Cybersecurity 10 min

Shadow AI Is Expanding Your Attack Surface; Here’s What to Do

Shadow AI is expanding the enterprise attack surface faster than governance can keep up. Members of the Senior Executive Cybersecurity Think Tank explain how security leaders can uncover hidden AI use, recognize compounding risk and build stronger controls.

by Cybersecurity Editorial Team on August 11, 2026

NIST emphasizes that effective AI risk management depends on organizations being able to govern, map, measure and manage how AI systems are used. However, following that guidance is becoming increasingly complicated.

Artificial intelligence is moving into everyday business operations faster than many organizations’ security and governance processes can keep up. Employees and business teams can now build workflows around large language models, add AI copilots to existing tools, and connect agents to company systems without the kind of formal deployment process that traditionally gives security teams visibility into new technology. 

As AI moves from standalone experimentation into copilots, connected workflows and increasingly autonomous agents, security teams may have less visibility into where it’s being used, what data it can reach and what actions it’s authorized to take. The result is a widening gap between the AI environment an organization believes it is governing and the one actually taking shape across the business.

It’s essential for security leaders to gain visibility into the web of AI systems being built across their organizations—and the ever-expanding attack surface that comes with it. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise spanning enterprise cybersecurity strategy, breach prevention, risk management and cybersecurity leadership—explain how security leaders can get ahead of business-led AI deployments and recognize when unmanaged AI risk is already beginning to compound.

“Security leaders should treat business-led AI like shadow cloud in its early days: Don’t shame it; map it.”

Maman Ibrahim, Founder of Ginkgo Resilience LTD and member of the Cybersecurity Think Tank, sharing expertise on marketing on the Senior Executive Media site.

– Maman Ibrahim, Founder of Ginkgo Resilience LTD

SHARE IT

Map the AI Estate Before Trying to Control It

Maman Ibrahim, Founder of Ginkgo Resilience LTD, says there are abundant signs that indicate an organization already has a knotty AI security problem.

“The risk is already compounding when teams can’t name the AI workflows in production, prompts contain regulated data, agents use shared credentials, outputs drive decisions without review, and/or no one can explain what changed after an incident,” he says.

Rather than discouraging teams from experimenting, however, he recommends beginning the remediation process by establishing visibility.

“Security leaders should treat business-led AI like shadow cloud in its early days: Don’t shame it; map it,” Ibrahim says. “The fix is a living AI register, clear accountability and controls built where the work actually happens.”

From there, he says organizations can distinguish between routine uses and those that demand stronger safeguards.

“Start with discovery,” Ibrahim says. “Identify where LLMs, copilots, plugins and agents touch sensitive data, trigger decisions or connect to systems. Then, tier workflows by risk and require owners, approved models, data rules, logging and human checkpoints for high-impact use cases.”

Give Teams a Safer Path to Build

Jamshir Qureshi, Vice President of DevSecOps Engineering at MUFG Bank Ltd., draws a direct parallel between today’s emerging AI environment and an already familiar enterprise security challenge.

“Security leaders should treat shadow AI the same way as shadow IT—you know you can’t properly guard what you don’t ever see,” he says.

Qureshi explains that the warning signs of rising security risk can show up in both network activity and business behavior.

“If the risk is already compounding, you’ll feel it,” he says. “Watch for a jump in odd internal API traffic, unexpected data egress headed toward new AI domains, and ‘zombie agents’ left running, unsupervised. When even nontechnical groups begin pushing complicated automations overnight, your attack surface is already racing ahead of your perimeter, no matter how strict it felt last quarter.”

Qureshi stresses that while visibility is an essential first step, it’s only part of a smart strategy. He argues that organizations also need to make secure AI development easier for business teams.

“Start with deploying discovery tools that can map every off-the-books API call, embedded copilot and agentic workflow humming along inside your network,” Qureshi says. “Then, rather than slamming the door shut, create a paved route: a preapproved structure with guardrails like data loss prevention and automated prompt filtering, so teams can actually build without stepping into trouble.”

“Agentic pipelines should be treated like privileged digital workers, not simple automation, because they can read, decide, write, call APIs and trigger downstream actions.”

Harikrishnan Muthukrishnan, Principal IT Developer for BCBS FLORIDA, member of the Cybersecurity Think Tank, sharing expertise on cybersecurity on the Senior Executive Media site.

– Harikrishnan Muthukrishnan, Principal IT Developer at BCBS FLORIDA

SHARE IT

Treat AI Agents as Privileged Digital Workers

For Harikrishnan Muthukrishnan, Principal IT Developer at BCBS FLORIDA, governance problems can emerge well outside traditional software development channels.

“The risk is compounding when workflows launch through low-code tools, spreadsheets, browser plugins or SaaS connectors without review and when no one can say who approved, validates or can shut down an AI process,” Muthukrishnan says.

He recommends establishing an accurate view of the organization’s AI environment before attempting to build policy around it.

“Security leaders should start with an AI asset inventory before writing policy,” Muthukrishnan says. “First, identify where LLMs, copilots, prompts, agents, APIs, plugins and model outputs are being used, what data they touch, where logs live and who owns the risk.”

He notes that agentic systems warrant particular attention because of the actions they can take on an organization’s behalf.

“Agentic pipelines should be treated like privileged digital workers, not simple automation, because they can read, decide, write, call APIs and trigger downstream actions,” Muthukrishnan says. “That means identity, least privilege, session controls, audit trails, approval gates and no shared credentials or permanent tokens.”

He concludes by stressing that the controls surrounding AI systems need to be addressed before deployment.

“AI governance needs to move into the software delivery lifecycle, with data classification, threat modeling, testing, monitoring and change management before production.”

Bring Security Into AI Development Earlier

Gaurav Kulkarni, Senior Manager, Cybersecurity Engineering for Staples, says security teams first need to establish whether they have an accurate picture of what’s already operating inside the business.

“The question security leaders need to be asking isn’t, ‘How do we secure AI?’ It’s, ‘Do we even know what AI systems are running in our environment today?’” Kulkarni says.

He notes that business-led deployments can bypass the controls organizations have built around more established technology.

“The fastest-growing attack surface isn’t tracked by security because it wasn’t deployed by them,” Kulkarni says. “Business teams ship LLM workflows, copilots and agentic pipelines into production with the same security hygiene applied to internal tools a decade ago.”

For Kulkarni, several conditions signal that the issue has moved beyond a theoretical governance concern.

“Signs that show risk is compounding are models touching sensitive data nobody approved, agentic pipelines with no audit trail, and unauthenticated MCP servers in production,” he says. “I’ve seen this firsthand. If you can’t list the AI systems touching production data today, the risk is already live.”

His preferred response is to establish security expectations before AI applications reach production.

“The approach that works is to stop auditing AI after deployment and require a ‘Responsible AI Security Baseline’—a checklist covering data access, authentication and logging,” Kulkarni says. “Security has to be in the room when AI gets built, not called in after it ships.”

Recognize When Experiments Become Infrastructure

Anand Salodkar, Co-Founder and COO of CompFly AI, cautions against viewing unmanaged AI simply as another backlog of unauthorized tools.

“Security leaders should stop treating this issue as a shadow IT cleanup exercise and treat it like a new production estate,” Salodkar says.

He explains that the transition from AI experimentation to everyday infrastructure may not arrive with a formal launch or obvious milestone.

“The warning signs are usually mundane: Teams cannot name all the bots in use, copilots have broader access than the people using them, ‘temporary’ automations become business-critical, prompts include customer or internal data, and no one knows how to reproduce or investigate a bad answer,” Salodkar says. “That is when the risk has moved from experimentation to unmanaged infrastructure.”

His recommended starting point is understanding where AI has begun influencing actual business activity.

“The first move is not to ban it, but to map where LLMs are making or influencing decisions, including what data they touch, what tools they can call, who owns them and where a human can still intervene,” Salodkar says.

“If your security team is learning about AI workflows only after they go live, the risk isn’t approaching; it’s already inside.”

Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, member of the Cybersecurity Think Tank, sharing expertise on cybersecurity on the Senior Executive Media site.

– Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA

SHARE IT

Treat Ungoverned AI as an Active Threat Vector

Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, argues that the risk posed by business-led AI deployment deserves the same rigorous oversight organizations apply to other production technologies.

“The most dangerous attack surface today isn’t infrastructure; it’s the ungoverned AI layer quietly entering production through business-led deployments,” Ritesh says.

He points to several indicators that an organization may already be losing control of its AI environment.

“The warning signs that risk is already compounding include shadow AI tools appearing in procurement data, LLM outputs influencing decisions without human validation gates, and no defined owner when an AI-driven process fails or is manipulated,” Ritesh says.

His prescription begins with applying established security rigor to AI systems—regardless of who deployed them.

“Security leaders must treat every embedded copilot, LLM workflow and agentic pipeline as a threat vector requiring the same rigor as external-facing systems,” he says. “Start by mapping what’s running—most organizations genuinely don’t know.”

Ritesh warns that the threat isn’t merely hypothetical. 

There is ample evidence that attackers are probing AI pipelines for prompt injection, data exfiltration and authorization bypass before defenders even know those pipelines exist,” he says. “If your security team is learning about AI workflows only after they go live, the risk isn’t approaching; it’s already inside.”

Practical Strategies for Managing Business-Led AI

  • Build and maintain a clear inventory of AI systems in use. Map where LLMs, copilots, plugins and agents operate; what data they touch; and who owns them so security teams can prioritize higher-risk use cases.
  • Create a secure, approved path for business-led AI development. Rather than trying to shut down experimentation, give teams preapproved frameworks and guardrails that make safer AI deployment easier.
  • Treat agentic systems as privileged digital workers. Apply identity controls, least privilege, audit trails, approval gates and other safeguards appropriate for systems that can access data and take actions across the business.
  • Move security requirements upstream in the AI development process. Establish baseline expectations for data access, authentication, logging, testing and oversight before AI workflows reach production.
  • Watch for signs that AI experiments have become critical infrastructure. Broader-than-expected access, business-critical automations and unclear ownership can indicate that unmanaged experimentation has quietly evolved into production risk.
  • Apply production-level security rigor to every AI deployment. Embedded copilots, LLM workflows and agentic pipelines should receive appropriate oversight regardless of whether they originated in IT, security or a business function.

Governance Must Catch Up With AI Adoption

AI is no longer entering the enterprise through a handful of centralized, easily monitored channels. It’s spreading through employee-built workflows, embedded copilots and increasingly capable agents that can interact with sensitive data, make decisions and trigger actions across systems. As that footprint grows, the security challenge shifts from simply protecting known AI tools to mapping the full extent and functionality of AI systems.

Visibility, ownership and governance can no longer be treated as after-the-fact controls. As AI becomes woven more deeply into everyday operations, unmanaged deployments can accumulate until they’re difficult to untangle—and by then, the attack surface may already be far larger than security leaders realize.


Copied to clipboard.