Shadow AI – the unauthorized use of AI technologies and tools without the organization’s knowledge or approval – has been a security concern since the launch by
OpenAI of ChatGPT almost three years ago, posing a range of risks from data leakage and privacy breaches to compliance issues and exposure of intellectual property.
Employees tend to adopt these AI tools for a number of reasons, including automating tasks, analyzing data, debugging code, or drafting reports, often without understanding that they’re giving sensitive data to third parties, according to
Aditya Patel, cloud security specialist with
Amazon Web Services (AWS).
Patel wrote in a blog post for the
Cloud Security Alliance in March that in a s
urvey of 7,000 employees, about 38% said they share confidential data with AI platforms without approval.
“Shadow AI isn’t new – it’s the rebellious cousin of shadow IT,” he wrote. "But while shadow IT involves rogue Dropbox accounts or unauthorized project management apps, shadow AI is riskier. Way riskier. Tools like ChatGPT, Claude, Mistral, and open-source LLMs like Llama and DeepSeek are too easy to use, too powerful, and too opaque.”
Cycode's Inventory and AIBOM
This month,
Cycode unveiled new solutions – its AI and machine learning (ML) inventory and AI Bill of Materials (AIBOM) – aimed at helping organizations discover, govern, and security the use of AI throughout the entire software development lifecycle (SDLC), giving them greater visibility into the rapidly growing number of AI tools, models, and infrastructure that developers are adopting.
“Developers, eager to innovate, are pulling in new AI models, using various AI coding assistants, and connecting to a wide array of AI infrastructure,”
Devin Maguire, product marketing manager for Cycode, wrote in a blog post. “The result is a sprawling, invisible ecosystem of AI tools and components across the software development lifecycle (SDLC). Security teams are left asking critical questions.”
Those include what AI tools developers are actually using, where they’re using models from third-party sources, and how to define and enforce policies for secure AI adoption without visibility.
Protecting Code
The AI and ML inventory and AIBOM are part of Cycode's AI-Native Application Security Platform, a solution designed to secure both AI- and human-generated code. The first gives security teams a complete inventory of all AI and ML assets and automatically detects when developers use AI coding assistants, connect a Model Context Protocol (MCP) server, or add AI models, then traces the asset back to its source in a code repository.
The inventory includes everything from AI infrastructure and coding assistants to models, packages, and secrets.
Security teams can also create controls by defining custom policies for AI use and creating an AIBOM, a manifest of AI components
.“In concert, Cycode’s MCP server and the AI and ML inventory, along with AIBOM capabilities, represent a comprehensive solution for securing AI development,” Maguire wrote. “While the MCP focuses on securing the outputs of AI coding assistants by providing essential context, the AI and ML inventory and governance capabilities address the broader landscape of AI tools and models in use.”
Cycode's MCP Server is available now, while the AI and ML inventory is in early access
A Minor but Growing Issue
Jack Gold, principal analyst with
J.Gold Associates, told MSSP Alert that Shadow AI, while still a “fairly minor issue,” is growing and is similar to what the industry has seen in the past.
“As new forms of apps become available, and enterprises don’t quickly adopt them, individuals take their own initiative to go out and get them to help them be more productive, or at least that is the hope,” Gold said. “This was true in early databases, even early spreadsheets, and some early CRM [customer relationship management]. AI is following a similar path.”
Enterprises try to control what Gold said is the “wild west of apps” by putting in place tools and processes.
“In coding, it’s a little different, since the results are not just for personal use, but affect the output of code that can affect the entire organization,” he said. “Companies discovering what is being used, how it’s being used, and by whom, is an important function. It also gives them insight into which types of tools are popular and perhaps offers them a way to focus on just a few to broadly implement.”
A Challenge for MSSPs
Shadow AI is also a challenge for MSSPs as it becomes clearer “how deeply embedded, technically invisible, and operationally risky these tools have become,”
wrote Brad Shannon, director of product management for managed services at MSSP
Summit 7. “For MSSPs, the shift is clear: Shadow AI is no longer peripheral or experimental. It’s embedded across client environments in ways that expand the attack surface and reduce visibility. The challenge is less about whether AI is present and more about whether anyone is watching how it’s being used.”
The AI and ML inventory and AIBOM are the latest efforts by Cycode to help organizations gain control of the rapidly expanding AI environment. At the Black Hat 2025 show in July, the AI-native application security posture management (ASPM) platform vendor
launched its AI Exploitability Agent to more quickly prioritize and fix high-risk and exploitable vulnerabilities.