
Shadow AI has been on the periphery of any Chief Security Officer’s agenda for years. But now, as AI pilot failures push more employees toward unauthorized tools, it must move up the priority list.
The threat level across all areas of cybersecurity is already high. Ransomware attacks alone climbed by 21% in 2025, and against that backdrop, shadow AI is driving risk levels even higher. In fact, I’d go as far as to predict that its growth will push cyberattack numbers up 25% in the next year.
But what is it, why is it such an existential threat to businesses, and what can be done about it? Put simply, shadow AI is when employees use unauthorized AI tools to help them complete their day-to-day tasks. That might sound like a relatively small misdemeanor, but it’s opening businesses up to a whole new level of attack.
The reason it is so dangerous is that it’s the employees, not the attackers, breaking through an enterprise’s defenses. That means the attack surface is broad, businesses have limited control over it, and, when a bad actor strikes, it’s tough to pinpoint exactly where the issue came from. In effect, it allows attackers to bypass existing security systems and governance processes because employees have inadvertently smuggled them in.Â
And once they’re in, they have unrivaled access to a company’s sensitive data. They can go unnoticed for days as they mine customer records, trade secrets, and financial data. Leverage they’ll either sell or use to extort the business.
The really concerning element is that, in some businesses, shadow AI usage is actually an open secret. One given the all-clear by the top brass. A recent BlackFog survey found that 49% of workers use it, and a huge 69% of C-suite leaders gave them the green light. It’s simply not being taken seriously, and that has got to change.
In fact, getting a grip on this issue should be the first item on any Chief Security Officer’s agenda, because use of unauthorized AI tools makes any other defense they might have put in place pointless. It doesn’t matter how strong the walls of the fort are if someone has left the back door open.
How do they do that? Well, there are several measures they should consider.Â
First, businesses that are rolling out AI projects need to ensure these launches provide useful tools for employees. That might sound simple, but it’s one of the most important changes any enterprise can make.
It’s become commonplace for companies to rush AI implementation, resulting in tools that don’t fit employees’ needs and make their lives harder in some cases. When employees are being asked to use tools that don’t work properly, and they know they could speed up their day-to-day by using unauthorized platforms instead, it’s no wonder they reach for their preferred chatbot.
Because, ultimately, they aren’t using these tools with malicious intent, they’re using them to keep up with expectations. Boards and executives often expect to see productivity jump as soon as an AI rollout is live, so if the tools aren’t useful, employees will find some that are. Approved or not.
Once they’ve made sure the AI they’re introducing is actually helpful, businesses must next do more to keep employees on it. Here I’m referring to long-term, extensive training that ensures they can use it successfully and reduces the temptation to lean on other tools.
This is also a perfect opportunity to conduct a spring clean of AI policies, and a full audit of AI usage across the business. Get employees in, encourage them to be upfront with how they’re leveraging the technology, and ensure browsers flag any unauthorized sites they are leaning on.Â
Once businesses have taken these steps, there is one other, more technical, way they can shore up their defenses: anonymizing all data that goes into AI. Replacing personal or sensitive information with tokens means that, if a hacker was to find their way into some of these unauthorized tools, they’d have a lot less to work with and could do far less damage.
Whatever route CSOs take, the important thing is that they start to take shadow AI much more seriously. Up until now, some have viewed it as an inevitability and something that comes with the territory of running a business in the 21st century. But that’s a dangerous mindset.
There’s no doubt in my mind that it will drive cyber risk higher over the coming year, and business leaders must make getting employees on authorized technology priority number one. If they don’t get this under control now, they are effectively leaving the back door unlocked and inviting cybercriminals in.
Â
Join our LinkedIn group Information Security Community!











