Shadow AI and agentic risk
Artificial-intelligence security
AI changes the speed of the attack and the internal surface. Shadow AI, context leaks and agentic cybersecurity require governance, not enthusiasm.
- For whom.
- Leadership that already has AI tools in use, with or without an inventory.
- Scope and deliverable.
- A distinction between models that suggest and agents that execute; an inventory of uses, data and permissions.
- Limit.
- It does not implement models or audit the code of AI vendors.
Perspective
AI changes the speed of the attack and the internal surface. Shadow AI does not wait for the innovation committee.
Governing agents that execute is not the same as governing a chatbot that suggests. That distinction is already a board decision.
Common risks
- Contracts and code pasted into models without a contract.
- Agents with production permissions.
- Innovation enthusiasm without an honest inventory.
Questions for a board
- Which AI tools are used with company data today, with or without a licence?
- Which data must never leave?
- Who answers if a model has already taken a contract?
- Do we distinguish between suggesting and executing?