Cyber Defense Advisors

The AI Security Problem Hiding in Plain Sight

The AI Security Problem Hiding in Plain Sight

Shadow AI has moved beyond unauthorized chatbots. Personal accounts, embedded AI features and browser extensions are creating a data-security gap that many companies cannot fully see. The biggest AI security problem inside many companies is not a sophisticated attack. It is ordinary work.

An employee summarizes a contract with an AI assistant. A developer pastes code into a chatbot to find a bug. A salesperson uploads a spreadsheet for analysis. An executive asks an AI tool to rewrite a confidential document.

Each task may save a few minutes. Taken together across an organization, they can create an enormous new flow of corporate data into systems that security teams may not know about, cannot distinguish from personal accounts or do not fully control.

This is the problem increasingly known as shadow AI. And it is growing well beyond employees secretly visiting ChatGPT.

AI Is Already Inside the Enterprise

The numbers suggest that AI adoption has moved considerably faster than the security infrastructure surrounding it.

In an August 2026 report, Akamai found that nearly half of enterprise AI conversations were taking place through unmanaged personal identities. Its researchers described a widening visibility gap between a relatively small number of approved AI platforms and a much larger collection of unmanaged tools operating outside normal corporate controls. (Akamai)

Netskope has documented a similar acceleration. Its 2026 Cloud and Threat Report found that the number of people using SaaS generative-AI applications such as ChatGPT and Gemini had tripled in a year, while the number of prompts they submitted increased sixfold.

Despite the shift toward company-managed AI services, 47 percent of generative-AI users were still using personal AI applications. (Netskope)

Zscaler, analyzing 989.3 billion AI and machine-learning transactions during 2025, reported a 91.2 percent year-over-year increase in AI/ML activity. Data transferred to AI applications rose 92.6 percent, reaching more than 18,000 terabytes. (Zscaler)

Those figures point to a basic problem: AI is no longer a discrete application category that an IT department can easily approve or block.

It is becoming part of the infrastructure of everyday work.

The Account Matters as Much as the Application

Early corporate AI policies often focused on a straightforward question: Which AI tools are employees allowed to use?

That question is no longer sufficient.

An employee may be using an approved platform but doing so through a personal account. The interface may look nearly identical. The underlying security controls may not be.

A company-managed account can be connected to centralized identity systems, retention policies, logging, data-loss-prevention controls and contractual safeguards. A personal account may sit outside much of that structure.

The difficulty is that many organizations cannot reliably tell the difference.

A 2026 survey of 1,253 cybersecurity professionals conducted by Cybersecurity Insiders in association with Netskope found that only 6 percent of organizations reported complete visibility into AI usage.

Forty-five percent said they could see activity in managed AI applications but had blind spots elsewhere. Another 35 percent had only network-level visibility, and 14 percent reported no meaningful AI visibility at all.

Perhaps more significantly, 88 percent could not reliably distinguish between personal and corporate instances of AI applications on the same platform. (Netskope)

That makes an apparently simple question surprisingly difficult to answer:

Is the employee using an AI service the company approved, or merely an AI service with a name the company recognizes?

The Real Exposure Is the Data

AI becomes useful when it is given context.

That is also when it becomes a cybersecurity issue.

Employees do not simply ask AI tools abstract questions. They upload documents. They paste emails. They submit source code, customer information, meeting notes, financial data and proprietary research.

Netskope found that the average organization in its 2026 research experienced 223 detected generative-AI data-policy violations per month, twice the previous year’s level.

For organizations in the top quartile, the average reached approximately 2,100 incidents per month. Netskope also reported that half of organizations lacked enforceable data-protection policies for generative-AI applications. (Netskope)

The danger does not require malicious employees.

A developer may simply want help fixing code. An attorney may want a faster summary of a document. A finance employee may want AI to analyze a spreadsheet.

The security question is what information was transmitted, where it went, under which account, under what contractual terms, how long it may be retained and what controls govern its use.

In an unmanaged AI environment, those answers may be unclear.

The Application May Be Approved. The AI May Not Be.

Shadow IT was relatively easy to understand.

Employees installed or accessed technology that IT had not approved.

Shadow AI is more complicated because the underlying software may already be approved.

AI capabilities are increasingly embedded inside browsers, CRM systems, office suites, collaboration platforms, development environments and other SaaS applications.

Zscaler specifically identified embedded AI as a growing unmanaged exposure, noting that AI functions built into ordinary business platforms can be enabled or used without receiving the same security review as a new standalone application. (Zscaler)

That changes the traditional approval model.

A security team may have reviewed the application two years ago.

It may never have reviewed the AI assistant that appeared inside it six months ago.

Browser and development extensions create another layer of risk. Akamai reported this month that almost 75 percent of the AI extensions it examined requested high or critical permissions, while 16.3 percent contained known vulnerabilities, or CVEs. (Akamai)

An innocuous-looking productivity extension can therefore have access to information far beyond the AI prompt itself.

That makes AI governance partly an application-security problem, partly an identity problem and increasingly a browser and endpoint problem.

The Financial Consequences Are No Longer Theoretical

There is also growing evidence that unmanaged AI is appearing in actual breach investigations.

IBM’s 2025 Cost of a Data Breach Report studied 600 organizations around the world that had experienced data breaches between March 2024 and February 2025.

Among those breached organizations, one in five reported a breach linked to shadow AI.

Organizations with high levels of shadow AI recorded average breach costs $670,000 higher than organizations with little or no shadow AI. IBM also found that 63 percent of the breached organizations either lacked an AI governance policy or were still developing one. (IBM Newsroom)

That distinction matters.

It would be incorrect to say one in five companies generally has suffered a shadow-AI breach. IBM’s sample consisted specifically of organizations that had experienced breaches.

But within that population, shadow AI was already showing up frequently enough to be measurable.

IBM also found that among organizations reporting AI-related security incidents, 97 percent lacked proper AI access controls. (IBM)

The broader message is difficult to miss: organizations are introducing AI faster than many are introducing the controls needed to govern it.

Blocking AI Is Unlikely to Solve It

Companies could respond by banning unauthorized AI tools.

That may reduce some risk. As a long-term strategy, it is unlikely to be enough.

AI is becoming too useful and too deeply embedded in ordinary business software. Employees have powerful incentives to use tools that can compress an hour of work into several minutes.

The practical goal should be to make AI visible, controlled and auditable, rather than pretending it can be kept outside the organization.

That starts with inventory.

Companies should know which standalone AI applications are in use, which traditional SaaS products contain AI capabilities, which browser and development extensions interact with AI, and which external models are connected to internal systems.

Identity is equally important. Wherever possible, organizations should move users onto corporate AI accounts controlled through centralized authentication and single sign-on rather than unmanaged personal accounts.

Sensitive data should be classified, and data-protection controls should account for AI-specific interactions such as prompts, pasted text and document uploads.

Permissions should also be examined closely. An AI application that can read email, access cloud storage or interact with internal databases should not automatically receive broad access simply because the employee using it already has those privileges.

And organizations should pay particular attention to their heaviest users. Akamai recommends concentrating monitoring and training on the roughly 5 percent of high-risk employees generating the majority of interactive AI prompts. (Akamai)

In other words, treating every AI user as equally risky may be less useful than finding the small number of people moving large amounts of information through AI systems every day.

The Question Has Changed

For the last several years, executives have asked whether their organizations should adopt artificial intelligence.

For many companies, that debate is effectively over.

Their employees already have.

The questions now are more specific:

What AI is being used? Which accounts are corporate and which are personal? What data is entering those systems? What permissions do they have? Which applications have quietly introduced new AI capabilities? And would the security team know if sensitive information were leaving through one of them?

Those are no longer questions about emerging technology.

They are questions about cybersecurity fundamentals: identity, access, data protection, application governance, logging and visibility.

AI may be new.

The security principle behind it is not.

You cannot protect what you cannot see. And increasingly, companies cannot assume they can see all of the AI already operating inside their walls.

Work with Cyber Defense Advisors

Shadow AI is already operating inside many organizations, often faster than security teams can identify or govern it. Cyber Defense Advisors can help you understand where AI is being used, what sensitive data may be exposed, and whether your existing controls are keeping pace. If you’re unsure what AI activity is happening across your environment, CDA can help assess the risk and identify the most important gaps before they turn into a larger security problem.

Contact Cyber Defense Advisors today to learn how to turn AI into a strategic advantage.

Leave feedback about this

  • Quality
  • Price
  • Service