Full Report
Organizations don’t realize how pervasive shadow AI has become. And as AI's capability grows, shadow use is harder to manage.
Analysis Summary
# Morning News Roll-up March 18, 2025
## Overview
Today's report focuses on the escalating risks of "Shadow AI"—the unsanctioned use of artificial intelligence tools within enterprises. Findings suggest that shadow AI is more pervasive and difficult to manage than traditional shadow IT, introducing unique risks such as autonomous "insider threat" agents and uncontrollable data exfiltration.
## Top Stories
### Shadow AI: The New Enterprise Insider Threat
- Summary: Organizations are finding significantly more unsanctioned AI tools in their environments than expected, with some reporting four times the suspected volume. The primary risks include sensitive data leakage and the emergence of autonomous AI agents that can trigger workflows and access corporate data without oversight.
- Source: hxxps://www[.]reversinglabs[.]com/blog/why-shadow-ai-is-far-riskier-than-shadow-it
### Black Hat 2026: AI Rewrites the Rules of Cybersecurity
- Summary: The annual conference highlighted the shift toward "frontier AI agents" and the security implications of autonomous models that can interact with systems independently, necessitating a rethink of traditional perimeter defenses.
- Source: hxxps://www[.]reversinglabs[.]com/blog/black-hat-2026-ai-is-rewriting-the-rules-of-cybersecurity
### The Rise of AI Worms and Excessive Agency
- Summary: New research identifies "AI worms" capable of reasoning about hosts they infect. Concurrently, the OWASP Top 10 for LLM Applications now ranks "Excessive Agency" as a top risk, where AI systems are granted too much autonomy to interface with other software and data.
- Source: hxxps://www[.]reversinglabs[.]com/blog/ai-worms-are-coming
***
# Shadow AI and Autonomous Agent Proliferation
## Key Points
- **Pervasiveness:** Surveys indicate over 70% of knowledge workers use AI tools without IT approval; 74% of organizations found more AI tools in use than they had initially suspected.
- **Data Leakage:** 38% of employees admit to uploading sensitive corporate data to unvetted AI tools.
- **Autonomous Risk:** Unlike traditional shadow IT, shadow AI involves "agents" that can trigger workflows, read data across systems, and continue operating even after an employee leaves the company.
- **Visibility Gap:** In 30% of cases, organizations discovered four times the number of AI tools they expected to find.
## Threat Actors
- **Insider Threats (Unintentional):** Employees bypassing security protocols to improve productivity using unauthorized tools.
- **Autonomous Agents:** Unsanctioned AI agents that function as persistent, unmanaged entities within a network.
- **External Adversaries:** Threat actors leveraging AI worms to infect and reason about target hosts.
## TTPs
- **Data Exfiltration via Personal Devices:** Using personal AI accounts on mobile devices to process and exfiltrate company data (bypassing corporate monitoring).
- **Excessive Agency:** AI tools granted broad permissions to interact with other applications and trigger workflows without human-in-the-loop verification.
- **Shadow Integration:** Employees installing unapproved AI coding assistants that directly interface with proprietary source code.
- **Prompt Injection:** Manipulating LLMs to disclose sensitive training data or bypass safety controls.
## Affected Systems
- **LLM Platforms:** OpenAI (representing 53% of shadow AI usage), Claude, and other public generative AI tools.
- **Software Supply Chains:** Proprietary source code repositories accessed by unvetted AI coding assistants.
- **Corporate Data Stores:** Sensitive internal documents uploaded for summarization or analysis.
- **Identity & Access Management (IAM):** Systems where AI agents have been granted persistent API access.
## Mitigations
- **Visibility and Discovery:** Implement tools to scan for and identify unsanctioned AI application usage across the network.
- **Access Control:** Utilize solutions to monitor AI-to-application interactions and provide the ability to revoke access if risk profiles change.
- **Policy Enforcement:** Establish clear governance on which AI tools are sanctioned and provide "safe" alternatives for common tasks (e.g., summarization).
- **Data Loss Prevention (DLP):** Update DLP signatures to detect sensitive data being sent to known LLM endpoints.
## Conclusion
Shadow AI represents a fundamental shift in risk from static unauthorized software to dynamic, autonomous agents. The high rate of sensitive data exposure (38%) combined with the lack of visibility (74% of orgs underestimated usage) suggests that traditional IT governance is currently insufficient. Organizations must prioritize AI-specific discovery and access management to prevent unmanaged agents from becoming persistent insider threats.