Hidden AI Use Is Creating a New Blind Spot for Enterprise Security Teams
- 4 minutes ago
- 2 min read
Artificial intelligence is spreading through corporate environments faster than security teams can track it, and new research suggests the biggest risks may be hiding outside traditional cybersecurity controls.
Fable Security analyzed 90 days of security telemetry covering approximately 290,000 employees across more than 30 organizations during the second quarter of 2026. Its inaugural AI Behavior Index found that 34 percent of workers had a detectable generative AI application, account, plugin, model, or agent.
That figure captures only the AI tools security systems can readily identify, such as ChatGPT, Claude, and Cursor. When Fable examined established business applications that now include AI features, the potential exposure expanded dramatically.
More than 91 percent of employees were enrolled in at least one application with built-in AI capabilities. Nearly 55 percent had access to role-specific software with recently added AI functions, even after Fable excluded broad productivity platforms such as Microsoft 365 and Google Workspace.
For security teams, an employee using an AI assistant inside Excel, Salesforce, Workday, or Snowflake may look virtually identical to someone using the application without AI. Sensitive information can still reach an AI model, but the activity occurs through trusted software and domains.
The behavioral findings were equally complicated. Employees with detected AI access were 36 percent less likely to be missing multifactor authentication, 43 percent less likely to generate a data loss prevention alert, and 21 percent less likely to become repeat phishing-link clickers.
Yet those same employees were 3.2 times more likely to engage in unsafe browsing and 3.7 times more likely to be overdue on compliance training.
The risk also changed sharply by department. AI-enabled legal, risk, compliance, and human resources employees were 23.5 times more likely to be classified as problematic phishing-link clickers than non-AI colleagues in comparable roles. They were also 5.3 times more likely to leave threat briefings incomplete.
AI-enabled technology workers were 3.7 times more likely to browse unsafely and 3.8 times more likely to fall behind on compliance training than their same-role peers.
Finance provided a counterexample. Although AI-enabled finance employees browsed unsafely more often, they were approximately 73 percent less likely to lack MFA or generate a new DLP alert.
Fable cautioned that its research identifies correlations, not proof that AI causes risky behavior. Detection coverage also varied among participating organizations.
Still, the findings expose a widening enterprise security gap. Companies have spent years hardening email, identity, and data-loss controls, but AI adoption is shifting risk toward employee behavior inside trusted applications. Security teams may now need to inventory embedded AI features, monitor AI-related browser activity, and tailor training by job function instead of treating every AI user as carrying the same risk.


