Skip to main content
Cybersecurity

Shadow AI Runs Rampant in 74% of Organizations

Empty office cubicle with laptop and smartphone on desk, surrounded by papers and office supplies.

“Seventy-four percent of organizations found more AI tools than they expected.” That single finding from ThreatDown’s research opens a window onto a governance problem that security leaders say is now shifting from user-led experimentation to agent-driven action with the power to access sensitive data, run code, and connect to other services.

Scope and scale: how unexpected AI use shows up in environments

The research reports that a majority of companies surveyed expected five or fewer AI tools deployed in their environments, yet 30% of those organizations discovered 16 or more were running. Diana Kelley, Chief Information Security Officer at Noma Security, summarized the mismatch between expectation and reality: “actual workforce use was a median 58% versus an expected 33%,” a gap she called evidence of the “shadow AI reality” many organizations face.

CISOs warn of agentic behavior and a governance gap

Security leaders quoted in the research frame the problem as more than inventory error. Kelley warned that “that governance gap becomes more serious as AI continues to shift from people-driven use to agent-driven action that can access sensitive data, run code, and connect to other tools and services.” Her prescription is simple: security teams need visibility into what’s running, what data and systems those tools can access, and “what agentic behavior is occurring at runtime.” As she put it bluntly, “You can’t govern what you can’t see.”

Infrastructure controls and least-privilege: Randolph Barr’s operational advice

Randolph Barr, Chief Information Security Officer at Cequence Security, described a common organizational dynamic: leadership pushing fast AI adoption while IT and security “are still figuring out the basics: getting AI governance stood up, building an actual inventory.” Barr said that pressure “is exactly what breeds shadow AI,” with departments experimenting without involving IT or security and users “spin[ning] up agents with their own credentials” or connecting to “models nobody approved.”

His guidance emphasizes infrastructure-layer controls that allow speed without surrendering safety: a control point between agents and resources so every action ties back to an identity, least-privilege scoping, continuous discovery of live tools and MCP connections, and runtime enforcement “with a full audit trail” so hijacked or errant agents can be contained and investigated. Barr’s framing rejects post-facto cleanup in favor of governing agents “from day one.”

Treat agents as identities and control behavior: insights from Pathlock and Noma Security

Chris Radkowski, GRC expert at Pathlock, pointed to complementary data: Pathlock’s 2026 AI Governance Gap Report found that 51% of organizations are unsure whether they know all the AI agents operating in their enterprise systems. Radkowski warns that discovery alone is insufficient because agents “operate continuously, interact directly with application APIs, and increasingly hold permissions to modify business records, execute cross-system workflows, and even approve transactions.” His recommended actions include maintaining an inventory of agents and permissions, enforcing least-privilege access tied to business tasks, and obtaining transaction-level visibility to answer not only what an agent is allowed to do, but what it is actually doing.

Gal Moyal from the CTO Office at Noma Security added that enterprise AI security hinges on the capability to “discover ungoverned agents and tools, analyze their real-time behavior, and enforce contextual controls before malicious actions occur.” He described agentic risks that include autonomous swarms and multi-step workflows using protocols such as the Model Context Protocol (MCP), and argued that legacy compliance audits, passive monitoring, and endpoint detection lack the runtime context needed to stop fast-moving exploits like prompt injection or compromised skills.

The research distills recommended technical capabilities into three foundation pieces: Behavioral Agent & Skill Discovery with AI-SPM; Protocol-Level Governance and Access Control; and Inline Behavioral Interception and Control with AI-DR. Together these map to continuous discovery, scoped protocol controls, and real-time interception of unauthorized tool calls and data exfiltration.

What this means for technologists, procurement leaders, and security teams

  • Technologists and security teams: prioritize real-time visibility and treat agents as identities — maintain inventories of agents and permissions, monitor transactions, and enable runtime enforcement so an agent’s actions are auditable and containable.
  • Procurement and business leaders: select controls that “let the business move fast,” or face users routing around governance; require that vendors deliver discovery, scoped access controls, and runtime enforcement capabilities rather than only passive monitoring.
  • Governance and compliance leads: shift from periodic audits to protocol-level governance and inline controls; require explicit authorization for high-risk operations such as arbitrary code execution or shell access, per the recommendations in the research.

The record from ThreatDown’s research and the security leaders it cites presents a clear practical test: if 74% of organizations are finding more AI tools than they expected, the immediate question is not whether shadow AI exists but whether governance can move from static inventories and alerts to continuous, contextual control. The leaders quoted here argue the answer lies in discovery, scoped protocol controls, and inline detection-and-response that stop unauthorized actions before they execute — because in the era of agentic AI, the window between detection and damage can be measured in seconds.

Original story