Application security, AI/ML, AI benefits/risks, Identity, Decentralized identity and verifiable credentials, Governance, Risk and Compliance

Shadow AI expands attack surfaces beyond visibility

AI Artificial Intelligence technology for data analysis, research, planning, and work generate. Man uses a laptop and AI assistant dashboard. Technology smart robot AI agents and agentic workflows.

COMMENTARY: Almost a third of U.S. adults report that they’re still afraid of the dark. It’s easy to understand why: we can’t protect ourselves against threats we can’t see. Shadow IT keeps enterprise security leaders awake at night for the same reason.

But as AI adoption booms and machine identities proliferate, organizations are facing a new era of unseen risk. Now, attack surfaces aren’t only growing, they’re outmaneuvering traditional governance and enforcement models. 

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

The solution isn’t just better visibility. When innovation and operational debt outpace security, seeing risk exposure is less important than controlling it. In the AI era, the defining security challenge isn’t just identifying what’s hiding in the dark but proactively defending against it in real time. 

Shadow AI: A familiar problem, amplified

Nearly 90% of organizations use AI in at least one business function, yet only 22% of U.S. workers rely exclusively on AI tools provided by their employers; that delta uncovers a massive shadow AI gap. 

This is a fundamentally familiar issue — business units have long adopted unsanctioned applications, collaboration tools, or cloud services. But security has lagged behind AI hype and innovation. 

AI integrations span SaaS platforms, cloud workloads, APIs, and internal data repositories. Machine-to-machine trust is expanding. Automated actions trigger across systems in real time. The result is a dramatic increase in: 

  • Data access pathways
  • Identity-to-application trust relationships
  • Cross-platform automation
  • Embedded third- and fourth-party dependencies

As a result, 57% of organizations have seen an uptick in security incidents linked to AI usage; access paths are expanding faster than governance can mature. Nearly two-thirds of organizations don’t have the necessary policies to manage AI or detect shadow AI.  

Meanwhile, rising AI adoption intersects with another notorious security blind spot.  

The machine identity majority 

AI adoption is exacerbating a quieter, structural shift inside enterprise environments: the explosion of non-human identities. 

Machine identities like service accounts now significantly outnumber human users, making up about 70% of networked identities. These identities are notoriously over-privileged and under-monitored. For example, just 2.6% of workload identity permissions are actually used, and 51% of workload identities are completely inactive. They interact across multiple systems, lack rotation controls, and bypass traditional monitoring models.


Related reading:


The overlap between shadow AI and machine identities means attack surfaces aren’t just expanding, they’re translating to widespread exposure — with rampant business risk. 

The cost of uncontrolled spread

The evolving threats transforming the risk landscape have a tangible business impact. The average cost of a data breach is $670,000 higher for organizations with high levels of shadow AI, and it takes 247 days to identify and contain a breach involving shadow AI — yet attackers can compromise over 60% of an environment in less than an hour

Importantly, though, the true cost of a cyber incident lies with uncontrolled spread. Modern sprawling networks and risk realities make it easier for attackers to escalate minor footholds into business-wide disruptions, triggering: 

  • Operational downtime 
  • Regulatory exposure 
  • Reputational damage
  • Cyber insurance scrutiny
  • Board-level escalation

The cumulative effect is difficult to quantify, but recent highly publicized breaches show how easily attackers can capitalize on ballooning attack surfaces and hide behind network complexity. In Jaguar Land Rover’s 2025 attack, threat actors relied on stolen credentials, excessive permissions, and tightly interconnected environments to force a five-week production shutdown that sent shockwaves across 5,000-plus associated businesses and ultimately cost the manufacturer an estimated $2.5 billion, making it the most financially damaging cyber event in UK history.  

Why traditional controls and IR playbooks fall short

Traditional enterprise security architectures were designed around relatively stable assumptions:

  • Assets were known and inventoried
  • Communication paths were predictable
  • Authentication was primarily human-centered
  • Trust boundaries were clearly defined

Modern environments break those assumptions.

AI agents initiate API calls dynamically. Plug-ins connect platforms that were previously isolated. Hybrid and multi-cloud architectures blur perimeters entirely. Meanwhile, machine identities operate with persistent privileges and limited oversight. 

These sprawling modern networks have grown beyond traditional security models. A single compromised API key, over-permissioned service account, or unsanctioned AI integration can lead to uncontrolled lateral movement. 

The result is not necessarily more breaches, but bigger, more impactful ones. Why? Traditional incident response strategies weren’t built for this new landscape. Typical IR playbooks assume that defenders can observe anomalous behavior, investigate it, and coordinate containment before business impact escalates. Widespread AI adoption challenges those assumptions due to: 

  • Speed: AI-driven processes operate faster than human response cycles.
  • Parallelism: Access decisions and automated actions occur simultaneously across multiple systems.

When innovation out-scales control, detection and response are insufficient. By the time anomalous behavior is identified, compromised identities may have already traversed multiple systems, exploiting implicit trust relationships and poorly mapped data dependencies.

In this context, incident response becomes reactive damage control rather than proactive risk reduction. These new risk realities aren’t creating architectural fragility, they’re just exposing existing gaps. 

We have to progress beyond detect-and-respond mindsets toward environments designed to absorb, isolate, and withstand compromise — particularly in an era of constantly evolving threats. 

Architecting dynamic defenses for a new threat landscape 

Enterprises don’t need more alerts or better dashboards — they need architectures built to reflect modern risk realities. Networks should be designed to assume: 

  • New tools will be adopted outside formal approval processes
  • Machine identities will continue to proliferate
  • Some credentials will be compromised, and breaches will occur
  • Some integrations will introduce unforeseen exposure
  • Vendor, contractor, and other third-party connections will introduce unseen risk 

This requires a strategic realignment. Rather than chasing alerts or building higher walls, organizations must design environments that minimize trust and shrink blast radius by design, containing and collapsing the blind spots where threat actors hide. 

In practice, this means maintaining end-to-end visibility into network behavior and dynamically adapting security policies as changes occur. It means enforcing real-time, identity-based access controls at the network layer to neutralize stolen credential threats. And critically, it means proactively isolating network assets in distinct security zones, so a minor breach never cascades into a business crisis. 

Today’s networks are tangled, multi-layered digital landscapes. In these environments, risk is no longer static — it’s a shapeshifting constant. While shadow IT once meant unknown software at the edges of the network, the shadows now live in identities, integrations, and inherited trust. 

The only durable advantage for defenders in the AI era is building a dynamic defense fabric by combining network and identity controls to remain resilient against threats lurking in the shadows — and even hiding in plain sight.

Chris Boehm

Chris Boehm is Field CTO, Zero Networks. He has 15-plus years in cybersecurity, spanning public sector IT, cloud engineering, and executive leadership.

You can skip this ad in 5 seconds