惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
有赞技术团队
有赞技术团队
Jina AI
Jina AI
H
Help Net Security
D
Docker
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
MyScale Blog
MyScale Blog
N
Netflix TechBlog - Medium
B
Blog RSS Feed
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
U
Unit 42
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
MongoDB | Blog
MongoDB | Blog
美团技术团队
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
博客园 - 司徒正美
Microsoft Security Blog
Microsoft Security Blog
IT之家
IT之家

Business Insights

What’s New in GravityZone September 2026 (v 6.77) Bitdefender Achieves AV-Comparatives EPR Certified Leader with Noteworthy Results The New AI Arms Race Starts Before the Attack Bitdefender Threat Debrief | September 2026 Why Are So Many Security Professionals Keeping Breaches Quiet? CyberLeek: Extortion Built for an Audience, Not a Victim Everyone Says Security Consolidation Saves Money. Four Organizations Did the Math The Next MDR Evolution: Digital Sovereignty, Trusted AI, Continuous Protection SilkParasite: Tracking a China-Nexus APT Across Central Asia Frontier AI and the Changing Dynamics of Cybersecurity Bitdefender Threat Debrief | August 2026 GravityZone Achieves Top Results in AV-Comparatives Testing When Visibility Becomes the Target: Bitdefender at Black Hat USA 2026 Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core Bitdefender Recognized as a Major Player in the 2026 IDC MarketScape for Worldwide MDR Service for Midmarket Are You Falling for the Privacy Illusion? What’s New in GravityZone July 2026 (v 6.75) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR Bitdefender Threat Debrief | July 2026 Trust Under Attack: How Deepfakes Are Rewriting Cybercrime Your AI SOC Won’t Catch Ransomware by Itself 2026 Cybersecurity Assessment: The Gap Between Knowing and Doing Your Last Red Team Tested the Wrong Attack MSP Strategic Defense: Why MDR Is the New Security Baseline for MSPs Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices Bitdefender Recognized in the 2026 Gartner® Europe Context: Magic Quadrant™ for Endpoint Protection CISA Mandates Change for Structured, Prioritized Updates and Vulnerability Management Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags What’s New in GravityZone June 2026 (v 6.74) Bitdefender Threat Intelligence: Built for How Security Teams Work
Rapidly Rising Risk: AI in the Shadows
Nicholas Jackson · 2026-08-04 · via Business Insights

Artificial intelligence is breaking a long-standing model within many organizations.

AI isn't arriving through carefully planned IT projects or lengthy procurement cycles. It's arriving organically—through every department, every browser, every SaaS platform, and increasingly, every employee.

This has created one of the major blind spots in enterprise cybersecurity today: internal AI visibility.

The Industry Benchmark on AI Visibility and Shadow AI

The 2026 Bitdefender Cybersecurity Assessment asked 1,200 IT & cybersecurity professionals how much visibility they have into AI usage across the organization.  More than four-in-ten (44.8%) acknowledge they only have partial visibility into employee AI usage, saying they can monitor sanctioned enterprise LLMs but lack visibility into personal AI accounts and Shadow AI subscriptions used for work. And while 51.8% say they have full visibility into all AI usage at their organizations, that figure is optimistic and warrants scrutiny.

AI-visibility-de-revised

We explored the topic recently on a webinar around cybersecurity benchmarks and blind spots, and my colleague Martin Zugec made a key point on AI visibility: "We had a roundtable with CISOs where we discussed this. It turns out you have a lot of tools that you approved and have been using for a while that suddenly turn themselves into LLM enabled, and you probably don't even consider them."

Many organizations believe they understand their AI exposure because they can account for the enterprise AI platforms they've approved. Those sanctioned tools represent only a fraction of the AI ecosystem employees interact with every day.

Visibility Goes Well Beyond Popular LLMs

When executives think about AI governance, many still picture employees opening ChatGPT in a browser.

That was the conversation twelve months ago.

Today's reality is far more complex. AI is now embedded throughout the modern enterprise. Productivity suites summarize meetings automatically. CRM platforms draft customer communications. Development environments generate code. Browsers offer AI assistants. Design software creates images. Security products analyze threats using generative AI. Employees sometimes don't even realize they're interacting with AI.

That means organizations aren't simply trying to inventory AI applications anymore—they're attempting to understand AI capabilities woven into hundreds of existing business tools.

The conversation has evolved from: "Which AI tools are employees using?"  to "Where does AI exist across our technology stack?"

Shadow AI Is More than Shadow IT Rebranded

Shadow AI may be the new Shadow IT, but the risks are far greater than the typical issues we've seen in the past.

When cloud adoption was the hot new thing, departments sometimes spun up their own S3 buckets or employees stored files in any number of unauthorized cloud services and apps. That was shadow IT. But with Shadow AI, your employees are likely asking AI to summarize contracts, rewrite customer communications, analyze financial data, generate source code, interpret legal documents, and answer sensitive business questions.

In many cases, sensitive corporate information is becoming part of these conversations.

And employees are increasingly granting AI platforms access to their corporate emails, calendars, and even private meeting rooms as they use AI tools to record every word and summarize next steps. Would your organization even know if these interactions have occurred?

Shadow AI is a significantly more dynamic attack surface than we've faced before.

Is Full AI Visibility Possible?

Recent Bitdefender research finds that more than half of IT & cybersecurity professionals believe they have "full visibility" into AI usage, however, I suspect many organizations are defining the term differently than reality demands.

The AI landscape changes almost weekly. New capabilities appear through software updates organizations didn't request and sometimes don't notice. In that environment, visibility is less a destination than an ongoing operational discipline.

And in my daily work with organizations around the globe, I'm finding that many need help to ask the right questions around AI usage, so they can form a baseline around AI visibility and decide where they should go from there.

Addressing The AI Governance Gap

When it comes to AI governance, technology alone will not solve this problem.

Many organizations are understandably looking for monitoring tools to improve visibility. But technology addresses only part of the challenge.

The larger issue is governance.

Organizations should ask themselves:

  • Have we updated acceptable use policies for AI?
  • Does every AI purchase require security review?
  • Are employees trained on information that should never be entered into public LLMs?
  • Do managers understand department-specific AI risks?
  • Are legal, compliance, procurement, HR, and security aligned on AI adoption standards?

Governance cannot be delegated entirely to IT or security. AI is now an enterprise-wide business capability and managing it often requires enterprise-wide accountability.

AI Visibility and Where We Go from Here

AI capabilities are being integrated into enterprise software faster than traditional governance models were ever designed to accommodate. And security leaders should not assume that the absence of incidents means the absence of risk.

The AI Visibility challenge isn't simply a technology problem. It's also a leadership challenge that requires accurately assessing how intelligence itself is becoming embedded throughout the organization. The sooner organizations recognize that distinction, the sooner they'll begin managing the AI risks they can't yet see.See the rest of the AI benchmarks and blind spots:
Download the 2026 Bitdefender Cybersecurity Assessment