Skip to content

Topic

Shadow AI

Unsanctioned use of AI tools and personal AI accounts inside organizations, outside employer visibility or policy.

Current stories

security5 publishers

AI coding agents posted 13,000 company images to developers' public GitHub repos, Glow says

Glow says AI coding agents asked for review screenshots put over 13,000 internal images from 300-plus organizations into public GitHub repositories. Most sat under developers' personal accounts, where the companies' security teams were not looking.

Perspective Coverage

5 publishers
Builder
Builder 37%
Operator
Operator 53%
Investor
Investor 10%

Reality

Evidence55
Adoption45
Hype gap+15
Incentives70
Confidence60
build3 publishers

Coding agents routed more than 13,000 private screenshots through public GitHub repos

Glow's PixelLeak report found coding agents exposed more than 13,000 private screenshots from over 300 organisations by hosting them in public GitHub repos. With 93% under developers' personal accounts, a company's own GitHub audit would miss most of them.

Perspective Coverage

3 publishers
Builder
Builder 42%
Operator
Operator 50%
Investor
Investor 8%

Reality

Evidence55
Adoption50
Hype gap+10
Incentives55
Confidence60
product1 publisher

Omnissa pitches Elara at the unapproved AI assistants employees run on work devices

Omnissa launched Elara for AI governance, citing its own report that AI-assistant use on work devices grew nearly 1,000% in 2025, mostly via unapproved tools. For endpoint teams it is a new category to assess, and the controls Omnissa described attach most clearly to agents IT has already granted access.

Publishers:siliconangle.com

Reality

Evidence35
Adoption
Insufficient
Hype gap+40
Incentives75
Confidence40
security2 publishers

Okta's Blueprint Alliance gives buyers a six-point checklist for AI agent identity

Okta and 11 vendors including AWS, Google Cloud and CrowdStrike signed six shared principles for securing AI agents under a new Blueprint Alliance. Buyers can put the list to vendors in procurement now, while Okta's release describes a reference architecture with no stated way to test compliance.

Publishers:okta.comscworld.com

Reality

Evidence40
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence55

Earlier coverage

  1. Deloitte puts UK workers' own spending on work GenAI tools at £958m a year

    Leadership · September 18, 2026 · 1 publisher

  2. Zscaler's Rob Sloan makes California's agency rule the case for a corporate AI security owner

    Leadership · September 18, 2026 · 1 publisher

  3. Nearly half of surveyed organizations had an AI agent take an unapproved action in the past year

    Security · September 15, 2026 · 1 publisher

  4. Exaforce ties every AI agent it discovers back to the employee whose permissions it borrows

    Product · September 15, 2026 · 1 publisher

  5. A personal AI account inherits consumer terms and everything its user can reach

    Build · September 15, 2026 · 1 publisher

  6. Team8's survey finds 71% of CISOs already putting AI agents into their security tools

    Security · September 14, 2026 · 1 publisher

  7. Weekly AI tax research nearly doubled to 60% among more than 1,000 tax professionals

    Invest · September 12, 2026 · 1 publisher

  8. Amazon's cure for shadow AI ships on the desktop from outside its European sovereign cloud

    Product · September 12, 2026 · 1 publisher

  9. Alvarez & Marsal's talent practice lead warns AI pilots often test the wrong thing, and premature cuts create talent debt

    Leadership · September 11, 2026 · 1 publisher

  10. Hunt.io traces intrusions in four countries to AI agents running eight known exploits

    Security · September 10, 2026 · 1 publisher

  11. Amazon pitches the Quick desktop app to IT as containment for shadow AI

    Build · September 10, 2026 · 1 publisher

  12. Copilot Chat read confidential mail for weeks past the DLP policy set to stop it

    Leadership · September 10, 2026 · 1 publisher

  13. OpenAI test found agents breaching Hugging Face; CrowdStrike touts new tools to police shadow AI

    Product · September 10, 2026 · 1 publisher

  14. Uber exhausted a year of Claude Code budget in four months

    Leadership · September 9, 2026 · 1 publisher

  15. Orphaned AI agents keep their access after the employee who created them moves on

    Product · September 7, 2026 · 1 publisher

  16. Anthropic's Compliance API now logs the Claude Code sessions running on inherited developer credentials

    Security · August 31, 2026 · 1 publisher

  17. Six to nine vendors, five obligations each: the first AI security exercise is arithmetic

    Build · August 26, 2026 · 1 publisher

  18. Akamai's 12x number turns shadow AI from a headcount problem into a shortlist

    Security · August 24, 2026 · 1 publisher

  19. IT's AI shopping list is inverted: 46.5% want automation, 71% of their AI tools are invisible

    Product · August 22, 2026 · 1 publisher

  20. AI risk filed in the wrong drawer: agents hold staff entitlements and nobody signs for them

    Security · August 22, 2026 · 1 publisher

  21. Approval is a snapshot: the same sanctioned app becomes shadow AI 24 minutes later

    Security · August 22, 2026 · 1 publisher

  22. Shadow AI now has an invoice: about $670K on top of the average breach

    Build · August 16, 2026 · 1 publisher