Shady AI: The Next Big Governance Problem in Cybersecurity
The increasing use of approved AI tools in unapproved ways is creating a new governance problem for cybersecurity teams, known as 'shady AI'

The use of artificial intelligence (AI) in organizations is becoming increasingly prevalent, and with it, a new governance problem is emerging. This problem, known as 'shady AI', refers to the use of approved AI tools in unapproved, unexpected, or poorly governed ways. A recent incident at Meta, where an internal AI agent exposed sensitive company and user data to unauthorized employees, highlights the risks associated with shady AI.
## The Rise of Shady AI Shady AI is distinct from 'shadow AI', which refers to the unapproved use of AI tools. While shadow AI occurs outside of an organization's visibility, shady AI happens inside the organization, making it harder to see, control, and govern. According to a recent SANS survey, 76% of security teams now have a role in governing enterprise AI, but they face significant challenges in addressing the issue of shady AI.
## What's Driving Shady AI? There are three main reasons why shady AI is becoming a significant problem. Firstly, the proliferation of approved AI tools is creating more opportunities for shady AI to occur. Secondly, permissions are often broad by default, allowing employees to use AI tools in ways that may not be intended. Thirdly, usage patterns are evolving faster than policy can keep up, making it difficult for organizations to anticipate and mitigate the risks associated with shady AI.
## Governance Challenges Traditional governance approaches are struggling to keep pace with the evolving nature of AI. Policies can't anticipate every use case, and training can't keep up with the constantly changing AI capabilities and usage patterns. Restrictions can create workarounds, and the result is a governance model that's always playing catch-up. The following table highlights the challenges associated with shady AI:
## Governance by Default The answer to addressing the challenges of shady AI is to make the easiest, most visible path the governed one. This means giving employees a place to build with AI where the necessary permissions, access controls, and oversight are built in. By controlling access to data and systems, applying appropriate permissions, maintaining visibility into what has been built, and putting controls around what AI-powered applications and agents can do, organizations can create a governance model that's proactive and effective.
## From Blocker to Strategic Enabler Security teams don't need to choose between enabling AI adoption and mitigating risk. By empowering employees to build in a secure environment with access only to tools and data they're authorized to use, security can spend less time chasing unexpected AI usage and more time proactively reducing the attack surface, strengthening access controls, and enabling the business to move faster. This approach requires a fundamental shift in how organizations think about governance, from a blocker to a strategic enabler.





