AI AI Tech Trends

70% of Enterprise AI Is Uncontrolled — Lenovo Research Reveals a Growing AI Execution Gap Driving Hidden Risk, Cost, and Slower ROI

AI  /  AI Tech Trends  |  4 min read


Lenovo (HKSE: 992; ADR: LNVGY; Morrisville, North Carolina; a US$69 billion revenue global technology powerhouse; ranked #196 in the Fortune Global 500; serving millions of customers in 180 markets), has published Leading Your Workforce to Triumph with AI — the fifth report in its Work Reborn Research Series, and the first focused on the employee perspective. Based on a survey of 6,000 full-time employees at enterprise organisations (1,000+ employees) conducted in December 2025 and January 2026 across the US, Canada, UK, France, Germany, India, Japan, Singapore, Brazil, Mexico, Australia, and New Zealand, the report reveals a structural AI governance crisis: more than 70% of employees are using AI weekly, with up to one third operating beyond IT oversight. At the same time, 80% expect to increase their reliance on AI within the next year — a trajectory that will deepen the governance gap further unless organisations act now.

"AI adoption is no longer the challenge. Execution is. Usage is growing faster than organisations can control or secure it. Without that control, AI introduces as much risk and cost as it does opportunity."

— Rakshit Ghura, Vice President and General Manager, Digital Workplace Solutions, Lenovo

The AI Execution Gap — Shadow AI, the Two-Speed Workforce, and a Widening Attack Surface

Employees are using AI with or without IT involvement — fuelling the rise of shadow AI across the enterprise and creating structural gaps in governance and control. The consequences are already visible and measurable. Uncontrolled AI is creating delayed ROI as AI initiatives remain fragmented across teams; duplicated spend as multiple tools solve the same problems in silos; an increased attack surface as unsanctioned tools access enterprise data; and a lack of visibility that makes it impossible to scale what works. The workforce impact is equally significant: AI adoption is uneven, with some employees operating within secure, optimised environments while others rely on whatever tools they can access to stay productive. This creates a two-speed workforce — slowing decision-making, duplicating effort, and making consistent enterprise-wide AI adoption difficult to achieve. The security risk compounds the operational one: 61% of IT leaders report a rise in cybersecurity threats linked to AI, yet only 31% feel confident in their ability to manage those risks. Meanwhile, 43% of employees are worried about AI-driven data exposure or attacks. Without clear governance, AI is quietly expanding the enterprise attack surface — increasing the likelihood of breaches, compliance failures, and operational disruption.

Lenovo's Response — Control at the Device, Security as a Service

Most organisations are trying to manage AI across disconnected layers — devices deployed and managed one way, infrastructure managed another, security layered on after. That fragmentation is precisely what creates the AI execution gap. Lenovo's approach establishes control at the point where AI first enters the enterprise: the device itself. From there, Lenovo connects device deployment, lifecycle management, infrastructure, and security into a single, governed operating model delivered through TruScale Device as a Service for Security. The offering combines enterprise-grade devices secured from day one, built-in device and firmware protection through Lenovo ThinkShield, advanced endpoint security from leading partners, and 24/7 managed security services including monitoring, detection, and response — all as a single, end-to-end managed service. The result: reduced risk through proactive always-on threat monitoring, elimination of gaps between device security and operational security, simplified vendor management, lower total cost of ownership, and internal IT and security teams freed up to focus on higher-value initiatives. More than 70% of employees already recognise AI's potential to drive gains in productivity, speed, and quality — and organisations that close the AI execution gap can move from fragmented experimentation to measurable outcomes faster.

The UK and European Dimension — EU AI Act Compliance and the Regulatory Urgency

For UK and European organisations, the AI governance gap carries an additional and more immediate dimension: regulatory compliance. With the EU AI Act now coming into force — setting new standards for governance, transparency, and risk classification across AI deployments — businesses operating in the UK and EU will need to demonstrate clear governance, accountability, and risk management for every AI system in use. Yet current patterns of adoption suggest many are far from prepared to meet these requirements. Shadow AI — where employees use AI tools without the knowledge or involvement of IT teams — is particularly problematic in a regulatory context: governance frameworks cannot cover tools that are invisible to the compliance function. The consequence is a direct exposure risk. Organisations that cannot demonstrate how AI is being used, what data it is accessing, and who is accountable for its outputs face potential regulatory sanction under the EU AI Act — on top of the operational costs already created by ungoverned adoption. Lenovo's TruScale Device as a Service for Security is designed to close this gap at the point of entry: by establishing control at the device level before AI tools reach enterprise data, organisations can build the audit trail and governance layer that regulatory compliance requires — without disrupting the productivity benefits that AI adoption delivers.

Key Takeaways

  • Lenovo (HKSE: 992; $69B revenue; #196 Fortune Global 500; 180 markets; VP and GM Digital Workplace Solutions: Rakshit Ghura) has published Leading Your Workforce to Triumph with AI — the fifth Work Reborn Report, and first focused on the employee perspective. Survey: 6,000 full-time employees at enterprise organisations (1,000+ employees); December 2025–January 2026; US/Canada/UK/France/Germany/India/Japan/Singapore/Brazil/Mexico/Australia/New Zealand. Announced 27 April 2026.
  • Headline findings: 70%+ of employees are using AI weekly; up to one third operating beyond IT oversight (shadow AI). 80% expect to increase reliance on AI within the next year — a trajectory that will deepen the governance gap. Business impact of uncontrolled AI: delayed ROI (fragmented initiatives); duplicated spend (multiple tools solving same problems in silos); increased attack surface (unsanctioned tools accessing enterprise data); lack of visibility (inability to scale what works). Two-speed workforce: uneven AI adoption slows decision-making, duplicates effort, prevents consistent enterprise-wide adoption.
  • Security findings: 61% of IT leaders report a rise in cybersecurity threats linked to AI; only 31% feel confident in their ability to manage those risks; 43% of employees worried about AI-driven data exposure or attacks. Without clear governance, AI is quietly expanding the enterprise attack surface — increasing likelihood of breaches, compliance failures, and operational disruption. The AI execution gap: usage is accelerating, but control is not keeping pace — described as no longer just an IT challenge but a CISO-level concern expanding across devices, endpoints, and data flows.
  • Lenovo's solution — TruScale Device as a Service for Security: control established at the device (where AI first enters the enterprise); then connects device deployment+lifecycle management+infrastructure+security into a single governed operating model. Components: enterprise-grade devices secured from day one + Lenovo ThinkShield (built-in device and firmware protection) + advanced endpoint security from leading partners + 24/7 managed security services (monitoring/detection/response). Delivered as a single end-to-end managed service — not an assembly of multiple vendor tools. Flexible as-a-service model aligns AI investment with actual demand; reduces upfront costs; avoids duplicated spend; scales as AI adoption evolves.
  • Strategic significance: the report marks a pivotal framing shift — from "AI adoption is the challenge" to "AI execution is the challenge." With 70%+ adoption already in place and 80% planning to increase reliance, the enterprise AI problem in 2026 is not uptake but governance. The gap between employees using AI and IT controlling AI is the structural risk that is simultaneously degrading security posture, slowing ROI realisation, and creating duplicated cost. For UK and European organisations this urgency is compounded by the EU AI Act — now coming into force with requirements for governance, transparency, and risk classification across AI deployments. Shadow AI directly conflicts with these requirements: ungoverned tools are invisible to compliance functions. Lenovo's device-first, as-a-service approach repositions itself not as a hardware vendor but as the managed security and governance layer for AI at the enterprise endpoint — a market position with direct relevance for CISOs, CIOs, and CFOs managing AI spend, regulatory risk, and compliance simultaneously.
Tags: AI News Enterprise AI AI Tech Trends Cyber Security AI Governance Artificial Intelligence News