IT Support in the Age of AI: Shadow AI, Access, and Accountability.
Today, nearly every employee uses AI in their work. They share data with it and grant it access to systems. Meanwhile, they approve integrations that IT isn’t even aware of. In the meantime, these tools have crossed a line: they no longer just make suggestions—they take action.
In this webinar, we’ll take a look at what’s actually running on your company’s systems today, who has access to them, and what happens when an automated process goes wrong. Who is responsible, and what evidence remains in the logs afterward?

Shadow AI is about taking the initiative, not breaking the rules: a colleague opens a tool in the browser, and by the afternoon, the report is ready. They don’t ask for permission because there’s no one to ask. However, company data and system access have still left the premises.
By 2029, 70% of companies may be using agentic AI to operate their IT infrastructure.
In 2025, this percentage was still below 5%.
Source: Gartner, "Predicts 2026: AI Agents Will Transform IT Infrastructure and Operations" (December 4, 2025).
By 2028, 40% of I&O organizations that deploy large-scale agent-based operations in a live environment may experience business-critical service outages. In 2026, this percentage is still below 1%. As AI becomes more autonomous, operational control becomes increasingly critical.
Source: Gartner, 2026 Hype Cycle for AI in IT Operations (July 2026).
97% of organizations that experienced an AI-related data security incident lacked adequate access controls. In other words, in many cases, the problem was not the AI itself, but rather the fact that there were no adequate controls in place to regulate who could access the systems and data and what they could access.
Source: IBM, Cost of a Data Breach Report 2025.
The goal of the webinar is not only to highlight trends but also to provide a decision-making framework that you can apply to your own IT environment.
How to find out which AI tools are currently in use at your organization—and why banning them is the fastest way to see even fewer of them.
Which data types can be exported and which cannot, and how can this be enforced through technical controls rather than relying on a policy?
Entra ID app registrations, OAuth authorizations, “Sign in with a Microsoft account”: what an external AI integration actually sees, and how to review this regularly.
Agentic tools perform operations in a live environment. What frameworks are needed to support them: authorization limits, approval points, and recoverability.
What remains in the logs after an AI-initiated operation, and what can you identify from this during an investigation?
Who is responsible for what: the user, the in-house IT department, or the service provider? Where is the line drawn, and what needs to be addressed in the contract?
This webinar is primarily intended for IT decision-makers at medium and large companies who, in addition to the day-to-day operation of their infrastructure, are also responsible for its development, automation, security, and future-readiness.
This is particularly relevant when:
Are you a CIO, CTO, IT Director, or IT Operations Manager;
They operated a Microsoft 365, Azure, or hybrid enterprise environment;
You are exploring AI and automation opportunities in IT;
A small in-house IT team manages a complex corporate infrastructure;
you want to determine which processes are worth automating;
It is important to you to clearly manage authority, decision-making points, and responsibilities;
You are preparing for a broader enterprise rollout of Copilot or other AI tools;
You'd like to start preparing your IT operations now for the changes that will come in the next few years.
01 | Shadow AI
Reconnaissance methods, typical entry points, and why blocking doesn't work.
02 | Data and Access
Data Classification in Practice, OAuth Authorizations, Review of App Registrations.
03 | AI in the Microsoft Work Environment
Copilot, agent-based workflows, permissions, SharePoint content, identities, and corporate data access.
04 | When an Agent Makes a Mistake
Permission limits, approval points, logging, and rollback. All of this through a specific scenario.
05 | Accountability and Support Model
What should be handled in-house, what should be outsourced, and what needs to be addressed in a contract.
Gloster has been developing, modernizing, and operating enterprise IT systems for more than two decades, while serving as the local enterprise partner for the world’s leading cloud, security, and AI companies. As a partner of Anthropic, we see agentic AI from the inside: we work with it every day in our clients’ systems, and we see where it can cause harm.
years of experience in enterprise IT and software delivery
expert at an international organization
Region: Hungary, England, Germany, and the U.S.
A company listed on the Budapest Stock Exchange




In addition to designing and operating enterprise Microsoft environments, we also work with leading vendor partners in the areas of cloud, networking, and security.
The starting point is corporate IT operations, not a specific technology. We’re examining how to keep everything under control while AI is already in use:

László Földesi is the head of the Gloster Cloud business unit, which designs and operates the Gloster Digital Group’s enterprise Microsoft 365, Azure, and hybrid infrastructures.
His areas of focus include production readiness, cloud architecture, security and compliance, and scalable systems.
In the webinar, he’ll show what he sees in day-to-day operations: how far AI tools have come in a corporate environment, what kinds of access permissions they operate under, and what happens when an automated process doesn’t go as planned.
Fill out the form, and we will confirm your registration via email within 48 hours and send you the information you need to participate.