Lurker AI: A risk that enterprises often ignore

Lurker AI: A risk that enterprises often ignore

Do your employees use AI without your knowledge? Innocent, unintentional or careless- Are they inviting new risks and threats from these backdoors?

Just a few years back, CIOs had an unusual problem to reckon with. On one hand, there was the trend of BYOD or Bring Your Own Device. On the other hand, it soon expanded into many siblings- bring your own apps, bring your own access modes and of course, bring your own risks. Today, the Shadow IT problem has donned a new avatar. It is now translating into new questions, challenges and fears in the form of AI that comes in sneakily, carelessly, invisibly and dangerously. 

With the rampant and easier-than-ever use of AI – specially GenAI- employees, departments, customers and vendors are bringing in AI for making their tasks fast, frictionless, autonomous and easy. There is no doubt that AI has made human work unprecedentedly simple, swift and productive. One can sit back by pushing a simple button and switching on an AI tool- and do everything possible under the sun. One can write emails, pop up meeting summaries, make presentations at the snap of a finger, resolve complaints, fix customer tickets, spot errors, crack issues, make killer client-briefs and what not.

But when all this happens- specially outside the purview of a well-laid-out security, procurement and IT governance template- this easy-breezy AI can easily turn into rogue and risky AI.

Where does Shadow AI prowl into your enterprise

Here’s how:

  • Sensitive data entering a chatbot through an employee’s reckless and innocent use
  • AI summaries that inadvertently share precious IP and confidential data to unknown servers
  • Employee-made GenAI tools that interconnect/import/export valuable data without IT’s radar
  • Use of LLMs besides, and inside, enterprise IT tools- without IT’s knowledge
  • Use of easily-available, but un-secured, AI services in pipelines and APIs 
  • Exploitation of third-party privileges in an insecure and ungoverned manner
  • AI’s use bypassing company’s procurement and compliance protocols
  • Imprudent exposure to malicious threats and model-poisoning
  • Risks of data leakage and corruption due to use of ill-governed GenAI
  • Poor identity configuration of AI tools used in a DIY format
  • Broad and ill-defined permissions and access for AI tools
  • An expanded attack surface that emerges abruptly with uncertain and unidentified risks
  • Unmanaged integrations and blind spots that open a new entry-point for attackers
  • Rogue agents that can exfiltrate data, manipulate records, and spread malicious instructions across enterprise data and processes
  • Huge compliance fragility and vulnerability to regulatory goof-ups
  • Penalties, investigations, and legal incidents arising out of DPDP, GDPR and HIPAA Acts
  • Foggy accountability and traceability for errors, critical issues and culprits

 

The Cost of Slippery Shadows- New AI Threats

All this is not fear on paper. It is already being manifested in several findings. The Palo Alto Networks ‘The State of Generative AI’ report shows that organisations saw on average 66 GenAI apps, with 10% classified as high risk, along with an average 6.6 high-risk GenAI apps per company; while GenAI-related DLP incidents increased more than 2.5X, now comprising 14% of all DLP incidents. Similarly, the IBM ‘Cost of a Data Breach Report, 2025’ pointed out how 63 % organisations either don’t have an AI governance policy or are still developing one. Also, as seen in Microsoft & LinkedIn Work Trend Index, 2024, 78% employees were seen to use personal AI tools at work (BYOAI). A recent Teramind ‘The Rise of AI Shadow IT’ report also underlines that 89% of workplace AI use escapes enterprise governance, not through rogue apps, but through the approved platforms organisations deployed and trusted. As many as 86 % organisations lack visibility into AI data flows and 20% organisations have experienced a Shadow AI breach. There was a 50% incidence of Unvetted integrations and plugins with browser extensions and SaaS connectors that move data between corporate systems and consumer AI services without security review- all this has been mimicking the classic shadow-IT pattern that research already links to nearly half of all cyberattacks.  There is also a survey from WalkMe that shows 78% of employees using unapproved AI. Almost 48% employees (in the Teramind report) upload PDFs, slide decks, spreadsheets, logs, and code repositories to summarise, redline, or debug, frequently containing proprietary IP, financials, or personal data (note that sensitive prompts increasingly involve legal and financial data (up to ~31%) and code (around 10%), not just generic content). Also 70-75% employees (tapping unapproved AI) admitted sharing potentially sensitive information such as customer data, employee details, or internal documents.

Fighting Shadow AI- with eyes, ears and smart hands on deck

The answer – then- lies in acceptance. Enterprises need to wake up from the bubble that everything is on the dashboard and under control. It is time that IT departments as well as other functions confront the possibility and ease of use of Shadow AI. They need AI experts, smart implementation wizards and deployment partners who can help them capture this side of AI with:

  • Proper and deep visibility into every AI area
  • Data definitions, boundary-setting and configurations with a secure-first and zero-trust mindset
  • Well-controlled architecture, gateways, discovery and traffic management for AI
  • Thorough and continuous assessment of tools, inputs and interconnections
  • Data governance and monitoring edge that aligns deeply with AI implementations
  • Expertise in permissions, access control and monitoring
  • Capabilities in strategising with AI-aligned protocols, CASB (Cloud Access Security Broker), DLP (Data Loss Prevention) tools
  • Sanctioned alternatives and ramps set for making AI accessible for employees but not at the cost of security

The Teramind report unravelled something important. If 60% employees feel that unsanctioned AI is worth the risk if it helps meet deadlines and if 48% would keep using AI tools even if explicitly banned- this is a wake-up call for enterprises to create and deploy an AI strategy that works for employees. AI should be done in a way that it integrates well, implements seamlessly and helps to empower users instead of complicating work for them. That’s where a trusted, capable, creative and on-ground-fluent AI partner is needed. To make AI work for you and your employees. Without the shadows.