Your AI Policy Assumes the Work Is Happening on a Laptop You Own

By David Matalon, CEO and Founder, Venn [ Join Cybersecurity Insiders ]
7

Most AI governance still rests on an assumption nobody states out loud: that the laptop belongs to the company, and that you can isolate and protect the work based on that assumption. This idea is carrying more weight than it can bear. More than a third of skilled knowledge workers in the United States now freelance, 38 percent in 2026, up from 28 percent a year earlier.[2] That is before counting offshore teams, outsourcing agencies, advisers and the remote employee who was never handed a corporate machine, or was forced to use the one they did receive. A great deal of sensitive work is already happening on hardware we do not own and cannot fully manage.

AI did not wait for us to notice. It stopped being a tab in a browser we could govern with a controlled browser. AI installs on the desktop as a native application, and on developer machines it reads the file system and runs commands on the endpoint it lives on. By mid 2026, 90 percent of professional developers were using AI coding agents at work at least weekly, and 68 percent were using them daily.[1] We built controls for a device we controlled and a browser we could manage. Increasingly we have neither.

Offshore teams, outsourcing agencies and remote employees are a permanent fixture

Historically, organizations answered this with one of three tools: ship a laptop, stand up a virtual desktop, or route access through a controlled browser or network path. Each of these has immediate drawbacks. None of them was designed for an AI agent that wants to live natively on the endpoint with access to local files and a terminal. Shipping hardware to every contractor is slow and expensive. A virtual desktop separates the worker from the local tooling that makes an agent useful, but comes at enormous cost, complexity and a poor user experience. A controlled browser has the obvious limitation of not being able to govern AI that is running natively on the desktop. Considering contractors, offshore teams and remote employees are a fixture in today’s workforce, assuming IT owns the device is obviously flawed logic. That doesn’t mean IT needs to run out and buy tons of laptops and ship them around the globe. It just requires them to evolve their governance strategy. Focus on the work, not the device. When IT does not own the device, a governance strategy that ends at the browser is a partial solution. AI is as ubiquitous on the desktop as it is in the browser, and users are taking full advantage.

A major cause of shadow AI: mixing personal and business

In a survey of 1,000 American office workers, 80 percent said they use AI in their roles, but only 22 percent rely exclusively on tools their employer provides.[3]

Policy has not caught up. ISACA’s 2026 poll of more than 3,400 digital trust professionals found that only 38 percent of organizations have a formal, comprehensive AI policy, and a quarter have no active policy at all.[4] One of the most critical policy gaps emerging today is a lack of tenant restrictions limiting access to corporate accounts.

Initially, the risk around AI was whether people were using it at all. Now the risk is which account is being used. The same AI model, reached through a company tenant with logging and data-use terms negotiated by the enterprise, is a governed asset. Reached through a personal login, it is a data exit. Data from one security vendor’s customers makes the point sharply: 62 percent of connections to browser-based AI tools from their managed workspaces were made through personal, non-corporate accounts. When customers configured their tenant restriction settings, the share dropped to 5 percent.[5]

Five principles for governing AI on any device

If the account is the problem and the device is often not ours, the governance model has to change shape.

First, govern the data, not the machine. It is too easy to exfiltrate data from a device, so a governance strategy relying on device ownership provides a false sense of security. Considering the prevalent use of freelance knowledge workers, organizations must assume most work is being done on computers they do not manage. The control boundary has to sit around the company’s data and applications, wherever they run.

Second, as personal and professional AI use blends, organizations must apply context-aware controls to ensure work accounts only process work data. Tenant restrictions, which allow approved AI services to be reached only through company-provided accounts, convert the single largest shadow AI vector into a governed one.

Third, reuse the access policies you already have. Most organizations already limit sign-ins to trusted networks or dedicated IP ranges for their productivity and CRM platforms. AI services deserve the same conditional access, not a separate rulebook. For systems that blend personal and professional usage, ensuring that only trusted connections reach corporate AI tools is critical.

Fourth, treat native AI applications and coding agents as first-class citizens of the policy. Whatever controls apply to AI in the browser, including limits on copy and paste, upload, download, screenshot and print, should apply equally to the desktop app and the agent in the terminal.

Fifth, embrace AI usage across your organization. The survey data is consistent: when workers are not given a capable, approved AI, they bring their own.[3] Governance that only says no produces shadow AI. Governance that provides the best available tools inside a controlled boundary removes the reason for it.

Where this lands

The organizations that get this right will not be the ones with the longest list of banned applications. They will be the ones that decided, early, that AI is a force multiplier that unlocks scale and efficiency across the organization. However, no force multiplier should be deployed without proper safeguards. The key is evolving controls to align with how the business actually runs. In a landscape filled with contractors, offshore teams and remote employees, AI governance must focus on the data, not the device.

_____

About David Matalon

David Matalon is the CEO and Founder of Venn, the secure remote work company. He previously co-founded OS33, the market-leading secure workspace solution for SEC and FINRA-regulated financial firms.

 

 

Join our LinkedIn group Information Security Community!

No posts to display