According to Foundry’s 2025 AI Priorities Study, businesses are pushing ahead with AI deployments to increase internal innovation, boost productivity, enhance customer service, and equip their employees with new tools and capabilities. Companies are keenly aware of AI’s potential — and concerned about possible security risks.
These concerns are well founded. IDC research found that 39% of employees were using free AI tools at work, while 17% were using tools they had paid for privately.[1] These workers may be feeding sensitive data into unsanctioned AI tools. Such behavior could inadvertently break privacy regulations or cause unintended cross-border data transfers.
CIOs and IT leaders want to leverage technologies like AI PCs to create a workforce that can innovate at scale. But they face a dilemma: how can they encourage knowledge workers to explore AI tools confidently — even enthusiastically — while avoiding the clear data risks?
Foundry contacted the CIO Experts Network, a community of IT professionals and technology industry influencers, to find out how the industry is responding.
“IT leaders can drive safe and enthusiastic AI adoption by combining strong governance with user empowerment,” says Vivek Singh, Senior Vice President of IT and Strategic Planning for the IT consultancy, PALNAR. Singh suggests that enterprises need to define clear standards for the responsible use of AI and explain (or educate) employees on how these rules relate to data privacy and compliance.
To build employee trust and compliance, companies need to embed approved AI tools into daily workflows. Dashboards are also useful for ensuring AI processes are explainable and transparent.
Perhaps most importantly, Singh adds, IT leaders need to provide training and engaging hands-on workshops, helping workers develop their AI skills. He suggests that “by balancing safety with usability and showing real productivity gains, leaders can foster a culture of responsible, confident AI adoption.”
Scott Schober, President/CEO at wireless security and cybersecurity specialists Berkeley Varitronics Systems, Inc. agrees. “As a cybersecurity business owner” he notes, “I’ve learned the hardest part is striking the right balance between control and empowerment. IT leaders naturally want their teams to handle technology responsibly, so it helps to put some guardrails in place — things like data protection rules, a shortlist of approved tools, and straightforward security training.” However, he also adds that “in my experience, none of that matters if employees don’t see how the tools actually make their day-to-day work easier.”
The trick, according to Joan Goodchild, cybersecurity journalist and founder of Cybersavvy Media, is to channel employee enthusiasm for AI into sanctioned channels. “Employees are eager to use new tools that make their work easier,” she suggests, “but IT leaders can’t ignore the security and compliance risks.”
Goodchild believes the process starts with strong guardrails, including clear data-handling policies, vetted platforms with built-in privacy protection, and active monitoring to detect misuse. This framework provides the benefits of AI within a secure environment while reducing the chance employees will turn to unsanctioned apps.
Of course, these guardrails only work if they’re neither too rigid nor too proscriptive.
“IT leaders need to ensure that knowledge workers have a smooth, safe, and personal experience with GenAI,” says Kumar Srivastava, Chief Technology Officer at the AI-enhanced R&D platform pioneers, Turing Labs. “If central IT places too many obstructions” he notes, “users will find ways to circumvent IT, which exacerbates the problem.” While guardrails are a necessity, he argues, it’s up to IT leaders to set up GenAI in a way that’s friction-free but still secure.
Use of unsanctioned AI tools isn’t the only risk CIOs face. Peter Nichol, Data & Analytics Leader for North America at Nestlé Health Science, feels that knowledge workers also need to be able to trust the outputs.
“AI can be very confident with incorrect information from hallucinations,” he says. “An AI distorting ‘orders placed’ as ‘orders shipped’ from semantic misalignment is inconvenient, but misinterpreting regulatory clauses could cost millions in penalties.” In industries like healthcare, even mistakes by AI summarization could have a serious impact should errors disrupt treatment pathways and put patients at risk.
The solution, Nichol argues, is layered mitigation, with human workers validating AI-generated work and confidence thresholds to trigger soft-checks before AI errors scale out of control. “AI becomes safe,” he argues, “when treated as a trusted copilot, not an all-knowing autopilot.”
Keeping human expertise in the loop is crucial. Emphasizing this as part of a broader AI communication strategy builds trust, confidence, and encourages employees to view AI as a valuable resource rather than a threat to their livelihoods.
Speaker, advisor, and blogger Arsalan Khan suggests that IT leaders must also “build trust through transparency, clearly communicating how AI will augment — not replace.”
Once people understand the positive potential of AI, it’s important to celebrate emerging use cases and the team members who discover them. “The quickest way to get buy-in is to point to small, practical wins that save time or cut down on busywork,” advises Schober. “When people see the benefits firsthand and know the safeguards are there, they’re much more likely to use new technology both safely and with enthusiasm.”
Khan agrees: “All leaders should also highlight successes, by showcasing who is using AI effectively and what others can achieve, creating a culture of learning and inspiration.”
He believes that this isn’t simply an IT priority. “Safety is provided by IT leaders,” he says, “but creating genuine enthusiasm for AI adoption is every organizational leader’s responsibility.”
In effect, the challenge for IT leaders is making AI part of the everyday fabric, using tools the enterprise sanctions with appropriate controls. Creating these smaller wins builds trust and confidence, encouraging a secure and AI-positive culture.
Moreover, CIOs can also use AI PCs to enhance data security in the AI era. AI PCs (or a hybrid system that combines local and cloud-based servers) also theoretically improve security by ensuring data is never exposed to exfiltration attacks aimed at the cloud.
Accelerate digital innovation with secure AI PCs.
[1] IDC, Shadow AI: How stealth productivity is strangling enterprise AI adoption. And creating a security nightmare, July 2025, https://blog-idceurope.com/shadow-ai-how-stealth-productivity-is-strangling-enterprise-ai-adoption-and-creating-a-security-nightmare/
