Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Photo of Trump in Moscow is real, but not from his first visit in 1987

    August 23, 2026

    One Nation MP concedes party’s migration target ‘not too different’ from Labor’s once rural workforce included | Australian politics

    August 23, 2026

    Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

    August 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Photo of Trump in Moscow is real, but not from his first visit in 1987
    • One Nation MP concedes party’s migration target ‘not too different’ from Labor’s once rural workforce included | Australian politics
    • Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments
    • CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
    • Morning Minute: CFTC Will Give Crypto Clarity If Congress Won’t
    • Tooth count may predict survival after pancreatic cancer surgery
    • Australia news live: Sydney Marathon admits ‘unfortunate error’ as finisher’s medal depicts Munich stadium as highlight of course | Australian politics
    • Inherent, founded by DeepMind alumni, says its AI ‘teammate’ just outperformed Anthropic and OpenAI at replicating research
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Why “Shady AI” is Security’s Next Big Governance Problem

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 23, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.

    The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee followed its advice, inadvertently making a large volume of sensitive data available to unauthorized engineers for over two hours.

    This was not shadow AI. The tool was approved, but the AI behaved in ways nobody had anticipated.

    It’s a perfect example of security’s next big AI governance problem: shady AI.

    • Shadow AI is the unapproved use of AI tools
    • Shady AI is when employees use approved AI tools in unapproved, unexpected, or poorly governed ways

    Shadow AI happens outside the organization’s visibility. Shady AI happens inside it. And that makes it much harder to see, control, and govern.

    The rise of shady AI

    AI governance isn’t solely a security responsibility. But when AI touches sensitive data, enterprise systems, or access controls, security has a critical role to play. A July 2026 SANS survey found that 76% of security teams now have a role in governing enterprise AI.

    But security teams don’t just need to worry about shadow AI. They need to think about shady AI, too.

    The difference matters because approving a tool is no longer the same thing as approving its use.

    You can block or ban an unsanctioned tool, but you can’t simply block something you’ve already approved and rolled out across the organization. The control lever security teams are used to pulling doesn’t exist here.

    Like shadow AI, shady AI has real consequences:

    • Security risks like increased exposure to data breaches, regulatory incidents, and data exfiltration
    • Financial costs from rising AI spend, including tokens spent on duplicative or unimportant tasks
    • Organizational drag as tightened controls block innovation and increase friction for employees
    • Security and IT team burnout as time is spent on retroactive governance and tool audits instead of proactively reducing the attack surface and strengthening access controls

    What’s driving shady AI?

    There are three main reasons why shady AI is happening now.

    1. The proliferation of approved AI tools

    As organizations continue to invest in AI tools, the opportunities for shady AI grow. Like SaaS sprawl before it, increased adoption creates a larger, more complex AI tech stack for security and IT to govern. With limited resources, it’s increasingly difficult to understand how every AI capability is being used across every tool and system.

    2. Permissions are broad by default

    AI is now woven into the tools that employees already use, and the functionality expands faster than security teams can keep up. An approved AI assistant might start as a way to summarize documents, then gain the ability to search internal knowledge, access business applications, create workflows, or take actions on an employee’s behalf.

    Enterprise-grade compliance and security features – like restricting AI tool usage to devices on a company domain – are often gated behind the most expensive licensing tiers, while the AI features themselves are available by default.

    The tool hasn’t necessarily changed from a governance perspective. What employees can do with it has.

    3. Usage patterns evolve faster than policy can

    Employees can use AI embedded into approved tools to build applications and deploy them before security and IT even know they exist.

    Organizations can lock down controls to prohibit one risky practice only to find that employees have already adopted a new tool or discovered another route to the same outcome.

    The result is a widening gap between what policy says employees should do and what AI makes possible.

    What traditional governance misses

    Traditional governance is built around defining what’s allowed and training employees to follow the rules. That works better when the technology and its use cases are predictable. AI makes both moving targets.

    1. Policies can’t anticipate every use case

    An Acceptable Use Policy (AUP) can establish principles, but it can’t anticipate every new capability an AI tool might gain, or every way employees might use it.

    An approved AI assistant might be cleared for summarizing documents today, then gain the ability to search internal knowledge, access business applications, create workflows, or take actions on an employee’s behalf tomorrow.

    2. Training can’t keep pace

    One-time training can’t account for constantly evolving AI capabilities and usage patterns. Many non-technical employees also don’t yet have a mental model for secure, responsible AI use.

    The rules are written in a vocabulary nobody taught them, making it difficult to apply principles like least privilege or secrets management.

    3. Restrictions create workarounds

    Locking down individual capabilities can address a specific risk, but it doesn’t solve the underlying problem. As AI capabilities evolve, employees may find another way to accomplish the same task – potentially making usage harder for security to see.

    The result is a governance model that’s always playing catch-up.

    What actually works: governance by default

    The answer is making the easiest, most visible path the governed one.

    In practice, this means giving employees a place to build with AI where the necessary permissions, access controls, and oversight are built in — rather than relying on employees to figure out the rules themselves.

    Instead of trying to predict every risky AI use case in advance, organizations can build governance into the environment where employees create and deploy AI-assisted workflows.

    That means controlling access to data and systems, applying appropriate permissions, maintaining visibility into what has been built, and putting controls around what AI-powered applications and agents can do.

    When creation, execution, and monitoring take place within a single environment, everybody benefits:

    • Employees can build and deploy fast within security-mandated boundaries, and use their unique subject matter expertise to solve problems, enhance workflows, and make meaningful improvements to their day-to-day work
    • IT and security teams can maintain visibility, apply consistent controls, reduce manual governance work, and scale AI adoption with confidence

    Governance stops being a roadblock. Instead, it’s the path of least resistance.

    From blocker to strategic enabler

    Security doesn’t need to choose between enabling AI adoption and mitigating risk. The goal is to make the governed path an easy one for employees to follow.

    By empowering employees to build in a secure environment with access only to tools and data they’re authorized to use, security can spend less time chasing unexpected AI usage and more time proactively reducing the attack surface, strengthening access controls, and enabling the business to move faster.

    That’s the approach behind Tines 3B, which gives teams the power to build AI-assisted apps, agents, and automations while giving security and IT teams the control and visibility to govern them. Get started for free with the Explore Edition.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    big Governance problem Securitys Shady
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

    Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

    Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Photo of Trump in Moscow is real, but not from his first visit in 1987

    August 23, 2026

    One Nation MP concedes party’s migration target ‘not too different’ from Labor’s once rural workforce included | Australian politics

    August 23, 2026

    Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

    August 23, 2026

    CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

    August 23, 2026
    Latest Posts

    Satirical fake Guardian front page on ‘genetic links’ between eating bacon and far-right activism shared as genuine – Full Fact

    July 28, 2026

    U.S. Foreign Policy Must Prioritize Human Rights

    July 28, 2026

    Madison revisits police body cameras after years of debate

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Photo of Trump in Moscow is real, but not from his first visit in 1987

    August 23, 2026

    One Nation MP concedes party’s migration target ‘not too different’ from Labor’s once rural workforce included | Australian politics

    August 23, 2026

    Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

    August 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.