New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"
A LayerX Security report reveals that enterprise AI risk is heavily concentrated among a small group of ‘AI power users’ rather than being evenly distributed across all employees. The report highlights the fragmented nature of AI usage, with many organizations lacking visibility into how AI is being utilized, particularly through personal accounts and consumer-driven platforms like ChatGPT. This creates a significant governance challenge as organizations struggle to track and manage the growing ‘shadow AI’ ecosystem.
The LayerX Security report, titled ‘State of AI Usage Report 2026,’ identifies a concerning trend: enterprise AI risk isn't spread broadly but is heavily concentrated within a small percentage of users – specifically, the top 5% who generate significantly more AI interactions than the majority of employees. These ‘AI power users’ engage in deeper conversations, utilize multiple AI platforms, and employ complex prompt chains, creating a disproportionate amount of exposure. This contrasts with the common perception that ‘everyone’ is using AI, as only 18% of enterprise users interact with AI on a weekly basis, with the majority being casual users.
The report emphasizes the fragmented nature of the AI landscape, with users leveraging a diverse range of tools including ChatGPT, Copilot M365, and Gemini, often through personal accounts and unmanaged environments. This ‘shadow AI’ – encompassing AI browser extensions, embedded copilots, and AI-powered SaaS features – presents a significant governance challenge, as organizations often lack visibility into how data is handled and whether prompts are used for model training. The rise of consumer-driven AI adoption, particularly through platforms like ChatGPT, exacerbates this issue.
Furthermore, the report highlights that the traditional definition of ‘Shadow AI’ – employees using unapproved chatbots – is outdated. The reality is a ‘long tail’ of AI tools operating outside of established governance controls, with nearly 30% of enterprise users utilizing multiple AI platforms and the top 5% interacting with six or more. This complexity makes it increasingly difficult for organizations to track, manage, and secure their AI usage, demanding a shift in governance strategies.
