Shadow AI Evolves into Leading Cyber Threat

'I've seen users spin up agents ..., connect to models nobody approved, and test against production data.'

Ai Good Bad Roberthyrons
istock.com/roberthyrons

New research from ThreatDown reveals that most companies massively underestimate how much unknown and ungoverned AI is running inside their environment. According to the research, nearly three-quarters (74 percent) of organizations had more AI tools running than they expected.

Additional findings show that 30 percent of organizations found 16 or more tools already active, which is four times more than expected. Additionally, 58 percent of employees are using AI tools at work, which is 75 percent more than IT and security teams expected. 

Agentic AI tools increasingly run with standing account permissions, reading files, writing code, and connecting to other systems through protocols like Model Context Protocol (MCP). Each of those connections is a new, unreviewed link in a company's software supply chain. If an attacker hijacks one of those shadow agents, they inherit its access to everything it was trusted to touch: the files, the credentials, and the open connections into the rest of your environment.

Dubbed Shadow AI, the use of these unreported platforms presents a significant conflict for technology managers. While employees are encouraged to embrace AI and leverage it increasing benefits, governance appears to be necessary to ensure the expanded use doesn't create unintended, but very real risk for the enterprise.

A number of cybersecurity stakeholders offered their take on the findings. 

Diana Kelley, CISO at Noma Security 

"The fact that 74 percent of organizations found more AI tools than they expected, and that actual workforce use was a median 58 percent versus an expected 33 percent, underscores the shadow AI reality that many organizations and CISOs are struggling with right now. 

"That governance gap becomes more serious as AI continues to shift from people-driven use to agent-driven action that can access sensitive data, run code, and connect to other tools and services. You can’t govern what you can’t see, and with agentic AI, unknown access can quickly become enterprise harm."

Randolph Barr, CISO at Cequence Security 

"The 74 percent number doesn't shock me. Most organizations are still figuring out the basics: getting AI governance stood up, building an actual inventory, and doing all of it while leadership is pushing hard to adopt AI faster. 

"Meanwhile, IT and security teams are wading through an endless parade of vendors promising to secure AI adoption and finding out too late that the tools don't give them the visibility they actually need, or that they needed a foundational secure-AI program in place before buying anything at all.

"And that pressure from the top is exactly what breeds shadow AI. Every department wants to improve how it works, sees AI as something to experiment with, and doesn't think to loop in IT or security first. I've seen users spin up agents with their own credentials, connect to models nobody approved, and test against production data real, sensitive data. 

"Here's the part people miss: it used to be that rolling out an application required engineering or IT, and that requirement was a built-in checkpoint. AI erased it. Now anyone with a browser can wire up an agent over lunch.

"So, what do you do about it? Start with the oldest rule in security: you can't protect what you can't see. If this research tells us anything, it's that most organizations' inventories are off by a mile. Get visibility into what's actually running not what's on the approved list.

"Then, when you pick your first controls, choose the ones that let the business move fast. If governance feels like a roadblock, people will just route around it, and you're back where you started. The controls that matter most for agents live at the infrastructure layer:

  • Acontrol point between agents and everything they touch, so every action ties back to a real identity instead of somebody's borrowed login.
  • Last-privilege scoping so an agent can only reach what it was explicitly trusted to touch.
  • Continuous discovery of which tools and MCP connections are actually live.
  • Runtime enforcement with a full audit trail, so if an agent gets hijacked or wanders off script, the damage is contained and you know exactly what happened.

"The goal isn't to stop shadow AI after the fact. It's to govern it from day one, so the business gets the speed it wants and security gets the visibility it needs."

Chris Radkowski, GRC Expert at Pathlock

"These findings mirror what we are seeing in our own research. Pathlock's 2026 AI Governance Gap Report found that 51 percent of organizations are unsure whether they know all the AI agents operating in their enterprise systems. The problem is that AI adoption is accelerating faster than governance can keep up.

"Discovery is an important first step, but it's no longer enough on its own. AI agents operate continuously, interact directly with application APIs, and increasingly hold permissions to modify business records, execute cross-system workflows, and even approve transactions. An unknown or compromised agent with excessive privileges can create significant business risk at machine speed.

"Security teams need to treat AI agents as identities, not just tools. That means maintaining an inventory of agents and their permissions, enforcing least-privilege access based on the specific business tasks they perform, and continuously monitoring their activity. 

"Organizations also require transaction-level visibility, so they can answer not only 'What is this agent allowed to do?' but 'What is it actually doing?' across connected systems.

"Organizations shouldn't try to stop employees from adopting useful AI. The goal is making sure that adoption happens within security and governance frameworks, not outside them."

More in Cybersecurity