Shadow AI: Unseen Tools Proliferate in Organizations, Exposing Security Concerns
Shadow AI Is Running Rampant: 74% of Organizations Have More AI Tools Than They Know About
Most companies thought they had a handle on their AI deployments. New research suggests they were wrong by a significant margin — and the security implications are serious.
Research from ThreatDown reveals that 74% of organizations are running more AI tools than they anticipated as of August 2026. A majority of companies surveyed expected five or fewer tools deployed in their environments. However, 30% of those same organizations discovered 16 or more were actively running — a finding that has rattled cybersecurity leaders across industries.
The phenomenon has a name: shadow AI. Much like shadow IT — the unauthorized use of technology within organizations before it, shadow AI refers to artificial intelligence tools adopted by employees or departments without the knowledge or approval of IT and security teams. The difference this time is that the stakes are considerably higher.
The Scale of the Problem Is Catching Organizations Off Guard
The ThreatDown research exposes a striking gap between perception and reality. Actual workforce AI use registered at a median of 58% — nearly double the 33% that organizations expected. That discrepancy is not a rounding error. It represents thousands of ungoverned tools quietly operating inside enterprise environments.
Diana Kelley, Chief Information Security Officer at Noma Security, described the finding as a confirmation of what many in the industry have long suspected. "The fact that 74% of organizations found more AI tools than they expected — and that actual workforce use was a median 58% versus an expected 33% — underscores the shadow AI reality that many organizations and CISOs are struggling with right now," she said.
Kelley warned that the problem is compounding as AI evolves. "That governance gap becomes more serious as AI continues to shift from people-driven use to agent-driven action that can access sensitive data, run code, and connect to other tools and services," she added. "You can't govern what you can't see, and with agentic AI, unknown access can quickly become enterprise harm."
Pathlock's 2026 AI Governance Gap Report adds further weight to these concerns. That research found that 51% of organizations are unsure whether they know all the AI agents operating in their enterprise systems — a figure that Chris Radkowski, GRC Expert at Pathlock, described as consistent with what his team is observing directly.
The Governance Gap Is Widening in Real Time
The speed at which AI tools are being adopted internally — often without procurement cycles, IT review, or security sign-off — means governance frameworks are perpetually behind. Understanding the key risks and challenges artificial intelligence presents to businesses is no longer optional for security teams; it is foundational to building any effective response.
The core issue is not that employees are acting in bad faith. Most are reaching for AI tools because those tools make their work faster and more effective. The problem is that speed of adoption has outpaced the institutional structures designed to keep sensitive data and systems secure.
Why Traditional Security Tools Are Failing to Keep Up
The core challenge is architectural. Legacy security tools were not designed to monitor AI agents operating across interconnected systems in real time.
Randolph Barr, Chief Information Security Officer at Cequence Security, pointed to a fundamental shift in how software gets deployed. "It used to be that rolling out an application required engineering or IT, and that requirement was a built-in checkpoint," he said. "AI erased it. Now anyone with a browser can wire up an agent over lunch."
Barr described scenarios his team has observed firsthand — users spinning up agents with personal credentials, connecting to unapproved models, and testing against production data containing sensitive information. The pressure from organizational leadership to adopt AI quickly is creating exactly the conditions that breed shadow AI.
Static Audits Cannot Keep Pace With Autonomous Agents
Gal Moyal, from the CTO Office at Noma Security, outlined why existing security frameworks are structurally insufficient. Static compliance audits measure security posture at a fixed point in time. Autonomous AI agents constantly change their connection points and execution paths. By the time a periodic audit is completed, the environment it assessed may already look completely different.
Moyal also highlighted the speed problem with alert-based detection. "In the time required for a Security Operations Center team to triage an alert, an automated agent executing a multi-stage payload can map internal networks, exfiltrate sensitive data, and modify production systems," he explained.
Traditional Identity and Access Management systems face a similar limitation. Standard IAM can verify whether a service account has permission to access a resource — but it cannot evaluate the intent behind a specific action within a chain of agent behaviors. As Moyal put it: "An agent might be privileged to remove a file, but that privilege can be abused to wipe the whole drive."
The Pressure to Adopt Quickly Is Part of the Problem
It is worth acknowledging that shadow AI does not emerge in a vacuum. Organizational pressure to demonstrate AI productivity gains, combined with the structural and cultural barriers that slow formal AI adoption, creates a predictable outcome: employees find their own path forward. When approved tools are slow to arrive or difficult to access, ungoverned alternatives fill the gap. Security teams must account for this dynamic when designing governance programs — friction in formal channels directly fuels shadow deployments.
What Security Teams Should Do Now
Security experts agree that the solution is not to block AI adoption. The goal is to govern it before shadow deployments create irreversible damage.
Barr offered a direct prescription: "Start with the oldest rule in security — you can't protect what you can't see. Get visibility into what's actually running, not what's on the approved list." He emphasized choosing controls that allow the business to move quickly. If governance feels like a roadblock, employees will simply route around it.
Radkowski echoed that philosophy. "Organizations shouldn't try to stop employees from adopting useful AI," he said. "The goal is making sure that adoption happens within security and governance frameworks, not outside them."
Priority Capabilities Organizations Should Build Now
Security experts identified several capabilities organizations should establish as a matter of urgency:
- Behavioral agent discovery that detects ungoverned agents, autonomous swarms, and shadow tools across the entire software supply chain in real time
- Protocol-level governance enforcing adaptive access controls between agents and downstream systems, with explicit authorization required for high-risk operations
- Inline behavioral interception transitioning from reactive alerts to real-time AI Detection and Response that blocks unauthorized actions before execution completes
Treat AI Agents as Identities, Not Tools
Radkowski stressed that AI agents must be treated as identities rather than simple tools. That means maintaining a live inventory of agents and their permissions and continuously monitoring transaction-level activity — not just asking what an agent is allowed to do, but tracking what it is actually doing across connected systems.
For further context on how security researchers and industry bodies are framing these risks, the NIST AI Risk Management Framework provides a structured approach that organizations can use as a foundation for internal governance policy.
The research arrives at a critical inflection point. AI adoption is accelerating faster than governance frameworks can adapt. For security teams, the window to establish foundational controls is narrowing — and the organizations that act now will be significantly better positioned than those waiting for a governance crisis to force their hand.