Omnissa Report Reveals ChatGPT Dominates Shadow AI Use
A new report from digital work platform Omnissa reveals that workplace AI assistant use grew by nearly 1,000 percent in 2025, exposing critical security and device management gaps.

Omnissa's State of Digital Workspace 2026 Report, which analyzed telemetry from millions of managed devices across 17 industries, found that AI assistant adoption grew by close to 1,000 percent during 2025. While Microsoft Copilot leads on IT-managed mobile devices, ChatGPT dominates unapproved environments. The OpenAI chatbot is installed on 91 percent of unsanctioned iOS devices and 61 percent of unsanctioned Android devices, with Google Gemini capturing most of the remaining Android shadow market.
The report highlights a strong correlation between shadow AI adoption and poor security hygiene, particularly in regulated sectors. For instance, healthcare exhibits high exposure to unsanctioned apps alongside slow patching and unencrypted desktops. Across industries, 23 percent of banking desktops, 27 percent of healthcare and high-tech desktops, 28 percent of media and entertainment desktops, and 20 percent of government desktops are unencrypted. In education, over half of all desktop and mobile devices lack encryption. Furthermore, iOS devices update eight times faster than Android, and macOS updates 1.5 times faster than Windows. Healthcare, pharmaceuticals, and retail have the highest concentrations of Android devices running four or five generations behind.
For IT practitioners, these vulnerabilities are compounded by device performance issues. Windows desktops experience 3.1 times more forced shutdowns and 7.5 times more unresponsive application states than Macs, which can severely disrupt resource-heavy on-device AI workloads. Meanwhile, regulatory relief has arrived as EU negotiators delayed the high-risk obligations of the AI Act under Annex III from August 2026 to December 2027, though transparency rules still take effect in August 2026.
This delay gives enterprise security leaders more time to integrate their data. Practitioners must move away from isolated dashboards and instead unify AI usage tracking with endpoint health metrics like encryption status and patch levels. Written policies alone cannot stop employees from using faster, unapproved tools; security teams must gain complete visibility to manage the compounding risks of shadow AI and aging hardware.
This is our own summary of reporting by Unite.AI



