Every company now has AI, but it did not deploy. Employees paste customer records into a chatbot to draft a reply, run spreadsheets through a free analysis tool, and connect AI assistants to email and calendars without asking anyone.

The work gets done faster. The data goes somewhere the security team cannot see. This is not a fringe habit. In a survey of US employees, 65 percent said they use AI tools their employer has not approved, and 71 percent of those users admitted to feeding sensitive data into them: customer details, employee records, and internal documents.

And shadow AI is no longer just the old problem of employees signing up for unapproved apps.

The two faces of shadow AI

The first face is familiar. Employees use public AI tools, and what they paste into them can leave the company's control, get retained, or be used to improve the service, depending on the provider and the account.

A developer debugging code can paste in a script that still holds an API key or a database credential. Once that data reaches a third-party model, the company can lose the audit trail. If regulated data is involved, the transfer can trigger privacy, legal, and breach-review obligations under frameworks like GDPR or HIPAA.

The second face is quieter and harder to see. AI is now built into tools companies already approved, from help desks and CRMs to document platforms. A summarization or analysis feature, often switched on by default, uses the access already granted to that application to read and process data in new ways.

The line between approved software and ungoverned AI now runs straight through products already inside the building. Vetting a vendor two years ago is not the same as governing the AI it turned on last month.

Why the old controls miss it

Most of these rides are ordinary web traffic. AI services run over HTTPS, so without SSL inspection, which many organizations have not deployed, network monitoring and CASB tools cannot see the content of what is sent.

Embedded AI makes it worse because the data moves inside normal use of a trusted application and looks like business as usual. Traditional data loss prevention was built to catch files leaving by email or download, not text typed into an AI field inside an approved tool.

Most teams still cannot answer the first question: which AI is active across their stack, and what data is flowing into it?

What this year's winners are building

The 2026 Cybersecurity Stars Awards split the same way: discovery first, governance after.

On discovery, Nudge Security and Kanopy Security surface the AI and SaaS tools already in use, with Kanopy aimed directly at shadow AI, and Optro turns that visibility into governance.

Two winners give AI a managed path instead of an unmanaged one. Airia gives enterprises a controlled place to run AI rather than leaving each team to pick its own, and Arnica pushes governance to where AI enters the codebase: copilots, agents, and the commits they produce.

On control, LayerX Security won in AI Usage Control for governing AI inside the browser, where a lot of shadow AI starts, setting limits on what employees can paste and where. Jazz was recognized for AI-native data loss prevention, focused on sensitive data moving into AI tools rather than the file-exfiltration paths older DLP was built for.

Blocklists only go so far. Polygraf, named one of the year's Most Innovative companies, governs AI by what it is doing rather than which tool sits on a list.

The signal is not that every company needs every category. It is that shadow AI stopped being a one-control problem. It is discovery, access, data movement, browser use, and developer workflow at once.

What to do now

Find it, then govern it. Here is what that takes:

  1. Inventory the AI in use, both the unsanctioned tools and the AI features switched on inside approved SaaS. Check the release notes and settings on your top applications, and confirm where their data goes.
  2. Set a usage policy that people will follow. Say which tools are allowed and what data can go into them. Rules that are too strict only push people back toward shadow tools.
  3. Watch the data, not the domain. You cannot blocklist every new AI site. Put controls on sensitive data moving into AI fields: PII, source code, credentials, customer records, and internal documents. Close the SSL-inspection gap where you can.
  4. Give a governed alternative. A sanctioned, logged AI option removes the main reason people go around security in the first place: speed.

Treating shadow AI as something to keep out is the losing move. The harder problem is the AI already sitting inside approved tools, approved workflows, and approved vendors. The software you already paid for is now the software you have to watch.


Part of The Stars Briefing, our editorial series on the trends behind the 2026 Cybersecurity Stars Awards, a program The Hacker News runs. This piece analyzes where the field is moving and uses the winners as examples. It is not a product review. The complete list of 2026 winners is live at awards.thehackernews.com/winners/2026.