JULY 22, 2026
7 MIN READ

The Visibility Problem: We Can't Govern the AI We Can't See

The Visibility Problem: We Can't Govern the AI We Can't See
Only 13% of IT and security professionals are fully confident they can see every AI tool employees use. AI risk starts with visibility.

This is the first post in a multi-part post series iterating what the 2026 Drata State of GRC survey reveals about the gap between how fast AI arrived in GRC and how fast governance is catching up. We’ll start this series by focusing on one of the most foundational controls in security: asset inventory. Every governance program starts with inventorying what we can and quickly surface anything we can't see.

Today, asking a security, IT, or GRC team to provide an inventory of all AI models, tools, and agents running inside their company may yield a long, deafeningly silent pause. Our team members are signing up for AI tools, AI assistants, AI notetakers, and other AI capabilities; pasting company data into chatbots; and adding new skills, capabilities, and agents into workflows faster than our review processes can catch, identify, surface, and vet. Ultimately, our AI governance programs are accountable for this, including identifying what lies in the wake of harkening to the demands of our leadership teams to adopt and use AI as much as humanly possible. The gap? Shadow AI sprawl, and this gap is expanding faster than most GRC and security teams can bridge.

The State of GRC survey puts a number on it. Only 13% of IT and security professionals confidently claim full visibility into the AI tools active in their organization. I genuinely applaud and admire the efforts of these organizations! The other 87% report they aren’t fully confident—a natural and honest answer admitting a very real blind spot they’re attempting to govern.

The Visibility Problem

Read the Report

The visibility problem: only 13% are fully confident they can see every AI tool their employees use, which leaves 87% not fully confident they can account for all of it.

State of GRC

Ultimately, lack of visibility is the crack in the newly formed AI governance program foundation, and that’s a problem that isn’t going away anytime soon. A control we apply to the technology and processes we know about only stops there and does nothing for the ones we can't see, and a majority of programs are now operating with that blind spot. As usual, our team members find a pathway forward while impatiently waiting for procurement to catch up to the adoption of AI, and they found the tools, signed up, started using them, all while the governance framework and supporting technologies are still catching up to the footprint that grew without it.

Where Shadow AI Turns Into Unmitigated “Shadow” Risks

Shadow AI does not fly under the AI governance radar for long. Asked about the biggest risks of employees using shadow AI, security professionals named the exact risks GRC and security programs aim to prevent, as follows:

  • Data security risks: 57%

  • Privacy concerns: 52%

  • Compliance or regulatory violations: 51%

The list continues past the top three. Exposure of sensitive information (42%), inaccurate or unreliable outputs (39%), and loss of intellectual property (33%) round out the picture. Each one maps to real, business impacting risks, which may eventually yield to incidents. Sensitive data is input into an AI platform without protections to prohibit use in model training. Personal information gets processed outside the boundaries a privacy program promised customers and regulators. An AI capability is deployed into a critical business decision making workflow that was never defensibly proven and assessed to be commensurately reliable.

The throughline is every one of these risks stems from the tool not being in our awareness to be adequately vetted and deemed ok for use. When 87% of teams aren't fully confident in their inventory of AI use, the controls we rely on to mitigate risks lead to unknown unknowns—risks that may ultimately become a sleeping giant only to wake and cause problems we weren’t expecting.

Visibility Into Your AI Helps Determine Value

AI visibility is usually pitched as a precursor risk assessment and mitigation of data leaks, privacy violations, and failed audits, but the survey surfaced something else. Visibility also determines how much output we get from using AI.

Workload pressure is nearly universal. 77% of GRC teams report a meaningful increase. The difference is in who's handling it without hiring. Among teams that reported having confidence in the completeness of their AI inventory, 68% took on a 10%+ workload increase with no new headcount. Among teams that can't, only 55% did. When we have an inventory of AI, it's more likely to add to the output we’re hoping for.

Ultimately, governed AI yields capacity, while ungoverned AI simply adds technology and tools without adding the capacity we expect. That makes discovery an operational advantage over a compliance chore, and it shows up commercially. When a prospect's security team asks what AI touches their data, a live inventory is the difference between answering johnny-on-the-spot with the authoritative answer in the meeting vs. stalling the deal while we find out.

What a Real AI Inventory Looks Like

Visibility is the start that makes controls meaningful. Policies, approval workflows, and risk assessments are only as complete as the list of assets, processes, and systems they cover. Ultimately, with how quickly our organizations build and deploy, getting and keeping our inventory accurate means using automation with continuous discovery rather than a point-in-time periodic audit that's stale by the time it's completed.

In every program I've built, taking the time to truly understand the systems, assets, buildings, data, people, and company I’m securing puts the whole purpose in context, allowing me as a practitioner to approach security and GRC in a practical and pragmatic way. Expanding assets to include our use of AI, especially as an AI forward-thinking and AI enabling CISO within my organization, is only natural.

A useful AI inventory answers four questions:

  • What does it do?

  • What data does it touch or have access to?

  • What outcome does it own?

  • Who is responsible for its performance?

Any AI tool without reliable answers to these questions should be heavily scrutinized. The programs that scale chase these answers, connect AI usage signals across the environment, flag new tools as they appear, and give us a live view into what’s operating. Constant discovery stops being a pain-laden project and starts becoming a monitored, always-on control.

Close the AI Visibility Gap With Drata

Drata’s platform continuously monitors our environments so AI tools surface as they appear, giving our GRC teams the visibility that every downstream control depends on. It's becomes the always-current inventory of what's running and who owns it. See how continuous monitoring closes the AI visibility gap: schedule your demo today.

While visibility tells us what's running, it doesn't tell us who's on the hook when one of those tools goes off the rails. Once we can see the AI in your environment, the next question is who is accountable when AI breaks something. Look for the next post on the accountability problem soon.

Conducted by Wakefield Research for Drata among 300 U.S. IT and security professionals at companies with 1,000–20,000 employees across High-Tech, SaaS, FinTech, HealthTech, and Retail, fielded March 12–27, 2026. Overall margin of error ±5.7 percentage points at 95% confidence.

Image
Matt Hillary
CISO

Matt Hillary is the Senior Vice President of Security Engineering and CISO at Drata – a Trust Management Platform to help build and maintain trust in the cloud using AI and automation – where he oversees Drata’s global security, IT, compliance, and privacy strategy and programs. With 18+ years of security experience — 8 of those years as CISO at 5 large organizations — Matt has a track record of building and leading exceptional security programs.

He has been in a number of security leadership roles, including Senior Vice President of Systems and Security and CISO at Lumio, CISO at Weave, VP, Security and CISO at Workfront, VP of Security at Instructure, and other lead security roles at MX, Adobe, and Amazon Web Services. Outside of work, Matt enjoys traveling with his wife, making fun memories with his four kids, enjoying all genres of music and arts, exploring the outdoors and amazing recreation in Salt Lake City (Utah), and experiencing all this amazing world has to offer.

category + topics

Expert Insights
AI
Subscribe to the Trusted Newsletter
Get biweekly expert insights so you never miss what’s next.

Chart Your Course

Navigate to new worlds of trust with Drata.