approved takes six weeks and three committee reviews, employees will not wait. A lightweight approval track — something a team can run through in five to ten business days for low-risk tools — changes the incentive structure. Employees who know they can get to yes quickly will ask before adopting, rather than adopting and hoping nobody notices.
Data classification guardrails, not blanket bans. The correct governance model is not "no AI on sensitive data." It is "here are the approved tools for each data classification tier, and here is why." Customer PII goes through the enterprise contract with zero data retention. Internal code analysis runs on the air-gapped or self-hosted instance. Public-domain research and general drafting can use whatever the employee prefers on a free tier. Making the rules clear and logical means employees can follow them without treating every AI interaction as a compliance minefield.
## Why This Is a Strategic Inflection Point for CISOs
The security function has spent two decades fighting for budget and board-level relevance. The traditional framing — security as cost center, as risk reducer, as the team that slows things down for good reasons — has always made that argument harder than it should be.
AI governance is the first category in a long time where security can genuinely position as a business enabler without stretching the truth. The productivity gains from AI are real and measurable. Organizations that can capture those gains safely, with auditability and data protection built in, will outperform those that either block AI (and lose the productivity) or adopt it without governance (and absorb the data exposure). Security is the team that knows how to build the governance layer. That is a genuine value proposition, not a marketing exercise.
CISOs who execute on this will show up in conversations about competitive strategy, not just risk registers. That is a different kind of influence than the security function has historically held, and it is worth the organizational investment to pursue it.
## What the Other 24 Percent Should Know
The McKinsey figure cuts both ways. The 24 percent of employees who are not yet using AI at work are not a safe harbor — they are a gap that will close. The organizations where those employees work are not protected from AI risk; they are simply behind the adoption curve and will face compressed timelines to build governance frameworks under more pressure than their faster-moving peers.
There is a window here. Building AI governance before the C-suite is demanding AI-powered workflows gives security the leverage to set the terms. Trying to retrofit governance onto a workforce that has already normalized uncontrolled AI use is significantly harder and produces a measurably worse security outcome.
The CISO who moves now — who builds the fast lane, maps the shadow AI surface, and shows up to the AI strategy conversation with a governance framework in hand — is not being naive about security trade-offs. They are making the correct bet that enabling controlled adoption beats trying to stop the tide.
---
## HackWire Analysis
The McKinsey data point is being widely cited as evidence of AI's enterprise momentum. What the coverage is mostly missing is what that number tells us about security posture specifically.
Seventy-six percent adoption across a workforce does not grow from the top down. Enterprise AI rollouts driven by IT are organized, documented, and visible. What produces that kind of penetration that fast is organic, department-level, individual-user adoption — the definition of shadow technology. We saw the same signature in the shadow IT wave of the mid-2010s, when SaaS applications proliferated faster than procurement processes could track.
The prior incident worth studying closely here is the Slack adoption curve circa 2015-2017. Security teams that got ahead of it built SSO integration, set retention policies, and established acceptable use before the tool became load-bearing. Those that resisted until resistance was untenable ended up with Slack embedded in critical workflows, data scattered across personal accounts, and no audit history for any of it. The AI parallel is direct and the stakes are higher — the data types flowing through AI tools (code, contracts, customer data, strategic documents) are more sensitive than most of what went through Slack.
The hidden risk in current coverage is the gap between "AI governance program" and actual visibility. Many organizations are announcing AI policies without the telemetry to know whether employees are following them. A policy without enforcement is a false confidence generator. Before a CISO reports to the board that AI adoption is governed, they should be able to answer: how many unapproved AI tools did employees access last week, what data did they submit, and how do you know?
That answer requires tooling investment, not just policy work. The CISOs who will be able to make that case in eighteen months are the ones building the detection capability now.
— HackWire Editorial
---
## Related Coverage