惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
月光博客
月光博客
人人都是产品经理
人人都是产品经理
宝玉的分享
宝玉的分享
博客园 - 司徒正美
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
T
Tailwind CSS Blog
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
Visual Studio Blog
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News
博客园 - 聂微东

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
The Rise Of Shadow AI, And Why Your Security Stack Wasn't...
Ro'ee Margalit · 2026-05-04 · via Forbes - Innovation

Ro’ee Margalit, Co-founder & CEO of Rotate.

getty

Every security team has a blind spot that they have not planned for. Right now, for most organizations, that blind spot is shadow AI.

Across industries, I've seen employees adopting generative AI tools without formal approval, often with good intentions. They use AI to draft emails, summarize documents, analyze data or automate repetitive tasks. In many cases, leadership is aware and even encourages experimentation. But the security implications of this behavior are only beginning to surface.

This is not a hypothetical risk. It's something I've seen in my own work as the CEO of an AI protection company. According to IBM's 2025 report, one in 5 surveyed organizations experienced breaches linked to shadow AI, and those incidents added an average of $670,000 to breach costs. Among them, 97% lacked proper AI access controls.

The Governance Gap Is Wider Than Most Leaders Think

Shadow AI is not just about individual employees going rogue. It is a structural problem. In many organizations, I've found that AI adoption has outpaced the policies meant to govern it.

Saviynt's 2026 report found that 71% of CISOs say AI tools already access core business systems like Salesforce and SAP, yet "only 16% govern that access effectively." Three out of four CISOs surveyed had discovered unsanctioned AI tools running in their environments with credentials or elevated system access that were not being monitored.

These tools often come with embedded API integrations, tokens or stored credentials that plug directly into enterprise systems. They operate outside standard provisioning workflows. And because they are adopted by business units rather than deployed by IT, they sit in a gray area where no one has clear ownership.

I have seen this pattern firsthand, initially with smaller organizations where employees adopted AI tools to compensate for limited resources—and more recently in larger enterprises where entire departments have built workflows around unapproved AI services. In both cases, the security team was the last to know.

Why Traditional Security Tools Miss It

Most security stacks were designed to protect infrastructure, endpoints and identities, not to monitor how employees interact with third-party AI services. Endpoint detection tools flag malware and suspicious processes, but an employee pasting sensitive customer data into a chatbot does not trigger an alert. Cloud access security brokers can control sanctioned SaaS applications, but many AI tools operate through browser extensions, personal accounts or API calls that bypass corporate controls entirely.

The data exposure risk is significant. IBM's research linked above found that in breaches involving shadow AI, nearly two-thirds involved compromised customer personally identifiable information, compared with just over half in standard breaches. When employees feed proprietary data into AI models they do not control, that data may be stored, used for training or exposed through a vulnerability in a system the organization has no visibility into.

What makes this harder to address is that AI adoption is often driven by senior leaders. According to CIO, nearly half of workers admit to using AI tools without employer approval, and 69% of C-suite executives are comfortable with this behavior, "prioritizing speed over privacy." The result is a culture where adoption is rewarded, but governance is deferred.

From Blocking To Governing

Banning AI outright is not a realistic strategy. Employees will find workarounds, and organizations that refuse to engage with AI risk falling behind competitively. The better approach is to build governance that matches the pace of adoption.

That starts with visibility. Security teams need to understand which AI tools are being used, by whom, what data they access and how they connect to internal systems. This is not a one-time audit but rather an ongoing capability, similar to how organizations learned to manage shadow IT a decade ago, but with significantly higher stakes.

From there, organizations should focus on three priorities. First, establish clear AI usage policies that define what tools are approved, what data can be shared and how exceptions are handled. Second, extend identity and access governance to cover AI identities, including service accounts, API tokens and agent-level permissions. Third, integrate AI risk into existing security operations so that anomalous AI behavior is detected and investigated alongside traditional threats.

Gartner has identified AI security platforms as a top strategic technology trend for 2026, noting that fewer than 10% of enterprises currently use them. That gap between risk and readiness will define the next wave of security investment.

The Window Is Closing

Shadow AI is not a future problem. It is already embedded in how organizations operate. The question is whether security teams will build the governance and visibility to manage it before a breach forces the conversation.

The organizations that treat AI governance as a security priority, not just a compliance exercise, will be better positioned to adopt AI safely and at scale. Those that wait for a headline to spur them ahead may find the cost of inaction was far greater than the effort of getting ahead of it.​​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?