I've seen this movie before.
A dozen years ago, I ran the Cloud Application Security Program at Pandora. My job was to find out what SaaS applications employees were actually using. Not what IT had approved. What was actually in the proxy logs and firewall traffic. We fed those logs into Netskope and let it tell us what was there.
The gap between what leadership thought was sanctioned and what was actually running was never small. Employees had found tools that were faster, smarter, or just more convenient than whatever the company provided, and they were using them with company data. Not maliciously. Just practically.
The AI problem in 2026 is the same problem. The tools are different. The stakes around data exposure are higher. But the core dynamic is identical: employees adopt technology faster than security teams track it, and company data flows to systems nobody reviewed.
Ask a leadership team how many AI tools their organization uses. They'll name two or three. Maybe five if they've been paying attention. Microsoft Copilot. ChatGPT. Grammarly. The AI feature in their CRM.
Then pull the proxy logs. The DNS query logs. The IdP OAuth grants. What's actually there is almost always a different number.
Twelve tools. Eighteen. Sometimes more. Tools nobody approved. Tools running on free-tier accounts where the terms of service permit training on your data. Tools with OAuth access to email, calendar, and shared drives that nobody has reviewed. Tools employees signed up for personally and are using for company work because they're faster than whatever the company provides.
We know how to find this. We've done it before. What's new is what happens to the data once it gets there, and that part is worth understanding clearly.
The question isn't whether your organization has AI exposure. It does. The question is whether you have any visibility into it.
What Shadow AI Actually Looks Like
Shadow AI isn't a future problem. It's a current operational reality at virtually every organization with knowledge workers. The pattern is familiar — but the specific risks have evolved. Here's what to look for.
▣ Personal accounts for business work Critical
An employee has a personal ChatGPT account — likely the free tier. They paste client proposals, financial summaries, or internal strategy documents into it because it's faster than whatever the company has provided. The free tier's terms of service permit OpenAI to use that content for model training. The employee doesn't know this. The company has no visibility into what was submitted or to whom.
▣ OAuth grants nobody audited High
An AI writing tool requested access to "read and compose email" when a user signed up. They clicked Allow. The grant is still active eighteen months later — the user has forgotten about it, the tool has been through two acquisition cycles, and nobody in the organization knows the access exists. A pull of OAuth grants from your identity provider typically surfaces five to fifteen of these per organization.
▣ Sanctioned tools, unsanctioned use High
The organization licenses a legitimate AI tool for one department. Other employees find it, start using it, and feed it data well outside the intended scope. The tool is "approved" — so nobody looks at how it's being used. The vendor's data handling terms apply to whatever gets submitted, regardless of whether the use was intended or reviewed.
▣ AI features embedded in existing tools High
A SaaS product the organization has used for years quietly rolled out AI features. Employees are using them. Data is being processed by a third-party model the organization never evaluated. This doesn't show up as a new tool — it shows up as a new capability inside something that was already trusted. Most organizations have several of these.
The Data Exposure Problem
Discovery is only the first problem. Once you know what tools are in use, the next question is harder: what data is reaching them, and under what terms?
Not all AI exposure is equal. A sanctioned tool from a reputable vendor with a signed Data Processing Agreement, a privacy-preserving configuration, and a clear data retention policy is a very different risk profile from a free-tier consumer product that trains on inputs by default.
The specific questions that matter:
Does the vendor train on your data? Many consumer-tier products do by default. Enterprise tiers typically don't, but the configuration has to be set correctly and verified. "We have a business account" is not the same as "training is disabled."
Where does data reside, and for how long? Some tools retain conversation history indefinitely. Some send data to infrastructure in jurisdictions that create regulatory complications. Some offer zero-retention options but only if you know to ask for them.
What happens if the vendor is breached? If an AI tool holds months of your employees' queries — including proprietary strategy, client data, or internal communications — what does that look like in the hands of an attacker?
Does a signed DPA exist? For organizations subject to GDPR, HIPAA, or other regulatory frameworks, processing personal data through an AI vendor without a signed Data Processing Agreement is a compliance failure, not just a security risk.
The Governance Gap
Most organizations don't have a gap in awareness that AI is risky. They have a gap in operational governance — the documented policies, controls, and monitoring that would let them actually manage the risk.
Ask any leadership team whether they have an AI acceptable use policy, and the most common answer is: "We're working on it." Which means they don't have one, and employees are making independent decisions about what's appropriate to put into an AI tool with no guidance from the organization.
The governance gap typically looks like this across seven areas:
No tool inventory. Nobody knows what's in use. Discovery hasn't happened.
No approval process. No formal mechanism for evaluating and sanctioning AI tools before use.
No acceptable use policy. No documented guidance on what data categories are appropriate for AI tools.
No vendor review. DPAs not collected, data handling terms not reviewed, training opt-outs not configured.
No monitoring. No ongoing visibility into what tools employees are using or what data they're submitting.
No training. Employees haven't been told what responsible AI use looks like for their role and the data they handle.
No incident process. No defined response for what happens if sensitive data is submitted to an unsanctioned AI tool.
Most organizations score red or amber on five or more of these. That's not a criticism — AI adoption has outpaced most organizations' ability to build governance around it. But the gap is real and the exposure is current.
The Attacker Side of the Problem
AI hasn't just created new exposure through the tools your employees use. It has also materially changed what attackers can do against you.
This isn't theoretical. The shift is operational and it's happening now.
Phishing has changed. AI-generated phishing emails are now indistinguishable from legitimate business communication — correct grammar, appropriate tone, plausible context, no tell-tale signs of a non-native speaker. The volume attackers can generate has also increased dramatically. Campaigns that previously required significant human effort now run at scale.
Voice cloning is real and in use. AI voice cloning tools can replicate a person's voice from a small audio sample — a few seconds of a public YouTube video, a conference recording, a voicemail. Business Email Compromise attacks are adding voice components: a wire transfer request by email, followed by a "confirming call" from what sounds like the CFO. Several documented fraud cases involving AI-cloned voices have resulted in six-figure losses.
Reconnaissance is faster. AI tools can process public information about an organization — LinkedIn profiles, press releases, job postings, GitHub repos, conference talks — and produce a detailed picture of the org structure, tech stack, and key personnel in minutes. Attackers use this to craft targeted attacks that feel personal and specific.
Your AI tools are attack surface. Prompt injection — manipulating an AI tool's behavior by embedding instructions in content it processes — is an active and evolving threat. If your organization uses AI to process incoming documents, emails, or customer content, that pipeline can be targeted.
The organizations most exposed to AI-powered attacks are often the ones that haven't yet assessed their own AI exposure. The two problems are connected.
What to Actually Do About It
The path from "we have AI exposure we don't understand" to "we have reasonable control over our AI risk" is not as long as most organizations fear. It starts with getting a clear picture of the current state.
Discovery first. Pull OAuth grants. Analyze DNS query logs against a current AI vendor domain list. Review cloud audit logs. Run an employee survey. The goal is a complete inventory of what's actually in use — not what's approved, not what people think is in use, but what the telemetry shows.
Then classify what you find. Not everything is equal risk. Sanctioned enterprise tools with appropriate DPAs and configurations are different from consumer free-tier products accessing company email. Build a risk-tiered inventory that tells you where the real exposure is concentrated.
Data exposure analysis next. For the highest-risk tools, understand what data categories are reaching them, under what vendor terms, with what retention and residency implications. This is where the risk register gets specific.
Then close the governance gaps. An acceptable use policy doesn't have to be complex — a one-page document that tells employees which data categories should never go into an AI tool, which tools are approved, and how to request approval for a new tool is far better than nothing. Layer in vendor DPAs for tools that process sensitive data, and verify that training opt-outs are actually configured.
Finally, look at the threat landscape through your specific lens. AI-powered phishing is a generic threat. But whether it targets your finance team, your customer service reps, or your executives depends on who you are and what data you hold. Map the threat to your profile and address the specific risks that apply.
▣ The AI Security Assessment
This is exactly what Keser Security Operations' AI Security Assessment covers: shadow AI discovery, OAuth audit, data exposure mapping, governance gap analysis, and AI threat landscape — delivered as a fixed-price engagement in 10–15 business days, with a risk-ranked findings register and a three-track remediation roadmap.
It's designed to take you from "we don't know what we have" to "we know exactly where we're exposed and what to do about it" — without a long engagement or a vendor sales cycle.
See the assessment →The Honest Answer
Most organizations are not in a catastrophic position. They have AI exposure they don't fully understand, governance gaps they haven't yet closed, and a threat landscape that's moved faster than their security posture. That's uncomfortable, but it's fixable.
The organizations that end up in genuinely bad situations are usually the ones that decided the problem was too complicated to look at directly. Discovery is the hard part — not technically, but psychologically. Most leaders would rather not know what they'd find. That's exactly why most breaches involving AI exposure are entirely preventable.
The first step is just deciding to look.