The Hacker News

Why "Shady AI" is Security's Next Big Governance Problem

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee followed its advice, inadvertently making a large volume of sensitive data available to unauthorized engineers for over two hours.

This was not shadow AI. The tool was approved, but the AI behaved in ways nobody had anticipated. It’s a perfect example of security’s next big AI governance problem: shady AI.

  • Shadow AI is the unapproved use of AI tools.
  • Shady AI is when employees use approved AI tools in unapproved, unexpected, or poorly governed ways.

Shadow AI happens outside the organization's visibility. Shady AI happens inside it. And that makes it much harder to see, control, and govern.

The rise of shady AI

AI governance isn't solely a security responsibility. But when AI touches sensitive data, enterprise systems, or access controls, security has a critical role to play. A July 2026 SANS survey found that 76% of security teams now have a role in governing enterprise AI.

But security teams don't just need to worry about shadow AI. They need to think about shady AI, too. The difference matters because approving a tool is no longer the same thing as approving its use. You can block or ban an unsanctioned tool, but you can't simply block something you've already approved and rolled out across the organization. The control lever security teams are used to pulling doesn't exist here.

Like shadow AI, shady AI has real consequences:

  • Security risks like increased exposure to data breaches, regulatory incidents, and data exfiltration
  • Financial costs from rising AI spend, including tokens spent on duplicative or unimportant tasks
  • Organizational drag as tightened controls block innovation and increase friction for employees
  • Security and IT team burnout as time is spent on retroactive governance and tool audits instead of proactively reducing the attack surface and strengthening access controls

What’s driving shady AI?

There are three main reasons why shady AI is happening now.

  1. The proliferation of approved AI tools - As organizations continue to invest in AI tools, the opportunities for shady AI grow. Like SaaS sprawl before it, increased adoption creates a larger, more complex AI tech stack for security and IT to govern. With limited resources, it’s increasingly difficult to understand how every AI capability is being used across every tool and system.

  2. Permissions are broad by default - AI is now woven into the tools that employees already use, and the functionality expands faster than security teams can keep up. An approved AI assistant might start as a way to summarize documents, then gain the ability to search internal knowledge, access business applications, create workflows, or take actions on an employee's behalf. Enterprise-grade compliance and security features - like restricting AI tool usage to devices on a company domain - are often gated behind the most expensive licensing tiers, while the AI features themselves are available by default. The tool hasn't necessarily changed from a governance perspective. What employees can do with it has.

  3. Usage patterns evolve faster than policy can - Employees can use AI embedded into approved tools to build applications and deploy them before security and IT even know they exist. Organizations can lock down controls to prohibit one risky practice only to find that employees have already adopted a new tool or discovered another route to the same outcome. The result is a widening gap between what policy says employees should do and what AI makes possible.

What traditional governance misses

Traditional governance is built around defining what's allowed and training employees to follow the rules. That works better when the technology and its use cases are predictable. AI makes both moving targets.

  1. Policies can't anticipate every use case - An Acceptable Use Policy (AUP) can establish principles, but it can't anticipate every new capability an AI tool might gain, or every way employees might use it. An approved AI assistant might be cleared for summarizing documents today, then gain the ability to search internal knowledge, access business applications, create workflows, or take actions on an employee's behalf tomorrow.

  2. Training can't keep pace - One-time training can't account for constantly evolving AI capabilities and usage patterns. Many non-technical employees also don't yet have a mental model for secure, responsible AI use. The rules are written in a vocabulary nobody taught them, making it difficult to apply principles like least privilege or secrets management.

  3. Restrictions create workarounds - Locking down individual capabilities can address a specific risk, but it doesn't solve the underlying problem. As AI capabilities evolve, employees may find another way to accomplish the same task - potentially making usage harder for security to see.

The result is a governance model that's always playing catch-up.

What actually works: governance by default

The answer is making the easiest, most visible path the governed one. In practice, this means giving employees a place to build with AI where the necessary permissions, access controls, and oversight are built in - rather than relying on employees to figure out the rules themselves.

Instead of trying to predict every risky AI use case in advance, organizations can build governance into the environment where employees create and deploy AI-assisted workflows. That means controlling access to data and systems, applying appropriate permissions, maintaining visibility into what has been built, and putting controls around what AI-powered applications and agents can do.

When creation, execution, and monitoring take place within a single environment, everybody benefits:

  • Employees can build and deploy fast within security-mandated boundaries, and use their unique subject matter expertise to solve problems, enhance workflows, and make meaningful improvements to their day-to-day work
  • IT and security teams can maintain visibility, apply consistent controls, reduce manual governance work, and scale AI adoption with confidence

Governance stops being a roadblock. Instead, it’s the path of least resistance.

From blocker to strategic enabler

Security doesn’t need to choose between enabling AI adoption and mitigating risk. The goal is to make the governed path an easy one for employees to follow.

By empowering employees to build in a secure environment with access only to tools and data they’re authorized to use, security can spend less time chasing unexpected AI usage and more time proactively reducing the attack surface, strengthening access controls, and enabling the business to move faster.

That’s the approach behind Tines 3B, which gives teams the power to build AI-assisted apps, agents, and automations while giving security and IT teams the control and visibility to govern them. Get started for free with the Explore Edition.

Read on The Hacker News ↗ ← Back to News

Comments

No comments yet. Start the discussion.