← Back to roshantrivedi.co.in
RT · Identity Security
AI Governance · Shadow AI

You can't govern the AI tools you don't know exist.

A 2023 leak, a 2026 SEC filing, and a supply-chain breach through a browser extension all trace back to the same gap: AI tools employees adopted that security never approved — and in most cases never even knew existed. A look at how widespread that gap actually is, the market racing to close it, and the guardrails that would have caught each incident before data left the building.

Role
Independent Research & Control Design
Challenge
AI adoption is outrunning AI governance by years. Anywhere from half to four in five employees use AI tools their IT department never approved — a browser extension, a personal account, a copilot switched on inside a SaaS tool. Security can't secure what it can't see, and by the time it finds out, the data has usually already left.
Outcome
Traced three real incidents — a 2023 leak, a 2026 SEC filing, and a 2026 supply-chain breach — back to the same root cause: unmanaged, unapproved AI tools. Sized the gap against 2026 breach and survey data, mapped the fast-consolidating governance vendor market, and set out a discovery-first guardrail sequence.
APPROACH

Three moves, in order

Start from documented incidents, not hypothetical risk. Check the pattern against current research. Then map both the market response and the guardrails that actually close the gap.

01

Ground it in incidents

Samsung's 2023 ChatGPT leaks (three incidents in twenty days), the April 2026 Vercel breach that started with an employee's self-adopted Context.ai browser extension, and CB Financial Services' first-ever SEC Form 8-K filed over unauthorized employee AI use — three different failure patterns, the same root cause: a tool nobody in security approved.

02

Check it against the data

Cross-referenced against 2026 breach and survey research: shadow-AI-linked incidents nearly doubled year over year — from 20% to 43% of AI-related breaches — pushing average breach cost to $5.39M, while separate surveys put unsanctioned AI use anywhere from 49% to over 80% of employees.

03

Map the response

Reviewed the AI governance and discovery vendor market and its 2026 consolidation wave — Varonis absorbing AllTrue.ai, Veeam paying $1.725B for Securiti, Gartner's first dedicated Magic Quadrant — then set out the discovery-first guardrail sequence that would have caught each incident before data left the building.

AI Governance Shadow AI Data Security Posture Management AI Discovery Insider Risk Zero Trust
THE WORKFLOW

What security sees, versus what's actually running

Both are true at the same company, at the same time. Only one of them shows up in an asset inventory.

WHAT SECURITY APPROVED Employee 3–5 sanctioned tools SSO-gated, logged IT asset inventory known & governed via procurement reviewed & monitored WHAT'S ACTUALLY RUNNING Employee Extensions, personal apps self-served, no review 12+ ungoverned surfaces invisible to security data leaves the perimeter discovered ~247 days later, median
THE EVIDENCE · THREE INCIDENTS, ONE PATTERN

This didn't start as a theory

Three documented incidents across three years and three failure patterns, all tracing back to a tool nobody approved.

2023 · Samsung ChatGPT leaks. Within twenty days of allowing staff to use ChatGPT, Samsung's semiconductor division suffered three separate confidential data leaks — source code pasted in while debugging, an internal meeting transcript turned into notes, and code used to optimize chip-yield testing. Samsung banned generative AI company-wide days later.

— per Bloomberg and multiple contemporaneous reports

April 2026 · Vercel breach via a browser extension. An employee had self-adopted a consumer-grade AI browser extension — Context.ai — under a corporate identity, entirely outside any sanctioned deployment. When the vendor was breached, attackers moved downstream into Vercel, pulled customer environment variables nobody had flagged as sensitive, and used the data to fuel an extortion campaign on BreachForums.

— per Security Affairs and public breach disclosures

May 2026 · CB Financial Services SEC filing. An employee ran non-public customer data — names, Social Security numbers, dates of birth — through an AI application the bank had never approved. CB Financial filed the first-ever SEC Form 8-K triggered by unauthorized employee AI use rather than a cyberattack, even while disclaiming any financial loss.

— per SEC filings and legal analysis

Three incidents, three failure patterns — direct leakage, supply-chain compromise, regulatory exposure — and one identical root cause: a tool adopted outside every review process security relies on to know it exists.

— the pattern across all three
THE RISK PROFILE

Why shadow AI breaks the old assumptions

Shadow AI doesn't look like a breach until well after it already is one.

01

Invisible by design

Shadow AI doesn't show up in asset inventories, CASB logs, or SSO reviews, because it's adopted outside procurement entirely — a browser extension, a personal account, a copilot switched on inside a SaaS tool nobody re-reviewed.

02

Most incidents aren't hacks

The typical shadow AI incident isn't an intrusion, it's normal use: pasting a customer record into a prompt box is enough. Surveyed employees admit to sharing research data (33%), employee records (27%) and financial data (23%) with tools nobody approved.

03

Leadership condones it

69% of C-suite respondents and 66% of directors and senior VPs say using unsanctioned AI tools is fine if it makes work faster — the governance gap starts at the top, not with a rogue employee.

04

Growing faster than the controls

Shadow-AI-linked breaches rose from 20% to 43% of AI-related incidents in a single year, while the overwhelming majority of breached organizations had no AI governance policy and no adequate AI access controls in place at all.

THE MARKET RESPONSE

A category getting absorbed as fast as it formed

A wave of purpose-built vendors emerged to discover and govern shadow AI — and in 2026, the biggest data-security platforms started buying their way in rather than building it themselves.

Credo AI
Centralized inventory of AI systems, models, agents and vendors, with auto-discovery of shadow AI.
Netskope
DSPM-augmented DLP that classifies and governs data reaching sanctioned and shadow AI alike.
Varonis (Atlas)
AI inventory, shadow AI discovery, AI security posture management and runtime guardrails in one console.
Securiti
Data command center bringing AI governance, privacy and security posture under one policy layer.
Reco
SaaS-native discovery that surfaces unsanctioned AI tools connected via OAuth grants and browser extensions.
AvePoint
Governance and lifecycle management extended to AI agents and copilots across the Microsoft 365 estate.

This category is consolidating almost as fast as it formed. Varonis acquired AllTrue.ai in February 2026 to build shadow AI discovery directly into its new Atlas platform; Veeam paid $1.725B for Securiti in December 2025; and Gartner published its first Magic Quadrant dedicated to AI Governance Platforms in June 2026, evaluating 13 vendors. Visibility into AI use is being folded into core data-security platforms nearly as quickly as the shadow AI problem itself is growing.

THE GUARDRAILS

What would have caught each incident

Not "write an AI policy." A discovery-first sequence applied before policy is even drafted.

01

Discovery before policy

You can't govern what you can't see. Continuous discovery of AI apps, agents, browser extensions and OAuth grants across the SaaS estate has to come before any policy is written, not after.

02

Sanctioned alternatives, not just bans

Samsung's response was an outright ban. Most organizations need a faster path: an approved tool that's as quick as the one people already reached for — or usage simply moves further into the shadows.

03

Data controls at the AI boundary

Classify and gate what data can reach any AI surface, sanctioned or not, since most incidents are prompt-level exposure rather than intrusions. DSPM-style controls matter more here than perimeter defenses.

04

Materiality-aware incident response

CB Financial shows regulators will treat AI misuse like a breach regardless of dollar loss. Incident response playbooks need an AI-use branch alongside the hacking branch, with its own disclosure criteria.

Status: framework, not a product build. This is a discovery-first governance sequence grounded in real 2023-2026 incidents and current shadow AI research — it pairs directly with the credential-issuance guardrails in One Key, Every Agent and the risk-scoring inventory in Non-Human Identity at Scale.