



























Ro’ee Margalit, Co-founder & CEO of Rotate.

getty
Every security team has a blind spot that they have not planned for. Right now, for most organizations, that blind spot is shadow AI.
Across industries, I've seen employees adopting generative AI tools without formal approval, often with good intentions. They use AI to draft emails, summarize documents, analyze data or automate repetitive tasks. In many cases, leadership is aware and even encourages experimentation. But the security implications of this behavior are only beginning to surface.
This is not a hypothetical risk. It's something I've seen in my own work as the CEO of an AI protection company. According to IBM's 2025 report, one in 5 surveyed organizations experienced breaches linked to shadow AI, and those incidents added an average of $670,000 to breach costs. Among them, 97% lacked proper AI access controls.
Shadow AI is not just about individual employees going rogue. It is a structural problem. In many organizations, I've found that AI adoption has outpaced the policies meant to govern it.
Saviynt's 2026 report found that 71% of CISOs say AI tools already access core business systems like Salesforce and SAP, yet "only 16% govern that access effectively." Three out of four CISOs surveyed had discovered unsanctioned AI tools running in their environments with credentials or elevated system access that were not being monitored.
These tools often come with embedded API integrations, tokens or stored credentials that plug directly into enterprise systems. They operate outside standard provisioning workflows. And because they are adopted by business units rather than deployed by IT, they sit in a gray area where no one has clear ownership.
I have seen this pattern firsthand, initially with smaller organizations where employees adopted AI tools to compensate for limited resources—and more recently in larger enterprises where entire departments have built workflows around unapproved AI services. In both cases, the security team was the last to know.
Most security stacks were designed to protect infrastructure, endpoints and identities, not to monitor how employees interact with third-party AI services. Endpoint detection tools flag malware and suspicious processes, but an employee pasting sensitive customer data into a chatbot does not trigger an alert. Cloud access security brokers can control sanctioned SaaS applications, but many AI tools operate through browser extensions, personal accounts or API calls that bypass corporate controls entirely.
The data exposure risk is significant. IBM's research linked above found that in breaches involving shadow AI, nearly two-thirds involved compromised customer personally identifiable information, compared with just over half in standard breaches. When employees feed proprietary data into AI models they do not control, that data may be stored, used for training or exposed through a vulnerability in a system the organization has no visibility into.
What makes this harder to address is that AI adoption is often driven by senior leaders. According to CIO, nearly half of workers admit to using AI tools without employer approval, and 69% of C-suite executives are comfortable with this behavior, "prioritizing speed over privacy." The result is a culture where adoption is rewarded, but governance is deferred.
Banning AI outright is not a realistic strategy. Employees will find workarounds, and organizations that refuse to engage with AI risk falling behind competitively. The better approach is to build governance that matches the pace of adoption.
That starts with visibility. Security teams need to understand which AI tools are being used, by whom, what data they access and how they connect to internal systems. This is not a one-time audit but rather an ongoing capability, similar to how organizations learned to manage shadow IT a decade ago, but with significantly higher stakes.
From there, organizations should focus on three priorities. First, establish clear AI usage policies that define what tools are approved, what data can be shared and how exceptions are handled. Second, extend identity and access governance to cover AI identities, including service accounts, API tokens and agent-level permissions. Third, integrate AI risk into existing security operations so that anomalous AI behavior is detected and investigated alongside traditional threats.
Gartner has identified AI security platforms as a top strategic technology trend for 2026, noting that fewer than 10% of enterprises currently use them. That gap between risk and readiness will define the next wave of security investment.
Shadow AI is not a future problem. It is already embedded in how organizations operate. The question is whether security teams will build the governance and visibility to manage it before a breach forces the conversation.
The organizations that treat AI governance as a security priority, not just a compliance exercise, will be better positioned to adopt AI safely and at scale. Those that wait for a headline to spur them ahead may find the cost of inaction was far greater than the effort of getting ahead of it.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。