Shadow AI
,

74% of organizations exposed to shadow AI

Companies vastly underestimate how much unknown and ungoverned AI is running in their environment, creating an entirely new attack surface.

If you were to guess how many AI tools you need to monitor inside your organization right now, you’d likely be wrong, and not by a small margin. 

Research we conducted before the recent launch of ThreatDown AI Detection & Response (AIDR) revealed that:

74% of organizations were running more AI tools than they expected. 

That’s a systemic miss, not a rounding error.

That matters because of what it could hide. Someone on your team pasted a customer contract into a chatbot last week to save a few minutes. Someone else dropped in a chunk of source code to debug it faster. Neither of them thought twice about it. Both of them moved company data onto infrastructure your security team has never seen, never audited, and can’t control. Once that data gets out, there’s no pulling it back.  

This isn’t one overeager employee. If you’re one of the 74% of organizations already running more AI than you planned for, this same moment, an unreviewed tool, a quick paste, a permission granted without a second thought, is playing out in multiple departments, on multiple tools, right now. Marketing has its favorite tools. Engineering has the latest and greatest. They both make their own separate decisions about what enters and leaves your environment. Neither checks with the other, and nobody is asking legal or security. 

It gets worse. These tools don’t just take input anymore. They act. Many now run as agents: software with standing permissions to read your files, write and run code, and make decisions. They reach out to other systems through protocols like MCP (Model Context Protocol), quietly building a supply chain nobody signed off on and nobody is watching. 

If an attacker hijacks one of those shadow agents with a malicious skill, they inherit its access to everything it was trusted to touch: the files, the credentials, and the open connections into the rest of your environment.

More AI tools than you know

The companies we surveyed expected AI tool sprawl to be the exception, not the rule. Most predicted 5 or fewer tools running in their environments. 

Instead, 30% of organizations found 16 or more tools already active.

How many AI tools organizations think they are running vs reality
How many AI tools organizations think they are running vs the reality

If your organization expected a few tools but is actually running 16 or more, that means most of the AI tools your employees rely on are operating with no oversight as they process company data, execute unreviewed code, or reach out to systems nobody signed off on. 

More AI use than you expect

Tool count wasn’t the only blind spot. Surveyed companies assumed about 33% of their workforce was using AI tools. The actual median: 58%. 

What percentage of the workforce organizations think is using AI vs the reality

More usage means more exposure. Every one of those additional users is another way for company data to leave through a tool your security team doesn’t know it should be watching.

Find out what’s actually running

This is exactly the blind spot AIDR is built to close. It shows you which AI tools are actually in use across your environment, not just the ones on your approved list, so you’re governing shadow AI instead of discovering it after the fact.

Shadow AI is the new shadow IT. See it all now.Govern your AI →