惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
量子位
aimingoo的专栏
aimingoo的专栏
V
V2EX
Vercel News
Vercel News
B
Blog
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
TaoSecurity Blog
TaoSecurity Blog
N
News and Events Feed by Topic
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
S
Secure Thoughts
U
Unit 42
博客园 - 叶小钗
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Hacker News - Newest:
Hacker News - Newest: "LLM"
N
News | PayPal Newsroom
Help Net Security
Help Net Security
S
Security Affairs
Microsoft Security Blog
Microsoft Security Blog
W
WeLiveSecurity
博客园 - Franky
Forbes - Security
Forbes - Security
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
Schneier on Security
Schneier on Security
I
InfoQ
B
Blog RSS Feed
大猫的无限游戏
大猫的无限游戏
A
About on SuperTechFans
Webroot Blog
Webroot Blog
AWS News Blog
AWS News Blog
Last Week in AI
Last Week in AI
Security Archives - TechRepublic
Security Archives - TechRepublic
C
CERT Recently Published Vulnerability Notes
N
News and Events Feed by Topic
阮一峰的网络日志
阮一峰的网络日志
L
Lohrmann on Cybersecurity
SecWiki News
SecWiki News
Recent Commits to openclaw:main
Recent Commits to openclaw:main
J
Java Code Geeks

Fortinet All Blogs

Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog Cyber Attacks Leveraging AI Require Behavior-First Security Training, Not Simply Better Awareness | Fortinet Blog The AI Era Needs a New SASE. Here’s What That Actually Looks Like. | Fortinet Blog Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula | FortiGuard Labs Update on Fortinet Use of Frontier AI | CISO Collective Fortinet Supports INTERPOL Operation CyberProtect III Targeting Online Exploitation From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach | FortiGuard Labs Fortinet Launches Its Product Carbon Footprint Calculator FortiSASE Training Builds Skills for Secure Access Success | Fortinet Blog Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog Teaching Cybersecurity the Way It’s Actually Used | Fortinet Blog Introducing FortiSOC: One Platform, Total Control | Fortinet Blog Public-Private Cooperation Is Critical to AI-Driven Cyber Defense | Fortinet Advancing Threat-Informed Defense through Fortinet’s Collaboration with MITRE CTID | Fortinet Threat Actors Weaponize AI Hype to Deliver AsyncRAT | FortiGuard Labs Fortinet Achieves 1 Million People Trained in Cybersecurity Goal Ahead of Schedule | Fortinet Blog While OT Security Is Maturing, Risk Is Not Slowing Down | Fortinet Blog AI Policy Meets Operational Reality: White House AI Cybersecurity Order Calls for Public-Private Coordination | Fortinet Blog Executive Q&A: Strong Q1 Momentum Driven by Differentiated Innovation and Customer Demand | Fortinet Fortinet Earns AV-Comparatives Certification for EDR Detection Visibility | Fortinet Blog Cybercriminals Are Targeting the FIFA World Cup 2026 | FortiGuard Labs Fortinet Achieves AV-Comparatives Certification for Process Injection Protection | Fortinet Blog Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | FortiGuard Labs Battling AI-Based Threats with FortiNDR | Fortinet Blog Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data Defending Critical Infrastructure: Why OT Security Demands a Threat-Informed Approach | CISO Collective Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise | FortiGuard Labs Fortinet Expands Cybersecurity Investment in the United Arab Emirates | Fortinet Blog PureLogs: Delivery via PawsRunner Steganography | FortiGuard Labs The Future of Connectivity | Fortinet Blog Fortinet at the World Economic Forum: Frontier AI models, AI-Driven Threats, Deepfakes, and the Future of Cyber Defense | Fortinet Blog The Fortinet 2025 Sustainability Report | Fortinet Blog Supercharged Security: Security in the Time of Mythos | CISO Collective Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign | FortiGuard Labs AI Security Is an Architectural Decision | Fortinet Blog Fortinet Training Institute Wins Industry Accolades | Fortinet Blog Leading by Example in Sustainability: Fortinet Expands Global EPD Certification | Fortinet Blog When Cybercrime Becomes an Industry | Fortinet Blog FortiOS 8.0: Redefining Secure Networking in the AI and Quantum Era | Fortinet Blog Securing the Physical World as It Comes Online | Fortinet Blog Why the 2026 AI Cybersecurity Summit Matters | Fortinet Blog DPRK-Related Campaigns with LNK and GitHub C2 | FortiGuard Labs AI Is Changing Application Threats Faster Than Teams Can Adapt | Fortinet Blog Announcing the Fortinet Training Institute’s 2026 ATC Award Winners | Fortinet Blog Disrupting Cybercrime Networks at Scale Requires Sustained Global Collaboration | Fortinet Blog
Shadow AI: The Invisible Risk Growing Inside Your Organization | Fortinet Blog
2026-04-10 · via Fortinet All Blogs

AI adoption is accelerating throughout the enterprise, and it is increasingly being used outside formal controls and approved workflows. Employees utilize publicly available generative AI (GenAI) tools to write code, summarize documents, analyze data, and automate routine tasks, often through browsers or personal accounts.

This shift introduces what is now called shadow AI. It’s not a specific collection of tools but an environment in which AI is employed without oversight, governance, or visibility. It is rapidly becoming one of the most immediate and least understood risks in the enterprise.

This is one of the topics that will be addressed at the Fortinet AI Security Summit on April 21, where security leaders will examine how AI is reshaping risk across networks, applications, and data.

AI Adoption Is Outpacing Visibility

Alongside formal deployments, employees are adopting publicly available AI tools at a pace most organizations cannot match. Many of these interactions happen outside managed environments, which limits visibility into how AI is used and what data is shared.

Unlike earlier shadow IT challenges, shadow AI changes the nature of the risk. Many AI systems not only store or transmit data, but they also process, reshape, and often retain elements in ways that are not visible to users. When employees upload internal documents, customer data, or source code to external AI services, there is often no clear understanding of how that data is stored or used afterward.

Why Traditional Security Models Break Down

Traditional security architectures assume systems are known, access is managed, and data flows can be monitored. Shadow AI breaks those assumptions.

Complicating this further, AI tools are increasingly accessed outside managed environments, which reduces visibility at both the network and endpoint levels. And even when usage is detected, it can be difficult or impossible to determine what data was shared, how it was processed, or where it is stored.

Traditional controls were simply not designed to manage interactions with external AI systems. As a result, while organizations may have strong controls over infrastructure, applications, and identity, they still lack insight into how AI is being used in everyday workflows.

Fragmented security stacks, made up of isolated point solutions, make this worse. When network, cloud, and endpoint controls operate independently, no single system has enough context to understand AI usage end to end.

The Security and Data Risks of Shadow AI

These risks posed by shadow AI already exist in most environments, and they will only grow with use. The most urgent issue is data exposure. Information entered into AI systems may be stored or reused in ways that are not visible to the organization. Even when providers offer data privacy assurances, the responsibility for protecting that data remains with the organization.

Likewise, the reliability of AI-generated output also cannot be assumed. Models may produce results that may seem accurate but are actually incomplete or incorrect. When these outputs are used in workflows or customer-facing content, the consequences can extend well beyond technical risk.

And at the same time, attackers are adapting to exploit this new opportunity, with techniques such as prompt injection becoming more common as AI becomes embedded in business processes.

Regulatory Pressure Is Increasing

Regulatory controls are another issue that must be addressed. Regulations are no longer lagging behind AI adoption. New frameworks, such as the EU AI Act, require organizations to identify their AI systems, assess risks, and demonstrate oversight. Penalties, some of them severe, are linked to global revenue.

The challenge is that these models assume visibility into AI usage that many organizations do not have. When AI use occurs outside approved tools and processes, it cannot be inventoried, assessed, or governed in a way that meets these requirements. The gap is structural.

The Shadow AI Compliance Gap

The gap between AI use and regulatory expectations is largely operational. Most regulatory frameworks require organizations to identify the systems in use, assess the associated risk, and apply controls accordingly. However, if AI use cannot be inventoried, it cannot be assessed. And without that baseline, policies cannot be applied in a way that reflects how these tools are actually being used. What remains are policies that describe intended behavior but do not map to real activity.

This creates a disconnect between what organizations need to control and what they can demonstrate. From a regulatory standpoint, that matters because it limits their ability to show where data is being processed, which systems are involved, and whether controls are consistently applied.

In practice, the problem isn’t policy. It's the lack of visibility needed to enforce it.

Why Visibility Alone Is Not Enough

While discovery is necessary, it’s not sufficient on its own. Understanding shadow AI risk also requires correlating signals across multiple domains. Network traffic may show access to an AI service but not what data was submitted. Endpoint activity may indicate interaction but not how it fits into workflows or whether sensitive data was involved. Traditional controls provide only partial visibility into these interactions.

This fragmentation limits context. Each control point sees only a portion of the activity, not the full exchange between users, data, and external AI systems. Without that context, it is difficult to distinguish routine use from risky behavior.

Effective governance depends on shared visibility across the environment, where access, data movement, and user activity can be evaluated together and acted on in real time.

Bringing Shadow AI into the Security Fabric

Managing shadow AI must extend beyond visibility to control. At the network level, organizations already have a natural enforcement point. Within Fortinet environments, FortiOS provides native visibility into AI application usage through application control and deep inspection. This allows security teams to identify not only which AI services are being accessed, but also how they are being used, by whom, and in what context, without requiring additional tools or proxies.

This visibility is continuously enriched by intelligence from FortiGuard Labs, which classifies and tracks emerging AI services and usage patterns. As new GenAI tools are adopted, they are automatically incorporated into detection and categorization, enabling organizations to maintain awareness as the landscape evolves.

But network visibility alone does not capture the full risk. From a network perspective, a prompt submission and the upload of sensitive data can appear identical. Because of this, control must extend to the point where data is handled. This is where endpoint-level enforcement becomes essential.

Data loss prevention (DLP) extends across the environment. At the network level, FortiGate can inspect and control data in motion. In cloud-delivered environments, the same policies can be enforced through SASE. At the endpoint, FortiDLP serves as a final control point by inspecting content at the time of interaction. Together, these layers ensure that sensitive data can be identified and protected regardless of how AI services are accessed.

That control must also follow the user. AI usage increasingly happens off-network—across remote users, unmanaged locations, and cloud-delivered applications. Extending the same visibility and policy enforcement through solutions such as FortiSASE ensures that AI usage is governed consistently, regardless of where it occurs.

Together, these layers form a consistent, systemwide model. Network visibility establishes awareness, threat intelligence expands coverage, and endpoint controls enforce policy at the point where risk is introduced, ensuring enforcement remains consistent across environments.

A Structural Shift not a Temporary Risk

AI is becoming part of how work is performed across the enterprise. Unfortunately, unmanaged usage is increasingly becoming part of the baseline.

Organizations that treat shadow AI as a temporary issue will continue to operate with limited visibility and increasing exposure. A more effective approach is to incorporate AI usage into existing security and networking models, so it is visible, governed, and aligned with operational and regulatory requirements.

REGISTER NOW: Shadow AI sits at the intersection of visibility, data protection, and governance. This requires a coordinated approach across your distributed environment. To learn how to manage this challenge and enforce control over AI usage, join us on April 21 at the Fortinet 2026 AI Security Summit.