IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
When security creates friction, employees find workarounds

When security creates friction, employees find workarounds

Fri, 11th Sep 2026 (Today)
Patricia Leppert
PATRICIA LEPPERT Team Manager Customer Trust & Security TeamViewer

Security is meant to protect the business. But when it gets in the way too much, it can do the opposite. That challenge is becoming increasingly visible across Asia Pacific, where organisations are embracing AI and digital transformation at different speeds, while employees are under growing pressure to work faster and smarter.

For many employees across the region, security still feels like something that gets in the way. It might be a password reset at exactly the wrong moment, an approval process that holds up a project, or a blocked app that turns a simple task into a headache. These controls usually exist for good reasons. But when they're not built around how people actually work, they end up pushing employees towards the exact behaviour the business is trying to stop.

Shadow AI is a symptom of workplace friction

Shadow AI is a clear example of this. Employees are under pressure to work quickly while managing more information than ever. If approved systems are difficult to access, limited in functionality or unclear, people may turn to personal devices, public AI platforms or unsanctioned applications.

In most cases, this is not malicious. Employees are trying to solve a problem, whether that is meeting a deadline, responding to a customer or keeping a project moving. That is what makes shadow AI so difficult to manage. The same instinct that drives productivity can also create hidden exposure.

Our Digital Friction Report found that 40% of employees worldwide admit to using personal devices or apps as a workaround when work technology fails. In APAC, the numbers swing widely: in India, that figure climbs to 66%, the highest of any country in the study. In Japan, it drops to just 22%, the lowest. Australia sits in the middle at 38%. For leaders, this should be a wake-up call. Workarounds are no longer rare exceptions. They are becoming part of everyday working behaviour.

The risk is not only that employees use tools the business has not approved. It is that these behaviours reduce visibility. Organisations cannot govern what they cannot see, and they cannot secure activity that sits outside official systems. When too much security friction pushes work into unmanaged environments, it can make the business less secure, not more.

A security issue

Shadow AI is often framed as a technology problem, but that only tells part of the story. It is also a sign that security, governance and employee experience are not working together effectively.

Sensitive information could be entered into platforms that have not been approved or monitored, while teams may start relying on outputs or tools that sit outside official oversight. Yet focusing only on the tool can miss the wider issue. Shadow AI often appears because the approved route feels too slow, unclear or disconnected from the task at hand.

Employees may not know which tools they are allowed to use. They may be unsure what information can safely be entered into an AI platform. In some cases, the sanctioned tools simply do not support the way a team needs to work.

Leaders should treat this as a signal, not just a policy failure, but a design failure. It shows where employees are experiencing friction and where security may be creating gaps rather than closing them.

Poor digital experiences create business risk

That friction comes at a real cost. The research found 80% of people lose time to broken IT, around 1.3 workdays a month on average worldwide. Across APAC, that number swings a lot: India loses the most of any country in the study, at 1.9 days a month. Japan loses the least, at under a day a month, the only country in the study where that happens.

It's hurting business performance too. Almost half of respondents globally say digital friction has delayed important projects or operations.

What starts as everyday frustration can quickly become a wider business problem, slowing teams down and weakening trust in workplace technology. The challenge is to make the secure route the practical one, with controls that support how people actually work rather than interrupting it.

Security needs to enable productivity

Security should enable productivity, not compete with it. That means making secure processes clear enough to follow and practical enough to fit into daily workflows. When security feels intuitive, employees are far more likely to engage with it.

Authentication is a useful example. Passwords have long been a source of frustration for employees, as well as a known weakness for organisations. Moving towards approaches such as zero trust and biometric authentication can strengthen protection while improving the user experience. The strongest controls are often the ones that feel almost invisible to the people using them.

Trust is central to this. That lack of confidence matters: 57% of workers do not trust their IT team to resolve issues quickly or effectively, while 47% fear their IT team will not adequately protect personal or work-related data. If employees do not trust that official routes will meet their needs, they are more likely to find their own.

There's also a growing trust gap around AI. Globally, 62% of employees don't feel confident their IT team is giving them the latest AI and digital tools. Across APAC, attitudes towards technology and workarounds vary widely, suggesting that going around IT is not simply a matter of trust, but also one of speed, convenience and how people prefer to work.

AI governance must be part of daily work

This is where governance becomes critical. AI tools can enter an organisation through different teams, often for different reasons. A small productivity experiment can quickly become part of a core workflow, even if no one has clearly defined who owns the risk.

As adoption grows, that governance gap becomes harder to ignore.

Businesses need clearer responsibility for how AI is used and secured. Security teams have an essential role, but they cannot solve this alone. AI governance has to become part of the organisation's operating model, rather than a policy that sits separately from day-to-day work. This requires a shift in mindset, making responsible AI use part of everyday decisions and behaviours.

Human oversight is also essential. AI can process information at speed, but it does not understand every business context or reputational consequence. People are needed to challenge AI outputs and take responsibility for decisions that carry real-world impact.

For employees, this needs to translate into practical guidance. They should understand which tools are approved and what information should never be entered into them. That guidance also needs to be available when people need it. A policy that is difficult to find or hard to interpret will not change behaviour.

Building that trust also requires diverse perspectives in how security is designed. Teams that reflect different working styles and expectations are better equipped to create systems that are inclusive, usable and resilient in practice. Security cannot be designed for a single type of user if it is meant to work in practice.

Across Asia Pacific, governments are taking different approaches to AI governance. While regulations continue to evolve, businesses cannot afford to wait for every rule to be finalised before addressing how AI is used inside their organisations.

Reducing shadow AI starts with understanding the cause

Reducing shadow AI starts with understanding why employees are using unsanctioned tools in the first place. Leaders need to look closely at where approved systems fall short and where security is being introduced too late.

Too often, security is brought in after a tool or process has already been adopted. By that point, controls can feel like an extra layer rather than a natural part of the workflow. A security-by-design approach changes this. It brings security into the conversation earlier, so risks can be addressed before behaviours become embedded.

Transparency is another crucial ingredient. Customers, partners and employees increasingly want to understand how organisations are using AI and how data is being protected. Therefore, security can no longer sit behind the scenes as a black box.

Internally, that transparency is just as important. Employees are more likely to follow security guidance when they understand why it exists and how it supports the wider business. A policy that simply says "do not use this tool" is unlikely to be enough. People need context and confidence that the approved route will help them do their jobs effectively.

Cybersecurity conversations usually focus on outside threats. But businesses also need to look at the risks building up inside their own walls, most of which come from good intentions, not bad ones. So what does shadow AI really tell us? Not that employees are breaking the rules, but that workplace systems need to keep pace with how people actually work. Across Asia Pacific, reducing risk will depend on making secure tools practical, accessible and easy to use.

The businesses that succeed will not be those with the strictest rules. They will be the ones that make doing the secure thing the easiest thing to do.