Cybersecurity Teams Struggle With Rapid AI Adoption

Rapid, decentralized adoption of AI tools is outpacing what corporate security teams can see or control, Fortinet Executive Vice President Robert May said at a Fortinet event in Montreal, according to BetaKit. May said many companies "don't even know the problem that they're dealing with" because employees now use "thousands of tools" beyond central IT's visibility, up from mostly ChatGPT two years ago. BetaKit cites a McKinsey survey on broad enterprise AI adoption and Fortinet's own 2026 Cybersecurity Skills Gap research, which found only half of surveyed leaders believe their boards are "fully aware" of AI-related risks. May warned that AI tools now touch companies' most sensitive data and that understaffed security teams are reacting to live usage rather than setting guardrails in advance, citing potential source-code exposure as one example. For security and ML-ops teams, this signals a widening gap between AI adoption speed and the discovery, classification, and governance tooling needed to manage it.
Rapid, decentralized AI adoption shifts the locus of security risk from central platforms to individual workflows and endpoints. For security engineers, SREs, and ML-ops teams, that means more blind spots where sensitive data, prompts, or generated artifacts can leak outside monitored pipelines, raising the operational burden for discovery, classification, and response.
What happened
BetaKit reports that Fortinet Executive Vice President Robert May, who oversees the Fortinet Security Fabric platform, spoke at a Fortinet event in Montreal about the operational pressure AI is placing on security teams. May said companies "don't even know the problem that they're dealing with," and that two years ago AI usage was largely limited to tools like ChatGPT, but today employees use "thousands of tools," often without IT visibility. BetaKit also cites a McKinsey survey on broad enterprise AI adoption, and references Fortinet's own 2026 Cybersecurity Skills Gap Global Research Report - based on more than 2,750 IT and security decision-makers across 32 countries - which found only half of surveyed leaders believe their boards are "fully aware" of AI-related risks. May warned that AI tools are touching firms' most sensitive data and pointed to code-writing tools as an example, saying exposure there "would make your whole value proposition... public."
Technical context
Decentralized AI usage creates three interlocking problems for defenders: discovery (identifying which models and SaaS agents are active), data classification (detecting sensitive content in prompts and outputs), and telemetry correlation (connecting API usage back to identities and services). These are familiar gaps from past shadow-IT and shadow-SaaS waves, which typically produced delayed detection and higher cleanup costs.
Industry context
Fortinet's report finds six in 10 respondents cite finding cybersecurity staff with AI-specific experience as their biggest hiring challenge, compounding the discovery problem: security teams are simultaneously short-staffed and facing a new category of risk they don't yet have the specialized skills to monitor.
What to watch
Useful signals include inventories of third-party AI integrations, adoption of enterprise API gateways or CASB-style controls for model APIs, and whether boards or risk committees begin publicly documenting AI governance frameworks.
Key Points
- 1Fortinet EVP Robert May says employees now use thousands of unmonitored AI tools, up from mostly ChatGPT two years ago, per BetaKit.
- 2Only half of surveyed leaders believe their boards are fully aware of AI risks, per Fortinet's 2026 Cybersecurity Skills Gap report.
- 3Security teams face compounding discovery, classification, and staffing gaps, since 6 in 10 cite AI-specific hiring as their top challenge.
Scoring Rationale
A named Fortinet executive's on-record warning, backed by Fortinet's own multi-country skills-gap survey, is a concrete and directly practitioner-relevant governance signal, but it is a vendor-adjacent conference talk about an already well-known shadow-AI risk pattern rather than a new technical development, so it sits mid-notable rather than upper-notable.
Sources
Primary source and supporting public references used for this report.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problems
