Somewhere in your organisation right now, an employee is pasting client data into a chatbot. You probably won't find out. That's the uncomfortable finding at the centre of Cisco's 2025 Cybersecurity Readiness Index: 60% of organisations don't know the specific requests their employees make to generative AI tools.
It's not a training problem or a policy problem. It's a visibility problem — and it sits underneath every other AI security control a company thinks it has.
The Blind Spot Isn't the AI. It's the Traffic.
Enterprise AI adoption moved fast. Governance didn't. Employees adopted GenAI tools for drafting, coding, summarising and research long before security teams had a way to see what was flowing through them.
The result is a gap between what organisations assume is happening and what they can actually observe. Cisco's index puts a number on it: most organisations cannot name the prompts their own staff are sending.
Why "We Have a Policy" Isn't the Same as "We Have Control"
Most enterprises have an acceptable-use policy for AI. Far fewer can enforce it. You cannot block, log, redact or investigate activity you never captured in the first place.
That's why the report treats visibility as the prerequisite — not one control among many, but the layer everything else depends on. Data loss prevention, audit trails, incident response and compliance reporting all assume you can see the event.
How the Gap Opened So Quickly
Traditional monitoring was built for known endpoints, sanctioned applications and predictable network paths. GenAI broke all three assumptions.
Employees use browser-based tools that need no installation. Prompts travel over encrypted connections to third-party APIs. Sensitive context — customer records, source code, legal drafts — moves in plain text inside a chat window that no legacy tool was designed to inspect.
Adoption outran instrumentation. By the time governance caught up, the activity was already routine.
Who Feels This First
Security leaders carry the immediate burden, but the exposure spreads wider. Compliance teams cannot evidence what they cannot log. Legal teams cannot assess breach scope without a record of what was shared. Boards are being asked to sign off on AI risk they have no data to quantify.
And employees themselves are often unaware they're creating risk — most are simply trying to work faster with tools nobody explicitly banned.
What Security Teams Are Being Told to Do
The guidance emerging from the report is unglamorous but practical: instrument before you restrict. Build AI-specific visibility — which tools are in use, by whom, how often, and what categories of data are involved — before drafting enforcement rules that can't be measured.
That means treating AI activity as its own telemetry stream, not an extension of existing web or endpoint monitoring. It also means accepting that some usage will be legitimate and productive, and designing controls that distinguish risk from routine work.
Reading the 60% Correctly
The figure is a readiness signal, not a breach count. It measures what organisations can observe, not what has already gone wrong.
It's also self-reported, which cuts both ways: some organisations may be underestimating their own exposure, while others may simply lack the tooling to answer the question accurately. Either way, the direction is consistent — visibility is behind adoption.
Confirmed vs Unclear
Confirmed: Cisco's 2025 Cybersecurity Readiness Index reports that 60% of organisations do not know the specific requests employees make to GenAI tools. The report frames visibility as foundational to AI security.
Unclear: The precise breakdown by industry, company size or geography is not established here. Whether this figure has improved or worsened year-on-year is also not confirmed in the material available.
Where the Real Risk Sits
The danger isn't that employees use AI. It's that organisations are making security decisions — risk acceptance, incident response, regulatory attestation — on incomplete information.
There's also a governance cost to overcorrecting. Blanket bans push usage further underground, making visibility worse. The harder path is measured: observe first, then govern what you find.
This Is a Pattern, Not an Incident
Every major technology shift has produced the same sequence — adoption, then exposure, then instrumentation. Cloud computing followed it. Mobile did too. Shadow IT was the rehearsal for shadow AI.
The difference this time is speed. GenAI moved from novelty to daily workflow in under two years, leaving far less room for the usual catch-up cycle.
What Security Leaders Should Do Now
Start by answering a basic question honestly: can you list the GenAI tools your employees actually use? If not, that's the first gap to close.
From there, the practical sequence is to inventory AI usage, classify the data categories involved, establish logging that survives an audit, and only then layer policy and enforcement on top. Visibility first. Control second.
What Happens Next
Expect AI visibility to move from a security team concern to a board-level metric, the way cloud spend and third-party risk did before it. Regulatory pressure on AI data handling is likely to make unlogged AI activity harder to defend.
Organisations that instrument early will find governance far cheaper than those trying to reconstruct what happened after an incident.
Our Take
The 60% figure is uncomfortable precisely because it's mundane. It doesn't describe a dramatic breach — it describes a routine blind spot that most organisations haven't yet prioritised.
The real insight in Cisco's index isn't that AI is risky. It's that visibility has quietly become the price of admission for every other AI security promise a company makes. Without it, policies are aspirational and audits are guesswork.
Frequently Asked Questions
What is enterprise AI visibility?
It's an organisation's ability to see which AI tools employees use, what data they share with them, and how often — typically through logging and monitoring built specifically for AI activity.
Why can't traditional security tools track AI usage?
Most legacy tools were built for installed software and known network paths. Browser-based GenAI tools need no installation and send prompts over encrypted connections to third-party APIs, which traditional monitoring wasn't designed to inspect.
What did Cisco's 2025 Cybersecurity Readiness Index find?
It reported that 60% of organisations do not know the specific requests employees make to GenAI tools, highlighting a gap between AI adoption and AI governance.
What should organisations do first to improve AI visibility?
Inventory actual AI tool usage before writing enforcement policy. Logging, data classification and audit-ready records should come before restrictions, since controls can't be enforced on activity that isn't captured.