Executive Snapshot
Shadow AI and SaaS sprawl are no longer separate operating problems. Both describe technology adoption moving faster than centralized inventory, ownership, access review, and policy enforcement. Recent vendor telemetry, customer datasets, industry research, and public-sector cloud guidance point to the same leadership priority: make usage visible, assign accountable owners, and connect approval decisions to controls that can actually be enforced. [1] [2] [3] [4]
Personal AI Use Has Not Disappeared
Netskope reports that in its 2026 enterprise telemetry, 56% of AI users use only organization-managed AI applications, 14% use both managed and personal apps, and 30% use only personal apps. [1] These figures are specific to Netskope's observed environment, not a universal market benchmark. The leadership implication is narrower: an approved AI program does not automatically eliminate unsanctioned use. Discovery and guardrails still matter after a managed platform is launched.
The Application Estate Keeps Expanding
Okta's 2025 Businesses at Work report, based on its anonymized customer data, says the global average number of apps per customer topped 100 for the first time after 9% year-over-year growth. [2] The number itself will vary by organization, but the control problem is consistent. As app counts rise, security teams need a scalable way to know which services are approved, who owns them, and how access is reviewed.
SaaS Risk Is Spread Across Data, Identity, and Administration
The Cloud Security Alliance's 2025-2026 SaaS security report describes survey-reported challenges that include external data oversharing, sensitive data moving to unauthorized SaaS, fragmented administration, privilege enforcement, and monitoring of non-human identities and API access. [3] The report is survey evidence, not proof that every organization has the same gaps. It is useful because it shows why a single inventory spreadsheet is not enough: ownership, identity, data, integrations, and configuration all need operating controls.
Visibility and Secure Configuration Belong Together
CISA's Secure Cloud Business Applications program was created for federal cloud business application environments, so its scope should not be generalized into a private-sector mandate. Its architecture is still instructive: SCuBA combines visibility guidance, cloud solution guidance, secure configuration baselines, and assessment tooling. [4] The broader lesson is that knowing an application exists and knowing it is securely configured are different controls that should reinforce each other.
AI Is Adding Commercial Pressure to the Portfolio
Zylo's 2026 SaaS Management Index says its dataset covers more than 40 million SaaS licenses and more than $75 billion in discovered and categorized SaaS and cloud spend. Within that dataset, it reports AI-native application spend rising 108%, and 393% among large enterprises. [5] Those figures are vendor dataset observations. For leaders, the relevant question is whether AI purchasing and experimentation can be tied to ownership, policy, and measurable business use before subscriptions and integrations become difficult to unwind.
CyberTech Intelligence Perspective
The next phase of SaaS governance is not simply "more discovery." It is faster conversion of discovery into a decision. A service should move from observed to owned, assessed, approved or restricted, monitored, and eventually renewed or retired. When that path is clear, security does not have to treat every new application as an incident, and business teams do not have to guess how to get a useful service reviewed.
Five Questions for the Next Leadership Review
-
Which AI and SaaS services are in active use but missing from the approved service register?
-
What percentage of the service portfolio has a current business owner and technical owner?
-
Which services can receive sensitive data or connect to enterprise systems through delegated access?
-
Can policy decisions be enforced as approve, warn, restrict, or block at the point of use?
-
When a service is retired, are accounts, integrations, tokens, stored data, and renewal commitments all closed?
Read the Deeper Governance Model
Use these five questions as an executive scan. For the evidence model, readiness domains, and operating roadmap, move next to the CyberTech Intelligence research report for this campaign and compare its governance structure with your current SaaS and AI review process.
About CyberTech Intelligence
CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education, decision support, and claim-safe GTM planning.
Evidence and Citation Note
External sources are used only within their stated scope. Guidance statements are attributed to the issuing organization, survey or telemetry findings are identified as source-specific, and vendor material is used only for that vendor's capabilities or stated observations. CyberTech Intelligence does not infer a current incident, weakness, project, budget, or risk posture for any named organization without direct evidence. Editorial QA control completion: 10/10.
References
- Netskope Threat Labs, “Netskope AI Report: 2026,” 2026. https://www.netskope.com/resources/threat-labs-reports/netskope-ai-report-2026 (Accessed September 21, 2026. Relevance: vendor telemetry on managed and personal AI application use, used only within Netskope's stated observation scope.)
- Okta, “Businesses at Work 2025,” 2025. https://www.okta.com/reports/businesses-at-work-archive/businesses-at-work-2025/ (Accessed September 21, 2026. Relevance: anonymized Okta customer application trends, including average app count and year-over-year growth.)
- Cloud Security Alliance, “The State of SaaS Security: 2025-2026,” 2025. https://cloudsecurityalliance.org/artifacts/state-of-saas-security-report-2025 (Accessed September 21, 2026. Relevance: industry survey findings on SaaS data, administration, identity, API, and enforcement challenges.)
- Cybersecurity and Infrastructure Security Agency, “Secure Cloud Business Applications Frequently Asked Questions,” April 2024. https://www.cisa.gov/sites/default/files/2024-04/CSSO-SCuBA-FAQ-FINAL_508c.pdf (Accessed September 21, 2026. Relevance: federal cloud-business-application guidance describing visibility, cloud architecture, secure configuration baselines, and assessment tooling.)
- Zylo, “2026 SaaS Management Index,” 2026. https://zylo.com/2026-saas-management-index (Accessed September 21, 2026. Relevance: vendor dataset on SaaS licenses, spend, and AI-native application spending trends; figures are used only as Zylo dataset observations.)