Why Shadow AI Creates Insider Risk in Microsoft 365 ft. Gabriel Friedlander
In the age of AI, the “insider” is no longer human, and that changes the insider-threat model. Majorly.
In this episode of Demystifying Microsoft, Nathan Taylor speaks with Gabriel Friedlander, Founder and CEO of Wizer and former founder of ObserveIT, about shadow AI, identity-less AI workers, the limits of traditional access monitoring, and why human oversight becomes even more important as organizations give AI systems greater autonomy.
Organizations tend to approach AI risk from one of two directions: restrict it heavily or encourage adoption quickly. Gabriel Friedlander, Founder and CEO of Wizer and former founder of ObserveIT, sees problems with both.
In this episode of Demystifying Microsoft, Nathan and Gabriel discuss why organizations are dealing with a new category of insider threat, how security awareness needs to evolve alongside it, and why IT leaders should establish a baseline of actual AI usage before reaching for controls. They also look at what happens next because AI may increase what a team can produce, but that makes governance more important, not less.
What You’ll Learn:
- Why banning AI can push legitimate work into personal accounts
- How shadow AI develops even among well-intentioned employees
- Why AI workers introduce a different type of insider threat
- Where identity and observability become difficult with autonomous agents
- Why AI cannot be expected to apply human common sense to sensitive data
- How malicious and unintentional insider-threat models are expanding
- How short, continuous security training can improve engagement
- Why security guardrails should support AI adoption rather than stop it
- Why human oversight remains central as AI systems become more autonomous
About the Guest:
Gabriel Friedlander is the Founder and CEO of Wizer, a security awareness platform used by approximately 20,000 organizations.
Gabriel has spent more than a decade focused on insider threat prevention, human behavior, and security awareness. Before Wizer, he co-founded ObserveIT, an insider threat detection and prevention company that was acquired by Proofpoint. His work now focuses on helping organizations make security training more effective as new risks, including shadow AI and AI-driven insider risk, change how employees interact with company data.
About the Host:
Nathan Taylor is Senior Vice President and Global Microsoft Practice Leader at Sourcepass, where he leads the Sourcepass Center of Excellence for Microsoft, also known as the Sourcepass MCOE. With nearly two decades of experience, he helps organizations manage complex Microsoft cloud and security decisions by turning technology into secure, scalable outcomes.
Episode Highlights:
05:48 AI Bans Lead to Underground Usage
Gabriel explains why companies that believe employees are not using AI can easily lose visibility instead. When approved tools are unavailable, employees may bring personal AI accounts into the workflow to keep pace with expectations.
09:09 AI Workers Are the New Insider-Threat Model
AI agents can access data, take actions, and make decisions, but they may not have the identities and monitoring structures IT expects from human workers. Gabriel argues that this creates a genuine insider-risk problem.
16:46 Start With an AI Risk Baseline
Before assuming policy is working, Gabriel recommends finding out what employees are actually doing: which tools they believe are approved, whether personal accounts are involved, and whether people know where to go with questions.
20:48 Why Security Training Needs to Get Shorter
Gabriel explains Wizer’s approach to awareness content: roughly 90 seconds, direct, useful, and stripped of repetition. If the audience has to watch, that does not mean the content should stop competing for their attention.
25:38 Security Should Help AI Move Faster
Gabriel compares security with brakes on a car. Their purpose is not simply to slow things down; they make speed safer. The same principle applies to AI governance.
Episode Resources:
Quotes:
- “You’ve got a worker. You’ve got a real insider threat in the company.”
- “When it comes to AI, they don’t have common sense.”
- “We cannot offload decision-making. We have to be part of it.”
- “We’re not here to slow anyone down. We’re here to make businesses go faster without crashing.”