Three-Quarters of AI Tools on Company Devices Were Never Approved
Published on 09/30/2026 at 03:04 | Editorial boerse-global.deOmnissa unveils an "authority layer" for AI governance as surveys reveal how far unsanctioned tools have spread through the enterprise
ORLANDO, Florida — A new product category is taking shape around a problem most IT departments have only recently started measuring: the AI tools employees install and use without anyone's blessing.
At its Omnissa ONE 2026 event here, Omnissa introduced Elara, a platform it describes as an "authority layer" meant to give companies back a measure of control over AI use that is expanding far faster than policy can keep up. The product is currently in beta.
The case for such a system rests on numbers Omnissa itself has gathered. AI assistant use on endpoints jumped by nearly 1,000 percent year over year. Roughly 75 percent of the tools found on company-managed devices have not been officially approved — three out of every four, in other words, operating outside IT's knowledge or consent.
German executives confirm the pattern
Independent research points the same direction. A summer 2026 survey by the firm VIER found that 77 percent of German companies have unofficially used AI tools running without verified oversight. Among the executives polled, 32 percent openly acknowledged shadow AI use on their watch, while 17 percent admitted they could not gauge how widespread it was in their own areas of responsibility.
Elara attacks the visibility problem at the endpoint. The system processes about 50 terabytes of endpoint data daily and supports 150 million workflow executions per month. Its beta feature set includes detecting where AI is being used, setting guardrails through a dedicated AI gateway, controlling model access and token consumption, and producing audit-ready evidence for compliance teams.
An Okta report from 2026 illustrates how far that visibility gap reaches: only 47 percent of surveyed security leaders said they could confidently identify every individual AI agent in their environment. Organizations with mature identity governance, Okta found, report markedly less shadow AI.
Budgets leak, rollouts stall
Enthusiasm for the technology has not translated into smooth deployment. Freshworks reported in spring 2026 that 83 percent of IT decision-makers at German mid-sized companies intend to raise their AI spending over the next one to two years. Yet an average of 25 percent of global AI budgets disappears into complex workflows and governance obstacles, and German IT teams spend roughly 27 percent of their AI-related working hours on integrations and troubleshooting.
Timelines tell a similar story. For 61 percent of German mid-sized businesses, implementing AI takes six to twelve months. Just seven percent have so far embedded the technology across multiple core business areas.
Regulation raises the stakes
The regulatory picture tightened when the EU AI Act became largely applicable in August 2026. Analysis by ISG finds that documentation, auditability and control of sensitive data have moved to the center of compliance work. High-risk systems — in HR management, for instance — face strict requirements for risk management and human oversight.
German constitutional law adds its own limits, particularly in the judiciary. Under current case law, the Grundgesetz requires that decisions be made by a natural person; a fully automated process, or AI as the sole route to public services, is not permissible.
Against that, the SANS Institute advises companies to adopt a zero-trust approach to AI agents — maintaining a detailed agent inventory and assigning each agent its own identity, so that accountability and access rights can be managed consistently.
