For the last four years, organisations have been racing to put guardrails around generative AI. But new data suggests the conversation has overlooked one important detail: mobile devices have become a primary gateway to enterprise data and identity.
According to a survey from Lookout and ZK Research, 52% of generative AI usage now takes place on mobile devices. But only 41% of organisations say they can actively monitor mobile AI traffic – which means 59% of activity is bypassing traditional security visibility.
The findings suggest AI adoption has shifted faster than many enterprise security strategies.
AI has already gone mobile
It’s unsurprising that employees are turning to smartphones to use AI. Your phone is always in reach – and it’s powerful, and it’s packed with AI-enabled applications that promise to make everyday tasks easier.
So people are summarising emails on the commute; translating documents during a client meeting; recording and transcribing conversations. Mobile is very much part of the working day.
The problem is that most enterprise AI governance programmes were designed around laptops and browsers. Traditional security controls rely on traffic passing through secure web gateways, proxies or corporate networks. According to the report, many mobile AI applications communicate directly with cloud services in ways that can bypass these traditional inspection points.
And all of this is creating a visibility gap that keeps getting wider. While 93% of security leaders say they are confident in their AI governance, only 41% report having the technical capability to actively monitor mobile AI traffic. Confidence and visibility, it seems, are not always the same thing.
The AI you don't know you're using
The report also brings to light a less obvious problem. Instead of existing as standalone AI assistants, AI is being embedded into the apps that employees already use every day.
Think photo editors, productivity tools, note-taking apps, travel applications and meeting recorders – they’re all rapidly integrating generative AI capabilities through third-party software development kits (SDKs). Many users don’t even realise these features are present, let alone understand where their data is being processed.
And this presents a serious governance challenge. According to the survey, 72% of organisations can’t identify or audit embedded AI SDKs inside mobile applications.
In practice, that means sensitive corporate data could be processed by AI services embedded within otherwise trusted mobile applications – and security teams don’t have clear visibility into how that information is being accessed, processed or shared.
The report also found that organisations estimate employees are already using an average of 27 AI-powered applications, while 14% report more than 50 AI apps in active use across their workforce. Managing that level of software sprawl is difficult enough when applications are known and approved – but it becomes even harder as more software introduces embedded AI capabilities.
From mobile devices to mobile identities
The rollout of autonomous AI agents raises the stakes even more: 68% of organisations admit they have no technical visibility into AI agent workflows running on user devices.
The report argues that smartphones fundamentally reshape the risk equation because they consolidate corporate identities, authenticated sessions, MFA credentials and OAuth tokens. As AI agents gain greater access to these resources, mobile devices are becoming critical control points for enterprise security.
Rethinking AI governance
So organisations need to rethink where AI governance begins.
If employees increasingly interact with AI through smartphones (and if AI capabilities are appearing inside everyday mobile applications), then governance can’t focus on controlling browsers, laptops, and network traffic.
Equally, the solution isn’t going to lie in blocking access to individual AI tools. Instead, the next phase of AI governance will depend on understanding:
- What AI is doing on mobile devices
- Which applications are using it
- How corporate data moves between them
Because as well as changing how people work, the AI revolution is changing where they work. For cybersecurity professionals, this means we have to make sure mobile AI doesn’t remain a blind spot.
Learn from the world’s leading cybersecurity practitioners at Black Hat MEA 2026. Find out how they’ve solved the problems you’re facing today. Register now.