Full Report
AI tools let non-technical employees build workplace apps in minutes with natural language prompts. While these AI-generated apps boost productivity, they can create severe security and data risks. As Cybersecurity Awareness Month kicks off, we’re sharing how Tenable adopted a structured governance framework that allows our “citizen coders” to build secure and compliant apps with AI.Key takeawaysUnsanctioned applications that non-technical staff build using AI tools often bypass quality assurance and testing, creating shadow AI risks. Without IT and security oversight, these applications can go into use with critical vulnerabilities and misconfigurations, as well as weak data protection.Even when “citizen coders” comply with their organizations’ policies and processes, the number of applications they build using AI tools can become overwhelming and disruptive for the IT and security teams.Governance works better than blanket bans, because prohibiting AI-aided development usually causes employees to keep their app development activities hidden. Tenable has found that implementing a structured, multi-tiered governance framework gives employee citizen coders the security and compliance guardrails they need.An effective governance framework should combine peer leadership and training. While AI leaders in each department are tasked with overseeing tool approvals, managing app dev request queues, and tracking applications’ ROI, “citizen coders” should receive mandatory security and compliance awareness training.AI tools are making it easier than ever for non-technical employees to spin up workplace applications in minutes. Even staffers who have never written a single line of code, let alone set up a database, are jumping on the AI vibe-coding bandwagon, often encouraged by their team leadersFirst, the good news: These AI-generated applications can help boost employees’ productivity by automating workflows and streamlining processes. And if employees can build their own applications, the workload on your perennially busy professional developers shrinks.Now the bad news: If employees whip up and deploy them without the oversight of the IT and security teams, these applications become shadow AI assets with security and compliance issues that put your systems and data at risk.Even in scenarios where employee citizen coders adhere to company guidelines, the sheer number of AI-built applications they produce can easily swamp IT and security teams, a trend that’s intensifying as business leaders urge non-technical staffers to use AI to develop their own software tools.So how can an organization address this threat from employee citizen coders? Spoiler alert: A draconian, across-the-board prohibition won’t work, and in fact will likely backfire, as employees may then deliberately try to hide their AI-aided application development activities. In this blog, the first in Tenable’s weekly Cybersecurity Awareness Month series, we’ll share lessons learned and concrete best practices from Tenable’s internal cybersecurity team aimed at establishing policies and controls designed to curb this shadow AI risk from your employee citizen coders.The risks from citizen coders’ applicationsThe cyber risks of unsanctioned applications that employee citizen coders build aren’t new. The issue rose to prominence years ago when low-code / no-code development platforms gained widespread popularity. Of course, generative AI tools that can create fully-functioning applications from a natural-language prompt have exacerbated the issue by turning practically anyone into a developer. And unlike low-code / no-code platforms hosted as software-as-a-service (SaaS) and monitored by the organization, generative AI products tend to be consumer-grade tools that employees can access and use individually.These citizen coder applications can create a wide variety of security and compliance risks, as organizations, including the Open Worldwide Application Security Project (OWASP) in its OWASP Citizen Development Top 10 list, have documented.Below, we highlight common security and compliance issues in AI-generated citizen-coder applications that employees create without permission and oversight from the IT and security departments:Due to lack of testing, scanning, and quality assurance checks, their code can have critical vulnerabilities and dangerous misconfigurations, as well as contain risky open-source components.They may insecurely access company critical systems and store sensitive data.They will not be updated, patched, monitored, logged, nor be included in backup and disaster recovery plans.They may have excessive permissions and privileges, and the organization’s identity and access management (IAM) systems won’t protect them.Even when employee “citizen coders” alert and involve the IT and security teams, organizations are finding that the number of these applications has spiked to such a degree that it’s become burdensome to review, approve, and onboard them. In other words, in an average large organization there may be hundreds of employees building applications that they feel are worth seeing the light of day. IT and security suddenly face the daunting task of assessing each one, and deciding which are truly worth the cost and effort of securely deploying and maintaining them throughout their lifecycle.If these applications consume AI tokens to function, costs can add up quickly. For example, it’s not uncommon for citizen coders to leverage their legitimate access to business applications and create their own local data lakes to help power their vibe-coded application. In addition to the cost issue, the creation of these siloed data lakes creates dangerous data sprawl. A five-tier governance model for AI useAt Tenable, we allow non-technical citizen coder employees to develop workplace applications, and as such, we’re not immune to the risks outlined above. However, we have found that establishing a strong governance foundation goes a long way towards preventing problems, not just the ones associated with citizen coders but with overall employee AI usage.Specifically, Tenable has implemented a comprehensive five-tier AI governance framework, where at one end the executive leadership sets the direction, while at the other end lies daily community use guided by clear policies and peer oversight.In the case of citizen coders specifically, this means, for example, that the do’s and don’ts of AI-aided citizen coding aren’t determined by individual business units independently, but are rather established uniformly company-wide.These are the five tiers of Tenable’s AI Governance Model.Tier 1: Strategy The Executive Staff charts the course by providing strategic alignment, investment guidance, and prioritization for AI initiatives.Tier 2: GovernanceAn AI Governance Board and AI Technical Council create AI policies and guidance documentation, such as lists of approved AI tools. They explicitly own compliance, data privacy, and model risk, while also overseeing AI tool enablement, architecture, and design.Tier 3: ExecutionAI Functional Leads and R&D Champions drive specific use cases, manage departmental adoption, and measure productivity results.Tier 4: EnablementThe Enablement Working Group, led by IT, Learning & Development (L&D) and Corporate Communications, handles hands-on training, resource distribution, and enterprise demonstrations.Tier 5: CommunityDedicated Slack channels for AI usage questions, AI engineering, and other topics offer employees support and a forum for crowdsourcing solutions. With respect to citizen coders specifically, this AI governance model helps Tenable ensure that our IT and security experts establish foundational protections, guardrails, and controls for AI-generated applications. That’s because groups within the governance framework own the requirements for issues such as data privacy, compliance, and model risk, as well as for AI tool enablement, design, and architecture.The critical role of AI Functional LeadersA key element for mitigating citizen coder risks are Tenable’s AI Functional Leaders, which sit on the governance framework’s third tier — execution. Originally conceived as simple project coordinators, this group now operates within a strict governance role with direct authority and accountability over AI skill approvals, operational queues, and organization-wide AI adoption.These leaders are accountable for all AI use, development, and deployment across their respective departments. For example, there are AI Functional Leaders in sales, tech support, marketing, human resources, legal, infosec, finance, engineering, product management, and several other departments.AI Functional Leads are heavily involved in their department’s use cases. By overseeing all requests for new skills, connectors, and data access, the AI Functional Leads can flag, for example, the use of unvetted external AI components in citizen coder applications before they reach production.The importance of AI security awareness training for citizen codersSecurity and compliance issues related to AI usage, including applications citizen coders build, usually stem from a lack of knowledge about how to prevent these problems. That’s why Tenable has tied AI tool access directly to mandatory security training and responsible usage training, and in turn complements it with live webinars, pre-built courses, tool-specific deep dives, and weekly show-and-tell sessions. This way, employees in general, and citizen coders in particular, know they have access to vetted resources and expert peer support.Looking aheadThe citizen coder revolution is here to stay. Non-technical employees equipped with generative AI tools will continue to build applications, especially as their team leaders nudge them to experiment with vibe coding.At Tenable, we have found that implementing a solid governance framework provides a critical foundation for mitigating the risks associated with employees’ AI use, and specifically offers citizen coders guardrails to securely build AI-generated applications that help boost their productivity and efficiency. Have we completely solved the security and compliance challenges from citizen coder-built applications? Not by a long shot. The risks from employee vibe coding, along with those from AI use in general, are constantly morphing. But we feel that our governance framework gives us a solid foundation for tackling these and other AI usage challenges, as they emerge and evolve. Our Cybersecurity Awareness Month blog series continues next week, when we’ll tackle the challenges that critical infrastructure organizations face today.
Analysis Summary
# Best Practices: Mitigating Shadow AI and Citizen Coder Risk
## Overview
These practices address the security and compliance risks associated with "vibe-coding"—the trend of non-technical employees using generative AI to build workplace applications. The goal is to move from blanket bans (which drive activities underground) to a structured governance framework that provides guardrails for decentralized development.
## Key Recommendations
### Immediate Actions
1. **Publish an Approved AI Tool List:** Establish and communicate a clear list of vetted AI tools to prevent the use of high-risk, consumer-grade generative AI products.
2. **Establish a Multi-Tiered Governance Board:** Form an AI Governance Board and Technical Council to own compliance, data privacy, and model risk.
3. **Mandatory Training for Access:** Tie access to AI tools directly to the completion of mandatory security and responsible usage training.
### Short-term Improvements (1-3 months)
1. **Appoint AI Functional Leads:** Assign leaders within each department (Marketing, HR, Finance, etc.) to manage application dev request queues and track ROI.
2. **Implement Request Workflows:** Require employees to submit requests for new "skills," connectors, and data access to their departmental AI Functional Lead.
3. **Deploy Monitoring Channels:** Create dedicated Slack or communication channels for AI usage support to crowdsource solutions and provide peer oversight.
### Long-term Strategy (3+ months)
1. **Centralize AI Strategy:** Integrate the Executive Staff (Tier 1) into the framework to provide strategic investment guidance and prioritization for AI initiatives.
2. **Automate Security Guardrails:** Integrate citizen-coder applications into existing Identity and Access Management (IAM), logging, and disaster recovery plans.
3. **Formalize an Enablement Working Group:** Establish a group led by IT and Learning & Development (L&D) to conduct weekly show-and-tell sessions and resource distribution.
## Implementation Guidance
### For Small Organizations
- **Focus on Training:** With fewer resources, prioritize security awareness training so employees can self-police.
- **Single AI Lead:** Designate one person (likely the CTO or IT Manager) to act as the "Functional Lead" for all departments.
### For Medium Organizations
- **Implement Tiered Governance:** Focus on Tiers 2 (Governance) and 3 (Execution) to ensure departmental leads are vetting tool use before it hits production.
- **Departmental Templates:** Provide secure templates for AI prompts and data connectors.
### For Large Enterprises
- **Full Five-Tier Model:** Implement the complete Tenable model, from Executive Strategy to Community support.
- **Audit Data Lakes:** Actively monitor for "local data lakes" created by citizen coders to prevent dangerous data sprawl and excessive token costs.
## Configuration Examples
*While the article focuses on governance, the following technical guardrails are implied:*
- **Connector Restrictions:** Configure enterprise AI tools to only allow data connectors to approved, vetted internal databases.
- **IAM Integration:** Ensure all AI-generated apps utilize SSO (Single Sign-On) rather than local credentials.
- **Token Quotas:** Set departmental spending limits on AI API keys to prevent runaway costs from inefficient citizen-coded scripts.
## Compliance Alignment
- **OWASP Citizen Development Top 10:** Addressing vulnerabilities, misconfigurations, and insecure data storage.
- **NIST AI Risk Management Framework (AI RMF):** Specifically regarding governance, mapping, and measuring AI risks.
- **ISO/IEC 42001:** Alignment with AI Management System standards.
## Common Pitfalls to Avoid
- **Blanket Bans:** Prohibiting AI development usually leads to "Shadow AI," where employees hide their activities from IT.
- **Ignoring ROI:** Failing to track the costs of AI tokens and the productivity gains of citizen-built apps.
- **Siloed Data:** Allowing employees to create local data lakes that bypass enterprise data governance.
- **Skipping QA:** Letting apps go live without basic security scanning or testing just because they were built with natural language.
## Resources
- **OWASP Citizen Development Top 10:** [h]ttps://owasp.org/www-project-citizen-development-top-10/
- **Tenable AI Governance Framework:** Five-tier model documentation.
- **NIST AI RMF:** [h]ttps://www.nist.gov/itl/ai-risk-management-framework