The AI skills gap you are worried about is not a curriculum problem. It is a visibility problem: your people are already using AI, often heavily, and almost none of that activity shows up in whatever skills audit or training rollout your leadership team is planning. You cannot close a gap you cannot measure.
Ask most executives how many of their employees use generative AI regularly, and they will guess low. McKinsey surveyed C-suite leaders and employees at the same companies and found leaders estimate that only 4 percent of employees use generative AI for at least 30 percent of their daily work. Employees reported the real number at 13 percent, more than three times higher. That gap sits underneath every skills program built on the assumption that leadership already knows where its workforce stands.
No. The employees creating the most exposure for your organization right now are usually not the ones who feel unprepared to use AI. They are the ones who taught themselves outside any sanctioned system, using tools IT never evaluated, because the approved path was too slow or too limited for the work in front of them.
Microsoft and LinkedIn's Work Trend Index found that 78 percent of AI users bring their own AI tools to work, a practice researchers call BYOAI, and it shows up just as often at small and mid-sized companies as at large enterprises. More than half of those employees, 52 percent, hesitate to admit they use AI for their most important tasks, and 53 percent worry that visible AI use will make them look replaceable. High usage paired with active concealment is exactly why a curriculum-first response misses the real problem. You would be training a population whose actual behavior you cannot see and whose members have reasons not to tell you about it.
In the client environments we work in, this pattern shows up as two distinct groups sitting side by side on the same team. One employee has quietly become the AI power user, drafting proposals, summarizing calls, and building spreadsheet formulas faster than anyone else, without ever mentioning it because there was no reason to. The other has not opened an AI tool once and has no plan to. From the outside, both employees look equally "trained," because neither has gone through a formal program. Underneath, one has real, tested capability and the other has none, and no training rollout built on an average will serve either of them well.
Because the activity happens outside anything your organization monitors. It moves through personal accounts, browser extensions, and free-tier chatbots that never touch a device management policy or a procurement review, so there is no log, license record, or admin console showing you what is actually happening.
Gartner surveyed cybersecurity leaders in early 2025 and found that 69 percent already suspect or have direct evidence that employees are using public generative AI tools at work. That figure describes leaders who know something is happening and still cannot say what, by whom, or how often. Gartner also projects that more than 40 percent of enterprises will face a security or compliance incident tied to unauthorized AI use by 2030, and it names skills erosion, the quiet loss of institutional judgment as people lean on tools instead of building expertise, as one of the blind spots most likely to go unaddressed until it becomes a visible failure.
The business cost of that invisibility is not only security exposure. It is that nobody is correcting bad habits while they are small. An employee who has taught themselves to accept AI output without checking it looks, from a manager's seat, identical to one who has built a careful review process around every draft the tool produces. Both are quietly shaping how work gets done across your team, and without visibility into what either of them is actually doing, you have no way to reinforce the good pattern or catch the risky one before it becomes how your whole department operates.
Because a rollout built for an average employee masks two very different populations. Some employees have already built real, if unstructured, AI capability on their own, and a beginner-level course wastes their time and tells them leadership is behind. Others have not touched AI at all and will not be pulled forward by a policy memo, no matter how clearly it is written.
IDC's research on AI and enterprise skills found that only 36 percent of organizations mandate AI or GenAI awareness training in the first place, which means most companies are relying on employees to opt into the very programs meant to close this gap. IDC ties the broader skills shortage to direct financial impact too, estimating it will cost the global economy up to $5.5 trillion by 2026 in delayed projects, missed revenue, and lost competitiveness, with 62 percent of IT leaders reporting the shortage has already cost them revenue growth.
Closing a split-population problem like this is not something a generic course library solves. It takes a program built around your organization's actual usage patterns, which is the starting point for every AI services engagement we run with clients: find out what is really happening before you design what happens next.
Put next to each other, the data points above describe a consistent pattern. What leadership tends to assume about AI use inside their own organization does not hold up against what the research actually finds.
| What Leadership Typically Assumes | What The Data Shows |
|---|---|
| Employees will wait for a sanctioned tool before using AI | 78% of AI users already bring their own tools to work |
| AI use is limited to a small, easily tracked group | Employees report daily AI use at more than 3 times the rate leaders estimate |
| A training rollout, once launched, is generally being used | Only 36% of organizations mandate AI awareness training at all |
| Unapproved AI use is rare enough to not be a governance issue | 69% of cybersecurity leaders suspect or have evidence of it happening now |
Visibility first, then structure. You need an accurate picture of what your people are already doing with AI before you can decide what to train, restrict, or formalize, and that picture has to come from more than a policy acknowledgment form employees sign once and never think about again.
A practical starting point is running our cybersecurity assessment to establish a baseline of where AI tools and other unmanaged technology already touch your environment, rather than building a training plan on top of guesswork about who uses what.
Notice that none of this starts with a course catalog. Role-based training only works once you know which role is doing what. A finance employee summarizing vendor contracts with AI needs different guardrails and different skill-building than a marketing employee drafting client-facing copy, and a generic, one-size-fits-all module misses both. Once you have a real usage baseline, training stops being a compliance checkbox and starts being a way to raise the floor for the employees who have not started yet while giving the self-taught power users a formal structure that actually adds value to what they already know.
If you are also evaluating security vendors or tools as part of this process, our cybersecurity buyer's guide walks through the questions worth asking before you commit budget, so the tool you approve actually holds up against the same scrutiny you are now applying to shadow AI.
It is both, and treating it as only one is why the gap keeps widening. Training without visibility produces confident employees using tools nobody has reviewed. Governance without training produces policies people route around because the sanctioned path cannot keep up with their actual workload.
Pew Research Center found that among workers who received any job training in the past year, only about a quarter of that training involved AI, and 35 percent of employed adults rate AI skills as extremely or very important, compared to roughly 70 percent who say the same about communication and critical thinking. That is not evidence employees do not value capability. It is evidence AI training has not yet been built into the core skill set most people are actively developing, which leaves individual employees to decide on their own, without oversight, how much to lean on AI and for what.
McKinsey's broader research on AI readiness found that 70 percent of employees feel personally ready to use AI, while only 27 percent of leaders believe their own organization is ready to support that shift. Closing that 43 point gap is not about pushing employees to adopt AI faster. They already have. It is about building the visibility and structure that lets the organization catch up to where its people already are. Concretely, that means a usage baseline instead of a guess, a training cadence that gets revisited as tools change instead of a one-time rollout, and a feedback loop that lets you find and fix risky habits before they spread across a team.
The skills gap this article describes will not close through a course catalog. It closes when you can see how your people are actually using AI today and build training and guardrails around that reality instead of a guess.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.