{"id":26174,"date":"2026-09-21T15:13:09","date_gmt":"2026-09-21T23:13:09","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/why-shadow-ai-is-far-riskier-than-shadow-it\/"},"modified":"2026-09-21T15:13:09","modified_gmt":"2026-09-21T23:13:09","slug":"why-shadow-ai-is-far-riskier-than-shadow-it","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/why-shadow-ai-is-far-riskier-than-shadow-it\/","title":{"rendered":"Why shadow AI is far riskier than shadow IT"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>The AI version of shadow IT is proving to be just as pernicious as its more traditional counterpart \u2014 and in some ways, it\u2019s harder for organizations to see and control.<\/p>\n<p>Shadow AI refers to AI tools or AI-powered features that employees use for work without the knowledge, approval, or oversight of IT, security, or compliance teams.<strong> <\/strong>That use can range from<strong> <\/strong>the relatively innocuous \u2014 an employee pasting a document into ChatGPT or Claude to summarize it \u2014 to far riskier things such as installing an unapproved AI coding assistant that touches proprietary source code or giving personal AI agents access to company data and systems.<\/p>\n<p>Multiple surveys, including Proofpoint\u2019s<a href=\"https:\/\/www.proofpoint.com\/sites\/default\/files\/threat-reports\/pfpt-us-tr-the-state-of-ai-security-2025.pdf?utm_source=chatgpt.com\" rel=\"noopener noreferrer\" target=\"_blank\"> <span style=\"text-decoration:underline\">State of AI Security 2025<\/span><\/a> and Unseen Security\u2019s<a href=\"https:\/\/www.unseensecurity.ai\/shadow-ai-report\" rel=\"noopener noreferrer\" target=\"_blank\"> <span style=\"text-decoration:underline\">State of Shadow AI 2026<\/span><\/a><strong> <\/strong>report, have reported growth in unsanctioned AI use while warning about the security risks it creates for enterprises. These include sensitive data exposures and leaks, AI systems gaining unauthorized access to corporate applications, and employees relying on untrusted and unvetted AI-generated content.<\/p>\n<p>One of the most significant risks associated with shadow AI is unreviewed access, said Gal Nakash, co-founder and chief product officer at Reco. A<a href=\"https:\/\/www.reco.ai\/state-of-shadow-ai-report\"> <span style=\"text-decoration:underline\">survey<\/span><\/a> that Reco conducted last year showed that more than 70% of knowledge workers used AI tools without IT&#8217;s approval or knowledge and that 38% admitted to uploading sensitive data to AI tools. OpenAI accounted for 53% of all shadow AI usage across the enterprises in the survey and represented by far the biggest single source of risk.<\/p>\n<p>Here\u2019s why shadow AI poses such a huge risk to your organization \u2014\u00a0and four steps to reining it in.<\/p>\n<p><strong>[ Webinar:\u00a0<\/strong><a href=\"https:\/\/www.reversinglabs.com\/events\/less-noise-more-signal-soc-updates\"><strong>Less Noise, More Signal: Have the Right Tools for a Modern SOC<\/strong><\/a><strong>\u00a0]<\/strong><\/p>\n<h2 id=\"why-employees-gravitate-toward-ai\">Why employees gravitate toward AI<\/h2>\n<p>Many employees turn to unsanctioned and unmanaged AI tools because those tools can solve immediate work problems faster than approved processes. Shadow AI can also emerge from gaps in governance. Both are issues that have long contributed to the prevalence of shadow IT.\u00a0\u00a0<\/p>\n<p>But while some of the underlying causes might be the same, the security risks posed by shadow AI can be substantially different. Where shadow IT\u2019s risk lies in unmanaged applications storing or processing company data, shadow AI adds action and autonomy, Nakash said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAn unapproved file-sharing app may expose data placed inside it, but an unsanctioned AI agent can become an insider threat. It may read data from one system, trigger workflows, and continue operating after the employee who created it changes roles or leaves.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/naksec\/\"><span style=\"text-decoration:underline\">Gal Nakash<\/span><\/a><\/p>\n<p>More concerning is that organizations often underestimate the extent of shadow AI in their environments. In a recent<a href=\"https:\/\/www.threatdown.com\/blog\/74-of-organizations-are-exposed-to-shadow-ai\/\"> <span style=\"text-decoration:underline\">ThreatDown<\/span><\/a> survey, 74% of responding organizations said they had found that employees were using substantially more AI tools than the organizations had suspected. In 30% of the cases, the organizations had discovered four times the number of AI tools they had expected. On average, 58% of employees at the surveyed organizations reported using AI tools at work.<\/p>\n<h2 id=\"agents-present-an-outsize-risk\">Agents present an outsize risk<\/h2>\n<p>Aviv Nahum, co-founder and CEO of Above Security, said a big danger is that employees can build shadow business processes that rely on AI agents having credentials, permissions, access to enterprise data, and the ability to take actions across multiple systems.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAt that point, you haven\u2019t just introduced another SaaS application. You\u2019ve effectively introduced a new insider into the organization.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/avivon\/\"><span style=\"text-decoration:underline\">Aviv Nahum<\/span><\/a><\/p>\n<p>The organization can be unaware that the agent exists, much less who created it, what permissions it was given, what data it can reach, or whether its behavior continues to match the task it was intended to perform. Meanwhile, AI agents are using their credentials without supervision. \u201cA valid credential tells you almost nothing about whether the activity behind it is safe,\u201d Nahum said.<\/p>\n<p>Besides expanding risk much more than shadow IT, shadow AI is harder to address because you can\u2019t just identify and block unauthorized software or devices. AI that is embedded in approved applications such as Salesforce or Microsoft 365 or installed in personal devices is pretty much undetectable, and AI behaviors can change rapidly as employees adopt new tools. Security teams have little hope of building a complete inventory of where AI is being used and what data is being shared with it.<\/p>\n<h2 id=\"shadow-ai-is-hard-to-manage--but-it-can-be-done\">Shadow AI is hard to manage \u2014 but it can be done<\/h2>\n<p>Seemant Sehgal, founder and CEO of BreachLock, saidshadow AI is harder to scope than shadow IT because the artifact is often just a prompt and a pasted response \u2014 nothing that registers on a network or an endpoint agent to alert security teams.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAn employee running an unsanctioned SaaS tool in 2015 left a DNS query. An employee pasting proprietary deal terms into a consumer AI assistant today leaves almost nothing visible to a security team. Organizations benchmarking their exposure against what they can see are almost certainly missing the full picture and only measuring a fraction of it.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/s-sehgal\/\"><span style=\"text-decoration:underline\">Seemant Sehgal<\/span><\/a><\/p>\n<p>Given the difficulty of spotting and inventoryingAI, organizations need an approach that combines visibility, governance, and access controls.<\/p>\n<p>The challenge, security experts say, is that much of AI activity occurs outside the traditional security controls organizations rely on. They advise taking four actions.<\/p>\n<h3>1. Start with visibility and discovery<\/h3>\n<p>Discovery is more effective than blocking usage, Reco\u2019s Nakash said.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cA blanket ban usually pushes usage deeper into unmanaged channels.\u201d<\/em><br \/>\u2014Gal Nakash<\/p>\n<p>Security teams should aim for a live inventory of AI tools, agents, copilots, browser extensions, OAuth grants, and AI-enabled app features operating across their ecosystem. From there, they should identify for AI connection the owner, the business purpose, the permissions scope, and the review cycle. \u201cThe highest priority should go to tools that touch sensitive data, customer records, financial workflows, source code, regulated information, or production systems,\u201d Nakash said.<\/p>\n<h3>2. Enforce clear policies, not bans<\/h3>\n<p>Organizations should establish<strong> <\/strong>clear, enforceable policies covering approved tools, prohibited data exposures, acceptable use, and consequences. The approved path should be easy enough that employees have no incentive to circumvent it. \u201cBuild an AI governance program with enforceable acceptable-use policies that name which tools are approved, which data categories are off-limits, and what the consequences are,&#8221; advised Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cInventory which AI platforms employees actually use, including personal accounts on corporate devices, and audit the AI features inside your already-approved SaaS stack, because those likely never went through an AI-specific risk assessment.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/jacob-krell\/\"><span style=\"text-decoration:underline\">Jacob Krell<\/span><\/a><\/p>\n<h3>3. Focus on data, permissions, and actions \u2014\u00a0 not just the AI tool<\/h3>\n<p>Merely knowing which AI tools are present isn\u2019t enough.<strong> <\/strong>It\u2019s also important for organizations to<strong> <\/strong>assess what information each AI system can access and what it can do, said Donald McFarlane, advisory board member at Xcape.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAsking AI to fix grammar is not the same risk as giving an agent access to production, payroll, or customer records.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/dmcfarlane\/\"><span style=\"text-decoration:underline\">Donald McFarlane<\/span><\/a><\/p>\n<p>.Pay closer attention to tools that touch sensitive data, source code, production systems, or critical business processes, he said. Govern the information and the action an AI tool can take rather than just inventorying it by name. Organizations also need rules for AI memory such as what can be remembered, what must remain compartmentalized, who owns that context, and what happens to it when that person changes roles or leaves, he said.<\/p>\n<h3>4. Treat AI agents as privileged identities<\/h3>\n<p>AI agents that have been approved must adhere to rules on least privilege, strong authentication, narrowly scoped and time-limited permissions, logging, and human approval for consequential actions. Pay particular attention to combinations of data access, outbound connectivity, and the ability to trigger workflows. <\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe goal is to make shadow AI visible, assign ownership, narrow risky access, and give security teams a way to revoke access when risk changes.&#8221;<\/em><br \/>\u2014Gal Nakash<\/p>\n<h2 id=\"why-a-rethink-is-necessary\">Why a rethink is necessary<\/h2>\n<p>Suzu Labs\u2019 Krell summarized shadow AI\u2019s dangers with this example: A single employee with an AI account on a personal phone can exfiltrate company data without touching a single system the organization monitors.<\/p>\n<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The AI version of shadow IT is proving to be just as pernicious as its more traditional counterpart \u2014 and in some ways, it\u2019s harder for organizations to see and control.Shadow AI refers to AI tools or AI-powered features that employees use for work without the knowledge, approval, or oversight of IT, security, or compliance teams.That use can range fromthe relatively innocuous \u2014 an employee pasting a document into ChatGPT or Claude to summarize it \u2014 to far riskier things such as installing an un<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26174","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26174"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26174\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26174"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}