Skip to content
Article

Your peers' AI tools are multiplying. Governance isn't.

By DoGood Team · June 18, 2026

Member Signal

The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on June 18, 2026, and appears here lightly edited for the web.

The Signal

The DoGood network’s AI security activity has concentrated in one direction over the last 90 days: tool sprawl that has outpaced governance by at least two quarters.

The most direct data point from the last 30 days: one software VP has six AI coding tools officially sanctioned, including GitHub Copilot, Claude Code, Cursor, Lovable, and Google AI Studio, and is still working out how to govern any of them. Another member has 1,300 software engineers building on AI coding assistants without consistent SDLC review. A third has a board mandate and $100M+ in annual AI budget in motion, with security governance still being designed.

Members are not waiting for governance programs to catch up before deploying AI tools. They’re deploying first and figuring out controls after. That’s a different problem than most AI security vendors are solving for.

Vendor Watchlist — 30 Days

Vendor Member mentions
Microsoft (Entra ID, M365 Copilot) 7
ChatGPT / Claude / AI assistants 5
Amplifier Security 2
ServiceNow 2
Salesforce 2
Strivacity 2

Microsoft leads by a wide margin, mostly as the environment being governed rather than the solution. The fragmentation across five AI tools in a single submission is the real signal: the stack is not converging, and no single AI governance vendor has captured it.

From the Network

“We’ve got a large variety of coding agents; github copilot, claude code, cursor, plus lovable and Google AI studio are all officially allowed. Trying to wrap our arms around it all.”

VP-level, Software

“We have multiple AI initiatives. All over the place and need more vendors. 100M+ annually in budget for various new AI initiatives.”

Senior Director, IT Operations, Software

“We have a directive from our board to involve more AI in our operations where it can make an impact.”

Senior Director, IT Operations, Software

Three stages of the same problem: tool accumulation, investment pressure, and board mandate. In that order.

Top Open Priorities

“GRC team is responsible for a LOT of TPRM across the city. We need something that helps us not have to send questionnaires every year and HOPE they respond (with factual information).”

Head of Risk & Compliance (Deputy CISO), Government

“We are building a new system that requires tight security controls and have always struggled with identifying gaps and keeping in sync with CIS and other security frameworks. We need assistance in ways that we haven’t seen in the market yet.”

Senior Director ITIO & Cybersecurity, Hospitality

The first is a TPRM automation ask with a live budget cycle attached. The second is a framework-sync problem surfacing in a new-build context: the ask for capabilities the market hasn’t built yet shows up more in construction and hospitality than most vendors expect.

Member Spotlight

Bradley Schaufenbuel, VP & CISO, Paychex. When Paychex’s AI governance review was running at eight weeks, Bradley made a call: compress it to two. He assessed that the market risk of slowing AI innovation exceeded the security risk of the faster process and moved accordingly. That’s the lens he’s built a career on, and he put it plainly in his DoGood Member Spotlight: “Your success isn’t measured by how good a security expert you are. It’s measured by how well you help your peers succeed.”

Read his full story →

Deep Dive: AI Security & Governance

29 member submissions touched AI security and governance in the last 90 days, split across four clusters at different points in the buy cycle.

Where activity is concentrated

Shadow AI discovery is the largest cluster. Most programs haven’t completed a full inventory of AI tools running in their environment. Members cite visibility into unsanctioned AI as a precondition for everything else. This is stage zero, and most organizations are still there.

AI coding tool risk is the second-largest. The exposure isn’t the coding assistant itself: it’s AI-generated code entering production without the same review gates as human-written code. With 1,300-engineer shops running multiple assistants, the volume of AI-assisted commits is too large to review manually.

Agentic security is an emerging cluster. Members with deployed copilots and LLM-connected workflows are hitting a new problem: agents operating with limited human oversight and an incomplete audit trail. The ask is guardrails, not just visibility.

AI governance and policy enforcement is the fourth cluster, driven by board mandates, framework rollouts, and regulatory prep. The budget is real. The challenge: most governance frameworks are 12-18 months behind actual deployment patterns.

What your peers are buying

Vendor activity in this category is CISO-level and active:

Vendor Activity
Onyx Security CISO meeting · June 4
Heeler VP/CISO meeting · June 3
Amplifier Security 2 CISO-level meetings · May–June
DeepTrust CISO meeting · June 5
Blackbird.AI Head of IDM Risk · June 10

What’s still open

AI coding tool risk: the specific capability members need is a governance layer that can sit inside the SDLC pipeline and flag AI-generated code changes without adding friction at scale. Heeler and Amplifier Security are the most active vendors in this space, but the product maturity members are asking for isn’t there yet.

Agentic security frameworks: the ask is a governance layer for deployed agents across multiple LLM providers. It doesn’t exist as a single product. Members are stitching together solutions.

If you haven’t done a shadow AI inventory in the last 60 days, do one before Q3 planning. The gap between what IT has sanctioned and what employees are running is wider than most members estimated when they first checked.

The Context

The headlines are catching up to what the network already knew.

At RSAC 2026, Microsoft announced browser-level shadow AI detection in Edge for enterprise, flagging unauthorized AI tool use before data leaves the device. The announcement confirmed what the network has been working on for months: platform vendors now treat shadow AI as a detection-layer problem, not just a policy problem.

By the time those browser controls roll out broadly, the governance program they’re designed to support is the part that still needs building.

Bottom Line

Platform vendors are solving for detection. Your peers are learning that detection without an enforcement policy is another dashboard no one acts on.

What to Do About It

Schedule a shadow AI audit before Q3 planning starts. Pull all OAuth tokens and browser extensions in use across your environment: most AI tools authenticate this way and won’t appear in a standard SaaS inventory. Cross-reference against your acceptable use policy. The gap between what you’ve sanctioned and what’s running is your Q3 risk conversation.

Build pipeline you can actually follow up on.