COMMENTARY: Shadow AI is becoming a lot harder to spot. We spend a lot of time talking about employees using random AI tools without IT knowing, but AI is also getting switched on inside software companies have already approved. That makes this messy because nobody is necessarily going back to review every SaaS tool every time it adds a new AI feature, connector or data capability. For MSPs and MSSPs, there is a pretty clear opportunity here around keeping track of what changed, what data those features can touch and who actually owns the risk. Approving an app once just does not mean you know what that app is doing six months later.
Shadow AI has become one of the most talked-about risks in cybersecurity this year. A
recent WatchGuard report found 64% of employees admit to using unauthorized AI tools for work. While that is a real and growing risk, there’s another one hidden underneath that stat that isn’t getting as much attention. The more dangerous blind spot is showing up inside the tools that organizations have already approved and have been running for years.
Between video conferencing, security, payroll, and messaging tools, the average business runs more than 100 SaaS applications, according to
BetterCloud’s 2026 State of SaaS Report, a number that rose for the first time in two years. That’s already a significant list for organizations to manage and secure, and now these platforms are shipping new AI features into their products almost every day. Routine updates are no longer just patching bugs or fixing software; they now include AI features that are often enabled by default. But who’s reading the release notes across every application, after every update?
Few businesses have the bandwidth to keep up with every change, and small and midsize businesses in particular rarely have anyone whose job is to track it. That means AI capabilities are going live inside software that was vetted and approved months or years before those features existed.
Every SaaS update can change the risk
This dynamic creates exposure in two ways. The first is the more obvious one: Native AI features and their connectors can open new backdoors for bad actors, expanding the attack surface in ways security teams haven’t mapped.
Verizon’s Data Breach Investigation Report found that third-party supply chain breaches jumped 60%, now accounting for 48% of all breaches. The second type of exposure may not be as obvious, but is arguably more common: internal data leakage caused by employees who simply don’t know better.
Take an AI meeting summary that is generated automatically at the end of a video call. It’s often assumed to be temporary, but once that information is copied somewhere else, like a team’s Slack channel, it doesn’t disappear. Depending on access controls, an employee who uses AI to search that channel could find that summary, which may contain sensitive discussions, personal details, or client information. A seemingly benign feature is now expanding access to data that was never supposed to leave the meeting. Multiply that across an entire SaaS stack, and the exposure really grows.
That’s further complicated for small- and medium-sized businesses that don’t have the same resources dedicated to oversight. And in many situations, ownership over applications gets murky once they are deployed. For example, when marketing asks IT to help set up HubSpot, and then IT configures and hands it over, who owns that tool going forward? If HubSpot enables an AI feature six months later, whose job is it to catch that? The tool falls into a governance gap between departments.
AI is showing up inside apps you already approved
Getting a better handle on this threat starts with documentation. Organizations should keep a list of every application that they are using, then rank those applications based on which ones have access to the most critical and sensitive information. Having awareness around what is in an environment and what each application has access to is a crucial starting point.
On top of that, organizations should have a list of applications that are approved and denied as a standard of what employees can use. That’s especially helpful for businesses that lack the technical staff or bandwidth to vet every emerging AI product. Sticking to established, well-known tools is a practical way to reduce exposure.
There’s also an opportunity to use AI to help manage the AI problem itself. An agent could do a daily scan of the release notes for every application in an organization and flag whether any AI or autonomous capabilities were introduced. It’s not guaranteed to catch everything, as no AI is perfect, but it could make that task much more manageable.
Most businesses are already behind on managing this. The pace of AI feature releases will only accelerate from here, further widening the gap between what these tools can do and what organizations are equipped to govern. The acceleration will eventually flatten out, but businesses don’t want to look back and see a chasm of exposure from the years they let it go unchecked.
Right now, every unreviewed update is chipping away at the trust organizations have in their own tools. Getting basic visibility into what’s running inside the business and establishing clear accountability for who’s watching it will help organizations make progress against this invisible drift.
MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].