Malik Haidar is a veteran in the cybersecurity trenches, known for bridging the gap between high-level business strategy and the gritty reality of threat intelligence. Having protected multinational infrastructures for years, he understands that the biggest vulnerabilities often aren’t found in the code itself, but in the palm of an employee’s hand. He specializes in the intersection of mobile productivity and data sovereignty, helping organizations navigate the complex landscape of the modern workplace. Today, he breaks down the double-edged sword of enterprise mobile AI—where the promise of eliminating repetitive work meets the potential for catastrophic data exposure.
The following discussion explores the rise of “Shadow AI” and the psychological drivers that lead employees to bypass security protocols for the sake of efficiency. We delve into the unique risks posed by mobile devices as they transform into AI-integrated endpoints and the architectural shift required to keep corporate intelligence within the right hands.
Employees often use unauthorized AI tools to summarize sensitive meeting notes or draft emails just to stay productive. How does this “Shadow AI” phenomenon differ from the old shadow IT problems we’ve seen in the past?
Shadow AI is remarkably similar to the old shadow IT waves where people used unauthorized file-sharing apps, but the stakes have shifted from where data is stored to how it is processed. When an employee asks an AI to summarize a transcript, they aren’t just uploading a file; they are essentially handing over a notebook full of trade secrets to the “world’s smartest intern.” The concern isn’t necessarily malicious intent, as most workers are simply trying to eliminate the repetitive work that quietly steals hours from every week. However, according to IDC, 42% of organizations now cite the loss of control over data and IP as the primary barrier to adopting generative AI. This is a people problem where convenience beats policy every single time, creating a visceral risk because once that information is fed into a public model, you’ve lost the “notebook” forever.
With AI becoming a staple of the mobile experience—used while commuting or between meetings—why should IT leaders treat mobile security differently than desktop AI security?
The reality of the modern workplace is that work happens wherever people are, whether they are walking between meetings, traveling, or sitting in an airport café. Smartphones have evolved from mere communication tools into full-fledged AI devices that gain access to the same deep layers of business information as the operating system itself. Employees are now using their cameras to search for information, translating live conversations on the go, and joining calls from customer sites where sensitive data is out in the open. This level of intimacy and constant access means that if AI capabilities aren’t governed specifically for mobile, they become a massive leak point for managed corporate identities. We have to realize that the mobile endpoint is now the primary interface for AI interaction, making its security architecture more critical than the laptop on a desk.
You often emphasize that processing location is a security control rather than just a technical detail. Why is the “on-device” versus “cloud” distinction so critical for protecting corporate data?
Processing location is the first line of defense because it determines whether sensitive data ever has to leave the physical hardware in the first place. When AI tasks can run directly on the device, you eliminate a transmission step, which means there is one less environment to trust and one less place for a breach to occur. It’s a powerful feeling for a security lead to know that a product roadmap or a sensitive summary stayed within the device’s secure enclave rather than hitting the open cloud. While not every complex AI feature can run locally yet, the ability to manage which ones do is becoming a cornerstone of enterprise governance. Organizations must have the visibility to know exactly where the work is being done to confidently claim their data is secure.
Many organizations rely on employee training to manage AI risks, but you’ve suggested that technical controls are superior. How can companies take the decision-making out of the hands of the end-user?
Relying on thousands of employees to make the right security decision every single time they use an AI tool isn’t a strategy; it’s a massive gamble. The shift must move from policy-based governance to technical controls that centralize decision-making within the IT department. By using platforms like Samsung Knox, for instance, IT teams can manage supported AI features across an entire fleet and ensure that AI use is strictly tied to managed corporate identities. This ensures that if an employee leaves the company, the chat history, generated content, and organizational knowledge stay within the firm rather than disappearing with a personal account. Identity architecture is now just as vital as access management because it determines who truly owns the “corporate brain” being built through these AI interactions.
If a governance model is only as strong as its foundation, what is the one underlying assumption that most security leaders are overlooking right now?
The most dangerous assumption is that the device itself can be trusted by default, regardless of what AI features you layer on top. If the underlying hardware or operating system has been compromised, every high-level policy or encryption layer becomes significantly less convincing. This is why we argue that enterprise AI security must begin with the architecture, specifically hardware-and software-based protection from the chip up. At Samsung, we’ve integrated Galaxy AI features onto the Knox foundation to ensure that there is a “trusted device” reality before any data is processed. Security leaders need to stop looking at AI as a standalone feature and start asking if their foundation can answer where a summary lives and who controlled the policy behind it.
What is your forecast for the future of trustworthy AI in the enterprise?
The future belongs to the organizations that stop chasing the most AI features and start prioritizing platforms designed with governance in the DNA. We are going to see a major shift where “Trustworthy AI” becomes the only acceptable standard, as companies realize that even the smartest assistant is a liability if it’s not sitting on a trusted device foundation. I predict that within the next few years, the distinction between “on-device” and “cloud” processing will be the primary metric by which CIOs judge their security posture. Ultimately, the success of AI in the workplace won’t be measured by productivity gains alone, but by whether the organization can confidently hand over the “notebook” of its secrets to the AI without fear of losing it. My advice is to pause and ask those four critical questions about processing, cloud governance, identity, and hardware trust before rolling out any new capability.

