Across the Gulf, generative AI is no longer confined to innovation labs or isolated pilots. Banks are embedding copilots into internal systems. Government entities are building sovereign AI environments. Energy companies are testing AI-driven operational models across industrial infrastructure. Enterprises are under pressure to automate reporting, customer operations, software development, and internal workflows quickly enough to justify rising AI investment.
At the same time, regulators across the region are placing greater scrutiny on data handling, visibility, and sovereignty. The UAE’s Personal Data Protection Law (PDPL), Saudi Arabia’s localisation priorities, and frameworks such as NESA are forcing organisations to think more carefully about where sensitive information resides, how it moves, and who retains visibility over it once AI systems enter the equation.
What many enterprises are now discovering is that AI adoption is spreading much faster than governance.
Employees are feeding confidential financial information into public AI tools to accelerate reporting. Developers are pasting proprietary code into external AI assistants. Legal teams are testing contracts through generative AI systems. Customer data, operational records, and internal presentations are increasingly moving through AI tools that security teams may not even know employees are using.
The issue has become widely referred to as Shadow AI, though the term understates how deeply embedded these tools already are inside enterprise workflows. Unlike earlier waves of shadow IT, AI capabilities now sit inside browsers, APIs, collaboration platforms, SaaS applications, embedded assistants, and personal devices.
“Shadow AI has forced a conversation that many organizations were not ready to have,” says Mohammed Hilili, General Manager – Gulf, Lenovo. “When employees use unsanctioned AI tools, data leaves the enterprise perimeter without any audit trail, any governance policy, or any visibility into where it resides.”

For organisations operating under increasingly strict sovereignty obligations, the implications extend beyond conventional compliance exposure.
“In markets like the UAE and Saudi Arabia, where data sovereignty is not just a preference but a regulatory and national security consideration, that is an acute challenge,” says Hilili. “As enterprises are faced with confronting the potential implications of Shadow AI, the conversation shifts from ‘how do we adopt AI’ to ‘how do we know what AI is already being used, by whom, and at what risk.’”
Security operations teams are encountering the same issue from a different direction.
“AI governance is no longer only about productivity or compliance; it has become a cybersecurity and operational resilience issue,” says Ezzeldin Hussein, Senior Director, Solutions Engineering, SentinelOne. “Employees are increasingly using public AI tools outside approved governance frameworks, often without understanding where enterprise data is being processed, stored, or reused.”
Most Shadow AI exposure is not being created through deliberate attempts to bypass governance controls. Employees are using AI tools because the tools work.
Public AI platforms can summarise reports, automate coding tasks, draft presentations, analyse spreadsheets, and accelerate administrative work in seconds.
“The primary driver is speed and accessibility,” says Hussein. “Employees see immediate productivity value from AI tools, while governance frameworks and enterprise-approved alternatives often move much slower.”
Executive leadership is contributing to the acceleration as well. “The driver is productivity pressure, and it comes from the top as well as the bottom,” adds Hilili. “Leadership pushes teams to demonstrate AI value quickly, and employees reach for whatever tools deliver results fastest.”
Inside many organisations, governance visibility has not kept pace with actual usage patterns. “Most organizations cannot produce an audit trail of what data was submitted to which AI platform and by whom,” explains Hilili. “Under PDPL, that is a data handling accountability failure. Under NESA, the inability to demonstrate visibility and control over data flows is a governance gap that auditors are beginning to probe.”
The sovereignty implications become especially serious once employees begin interacting with public AI platforms outside approved enterprise environments.
“Employees using public AI tools have no mechanism to verify where their inputs are processed or stored, which directly conflicts with sovereignty obligations that apply to certain categories of government-adjacent and financial data in this region,” adds Hilili.
Many organisations technically prohibit unsanctioned AI usage through acceptable-use policies. Enforcement, however, remains inconsistent.
“A written policy without enforcement is not a defensible position when a regulator asks for evidence of control,” he says.
Security teams are increasingly shifting toward runtime governance models capable of monitoring AI activity continuously rather than relying solely on static controls.
“The biggest governance gaps are emerging around Shadow AI discovery, data classification, identity governance, runtime visibility, and policy enforcement,” says Hussein. “Many enterprises simply do not know which AI platforms employees are using, what data is being shared, or whether those interactions align with sovereignty requirements and regulations such as UAE PDPL.”

That visibility challenge is pushing enterprises toward AI-aware monitoring models designed specifically for generative AI interactions. “This is where platforms like SentinelOne Prompt Security become critical because they provide real-time observability, policy-based AI controls, sensitive data protection, and AI governance capabilities without forcing organisations to completely block innovation,” explains Hussein.
Why legacy security is struggling
Shadow AI is exposing blind spots inside enterprise security architectures that were designed long before conversational AI entered operational workflows.
Traditional shadow IT usually involved unmanaged applications or devices that could eventually be identified through asset discovery systems or infrastructure monitoring tools. AI interactions behave differently because they are woven directly into normal business activity.
“Shadow AI operates differently because employees can instantly access AI capabilities through browsers, plugins, APIs, SaaS platforms, collaboration tools, or even embedded enterprise applications with minimal visibility from security teams,” says Hussein.
The exposure itself is also harder to detect. “The challenge becomes even greater because AI interactions are conversational and behavioural,” says Hussein. “Sensitive information can be exposed through prompts, AI-generated outputs, automated workflows, or AI-to-AI interactions in ways traditional detection tools were never designed to inspect.”
The weakness becomes especially visible inside conventional DLP and perimeter-monitoring environments.
“DLP catches file transfers and email attachments. Network monitoring sees encrypted HTTPS traffic heading to a recognized AI endpoint and classifies it as clean,” explains Hilili. “Neither tool sees a paste event.”
Most employees interacting with generative AI systems are not uploading documents manually. They are copying and pasting information directly into prompts.
“No file moves. No alert fires. The data is simply gone,” says Hilili.
He adds: “The endpoint is where data originates and where control is often lost. Once an employee copies sensitive content into a browser tab and submits it to an external AI platform, that data has left the enterprise environment with no record and no retrieval mechanism.”
Security operations teams are increasingly shifting toward observability and runtime monitoring frameworks built for AI-driven activity. Modern SOC operations require AI-aware observability platforms capable of detecting Shadow AI usage, monitoring prompt activity, enforcing runtime policies, identifying prompt injection risks, and tracking AI-related data exposure across endpoints, browsers, APIs, and enterprise workflows.
“This is one of the core areas addressed by SentinelOne Prompt Security, which provides visibility into AI usage, real-time policy enforcement, prompt monitoring, protection against prompt injection attacks, and controls to prevent sensitive data leakage across employee AI usage, AI code assistants, homegrown AI applications, AI agents, and AI red teaming initiatives,” explains Hussein.
How sovereignty changes the architecture
In the region, soveregin AI initiatives are beginning to reshape procurement priorities across cloud, edge, and endpoint infrastructure.
Governments and enterprises increasingly want AI workloads, models, and sensitive data to remain inside national jurisdictions.
“Sovereignty requirements make on-device and on-premises inference capabilities non-negotiable for a growing segment of enterprise and government workloads,” says Hilili. “When data cannot leave a jurisdiction, the inference must happen within it.”
That shift is steadily moving governance closer to the endpoint itself.
“PCs must function as governance nodes with the management and telemetry capabilities to surface what is leaving and from where, not just a compute surface,” says Hilili. “That is a design requirement, not an add-on.”
As enterprises move toward local inference and sovereign AI environments, endpoint visibility and integrity are becoming procurement priorities rather than secondary security considerations. “ThinkShield provides that foundation, from silicon-level security to firmware integrity and endpoint management,” Hilili adds. “For organizations in the Gulf operating under data residency obligations, this is not a future consideration. It is a current procurement requirement.”
Security teams are also recognising that outright bans on AI usage rarely survive contact with operational reality once employees begin depending on these tools for productivity.
“Blocking alone is rarely effective because AI adoption is being driven by genuine business demand, operational efficiency, and competitive pressure,” says Hussein. “When organisations simply ban AI tools, employees often move toward unmanaged alternatives outside governance visibility, increasing overall risk rather than reducing it.”
Across the region, enterprises are now trying to accelerate AI adoption while maintaining sovereignty, runtime visibility, and governance control across increasingly distributed AI environments.
“The focus should shift from ‘stopping AI’ toward creating trusted AI environments where innovation and security can coexist,” says Hussein.






Discussion about this post