Most enterprises still make a binary call on AI: block it, or let it run and hope nobody notices. Two Gartner research notes published a week apart make the case that the binary itself is the risk, not the fix. Here’s what both reports say, where Gartner named Pluto Security in each, and what the shift means for the AI security controls you’re building this year.

The Case for Stronger Endpoint Controls

The newly published Gartner research describes a clear gap: employees and developers are adopting AI agents, browsers, and AI tools faster than security teams can see or control them.

Shadow AI Demands Stricter Endpoint Application Control (Gartner, 25 May 2026, Evgeny Mirolyubov, Deepak Mishra, Ashish Suraj Bhan) argues that unsanctioned AI use on managed endpoints has outgrown the controls most teams have in place.

Use the SAFE Framework to Secure AI Agents and Browsers in Endpoints (Gartner, 2 June 2026, Franz Hinner, Evgeny Mirolyubov) is a companion note offering a phased model for allowing AI experimentation under control instead of banning it.

Key Takeaways

  • The shadow AI note finds that 69% of organizations suspect or have evidence that employees are using prohibited public AI services, and calls for stricter endpoint application control paired with dedicated AI usage control.
  • The SAFE note introduces SAFE Lanes, a four-stage model that moves AI experimentation from isolated sandboxes to controlled production use instead of a blanket ban.
  • Gartner named Pluto Security as a sample platform in both notes: for AI usage control and DLP, and among specialized AI security providers for developers.
  • The throughline for security leaders: block-or-allow no longer holds, and the fix is stronger controls at the endpoint, built on the stack teams already run.

The shadow AI paper puts it bluntly: “Not all AI usage can be detected or controlled by the cybersecurity organization.” Its fix is stricter application control and privilege management paired with dedicated AI usage control, across employee, developer, and vendor-embedded AI alike. The SAFE note conveys the same premise: “AI agents and browsers compress human intent into machine-speed automation,” and answers it with SAFE Lanes: staged environments each with their own identity, data, and telemetry boundaries.

What This Means for Security Teams Today

The practical message is that banning AI is no longer a strategy, it’s a blind spot. Block a sanctioned tool without a safer path, and the same activity reappears in personal accounts and unmanaged browsers your controls can’t see. Both reports point the same way: put stronger controls on the endpoint you already manage.

In practice, that means:

  • Treat every endpoint as an AI endpoint, and inventory the agents, browsers, extensions, and MCP servers already running on them.
  • Pair stricter application control and privilege management with dedicated AI usage control, instead of expecting one tool to do both.
  • Enforce at runtime, not just at discovery, so risky tool calls and data movement are stopped as they happen.

How Pluto Meets the Moment

Pluto is the AI Workspace Security Platform, delivering full visibility across the AI tools people use, the ecosystem behind them, and the artifacts they generate, alongside contextual risk and policy enforcement on every endpoint.

That’s what Pluto shows you at the endpoint: what your workforce is using, where the real exposure sits, and how to stay in control without slowing anyone down.

  • Full discovery. Every AI tool, ecosystem, and app the workforce touches, down to the data underneath.
  • Context-grounded risk. Every finding tied to how it connects, how it’s configured, and what data it reaches, so real risk cuts through the noise.
  • Real-time enforcement. Controls that act the moment risk appears, without blocking the work underneath.

AI has already turned every endpoint into an open-ended workspace. Pluto gives security teams a way to say yes to innovation instead of just saying no to risk.

Book a demo with the Pluto team to see how it applies to your reality.

Gartner, “Shadow AI Demands Stricter Endpoint Application Control,” Evgeny Mirolyubov, Deepak Mishra, Ashish Suraj Bhan, 25 May 2026.

Gartner, “Use the SAFE Framework to Secure AI Agents and Browsers in Endpoints,” Franz Hinner, Evgeny Mirolyubov, 2 June 2026.

GARTNER is a trademark of Gartner, Inc. and/or its affiliates.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.