
The unsanctioned use of AI tools by developers is a serious issue.
Shadow AI is illuminating. In some ways, the use of unregulated artificial intelligence services that fail to align with an organization's IT policies and wider country-specific data governance controls might be seen as a positive i.e. it's a case of developers and data scientists looking for new innovations to bring hitherto unexplored new efficiencies to a business.
But mostly, unsurprisingly, shadow AI (like most forms of shadow technology and bring your own device activity) is viewed as a negative, an infringement and a risk.
AI Shadow Breeding Ground
The problem today is that AI is essentially still so nascent, so embryonic and only really starting to enjoy its first wave of implementation. With many users' exposure to AI relegated to seeing amusing image constructs built by ChatGPT and other tools (think about human plastic toy blister packs last week, cats on diving boards this week and something zanier next week for sure), we've yet to get to a point where widespread enterprise use of AI tools has become the norm. Although that time is arguably very soon, the current state of AI development means that some activity is being driven undercover.
The unsanctioned use of AI tools by developers is becoming a serious issue as application development continues to evolve at a rapid pace. Scott McKinnon, CSO for UK&I at Palo Alto Networks says that this means building modern, cloud‑native applications isn't just about writing code anymore, it's about realizing that we're now in a delivery model that's operating in 'continuous beta mode', such is the pressure to roll out new enterprise software services today.
'The knock-on effect is that developers are under intense pressure to be fast and reduce time to market. With this in mind, it's not surprising that many developers are using AI tools in an effort to increase efficiency and deliver on these challenging expectations,' lamented McKinnon. 'Our research suggests that enterprise generative AI traffic exploded by over 890% in 2024 - and with organisations now starting to actually use these apps - a proportion of them can be classed as high risk. Meanwhile, data loss prevention incidents tied to generative AI have more than doubled, which is a clear red flag for governance failures.
Go-Around Guardrails
Compound all these realities and it's easy to understand why software developers might be tempted to seek ways around the organization's AI guardrail policies and controls. In practice, this sees them plugging into services from open source large language models outside of approved platforms, using AI to generate code without oversight, or skipping data governance policies to speed up implementation. The upshot is the potential for intellectual property to be exposed through compliance slips that also compromise system security.
'It all points to one thing: if developers are to balance speed with security, they must adopt a new operational model. It must be one where clear, enforceable AI governance and oversight are embedded into the continuous delivery pipeline, not bolted on afterwards,' said McKinnon "When developers use AI tools outside of sanctioned channels, one of the most pressing concerns is supply chain integrity. When developers pull in untested or unvetted AI components, they're introducing opaque dependencies that often carry hidden vulnerabilities.'
What are opaque software dependencies?
It's a scary enough sounding term in and of itself, opaque software dependencies are indeed bad news. Software dependencies are essential component parts of smaller
data services, software libraries devoted to establishing database connections, a software framework that controls a user interface or a smaller module that forms a wider external third-party application in its entirety. Useful software dependencies make their DNA easy to see and can be viewed with translucent clarity; opaque software dependencies are functional, but cloudy or muddied in terms of their ability to showcase their progeny and component parts. In technical terms, opaque software application dependencies mean the developer can not 'assign' them (and forge a connection to them) using a public application programming interface.
According to McKinnon, another major problem is the potential for prompt injection attacks, where bad actors manipulate the AI's inputs to force it into behaving in unintended and dangerous ways. These types of vulnerabilities are difficult to detect and can undermine the trust and safety of AI-driven applications. When these practices go unchecked, they create new attack surfaces and increase the overall risk of cyber incidents. Organizations must get ahead of this by securing their AI development environments, vetting tools rigorously and ensuring that developers are empowered to work effectively.
The Road To Platformization
"To effectively address the risks posed by unsanctioned AI use, organisations need to move beyond fragmented tools and processes toward a unified platform approach. This means consolidating AI governance, system controls and developer workflows into a single, integrated system that offers real-time visibility. Without this, organizations struggle to keep pace with the speed and scale of modern development environments, leaving gaps that adversaries can exploit,' said McKinnon.
His vision of platformization (and the wider world of platform engineering) is argued to enable organizations to enforce consistent policies across all AI usage, detect risky behaviors early and provide developers with safe, approved AI capabilities within their existing workflows.
'This reduces friction for software developers, allowing them to work quickly without compromising on security or compliance. Instead of juggling multiple disjointed tools, organizations gain a centralized view of AI activity, making it easier to monitor, audit and respond to threats. Ultimately, a platform approach is about balance, providing the safeguards and controls necessary to reduce risk while maintaining the agility and innovation developers need,' concluded Palo Alto Networks' McKinnon.
At its worst, shadow AI can lead to so-called model poisoning (also known as data poisoning), a scenario which application and API reliability company Cloudflare defines as when an attacker manipulates the outputs of an AI or machine learning model by changing its training data. An AI model poisoner's goal is to force the AI model itself to produce biased or dangerous results when it starts to process is inference calculations that will ultimately provide us with AI brainpower.
According to Mitchell Johnson, chief product office of software supply chain management specialist Sonatype, 'Shadow AI includes any AI application or tool that operates outside an organization's IT or governance frameworks. Think shadow IT but with a lot more potential (and risk). It's the digital equivalent of prospectors staking their claims in the gold rush, cutting through red tape to strike it rich in efficiency and innovation. Examples include employees using ChatGPT to draft proposals, using new AI-powered code assistants, building machine learning models on personal accounts, or automating tedious tasks with unofficial scripts.'
Johnson says it rears its head now, increasingly, due to the popularization of remote working where teams can operate outside traditional oversight and where firms have policy gaps, meaning that an organization lacks comprehensive AI governance, which leaves room for improvization.
From Out Of The Shadows
There is clearly a network system health issue associated with shadow AI; after all, it's the first concern brought up by tech industry commentators who want to warn us about shadow IT of any kind. There are wider implications too in terms of some IT teams gaining what might be perceived to be an unfair advantage, or some developer teams introducing misplaced AI that leads to bias and hallucinations.
To borrow a meteorological trusim, shadows are typically only good news in a heatwave… and that usually means there's a fair amount of humidity around with the potential for storms later.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
3 minutes ago
- Yahoo
Lex Autolease reports loss amid market challenges
Lex Autolease, the car leasing company owned by Lloyds Bank, has reported a pre-tax loss of £10.6m ($14.2m) for 2024, marking a significant downturn from its previous profits. Headquartered in London, the business had posted pre-tax profits of £124.4m in 2023 and £544.2m in 2022. Despite the loss, Lex Autolease's revenue increased from £2.2bn in 2023 to £2.4bn in 2024. The board attributed the loss to increased depreciation charges on the growing fleet, reduced profits from vehicle disposals due to second-hand market conditions, and higher interest expenses amid rising interest rates. The company holds net assets of £182.1m as of 31 December 2024, down from £190m in 2023. Property, plant, and equipment increased to £5.73bn from £5.44bn, reflecting changes in fleet composition and vehicle costs. Lex Autolease's funding from within the Lloyds Bank Group resulted in borrowed funds of £5.84bn at the end of last year, up from £5.41bn in 2023. The directors noted that new business volumes decreased by 6%, influenced by high prices, residual value risk management, and economic pressures. The value of funded vehicles grew by 6% in 2024, driven by rising costs of new vehicles and a shift in consumer interest towards electric and hybrid vehicles. Lex Autolease maintained a 17% market share in deliveries for 2024. The company also scrapped its dividend to Lloyds Bank, having paid £439m in 2023 and £708m in 2022. Lex Autolease expects muted growth in new car and light commercial vehicle registrations this year due to the Zero Emission Vehicle mandate. Used car prices stabilised in 2024, particularly in the latter half, with expectations of continued stability into 2025. However, the rising supply of used battery-electric vehicles may exert downward pressure on this market segment, the group said, adding that while used vehicle prices stabilised, some volatility is anticipated as the industry transitions to electric vehicles. Earlier this year, Lex Autolease formed a partnership with motoring app Caura to allow its personal contract hire customers to manage all aspects of their vehicle needs. "Lex Autolease reports loss amid market challenges" was originally created and published by Motor Finance Online, a GlobalData owned brand. The information on this site has been included in good faith for general informational purposes only. It is not intended to amount to advice on which you should rely, and we give no representation, warranty or guarantee, whether express or implied as to its accuracy or completeness. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content on our site. Sign in to access your portfolio


CNN
6 minutes ago
- CNN
Guinness owner Diageo's CEO is stepping down after two years
Diageo, the world's biggest spirits maker, announced Wednesday that CEO Debra Crew is stepping down by 'mutual agreement' after just two years in the role. The abrupt change comes amid sluggish sales across the alcohol industry, which has also affected Diageo brands Johnnie Walker whiskey, Casamigos tequila and Guinness beer, as well as the threat of increased tariffs from the United States. In a press release, the London-based company said Crew is leaving with 'immediate effect.' Nik Jhangiani, Diageo's chief financial officer, will become the interim CEO as Diageo conducts a 'comprehensive' search process. Sir John Manzoni, Diageo's board chairman, thanked Crew for 'steering the company through the challenging aftermath of the global pandemic and the ensuing geopolitical and macroeconomic volatility.' Diageo's stock (DEO) has lost about 44% of its value since Crew became CEO in June 2023. She announced in May a plan that would slash $500 million in costs and potentially sell some brands over the next three years. Several of the biggest booze brands are dealing with a sharp decline in sales following the Covid-19 boon, which prompted some people to stock up their home bar carts. That has forced some companies, like Woodford Reserve maker Brown-Forman, to undergo layoffs. In addition, Diageo has been dealing with its own issues including supplying too much alcohol to its Latin America markets as demand slid and a shortage of Guinness beer at pubs in the United Kingdom. In the United States, its Casamigos and Don Julio tequilas are battling a class action lawsuit accusing them of falsely labeling them as '100% agave.' The company denies the allegations.
Yahoo
33 minutes ago
- Yahoo
THOR Industries and Harbinger Earn Fast Company 2025 World Changing Ideas Award for World's First Hybrid Class A Motorhome
Annual Awards Recognize Innovative Companies and Projects Addressing the World's Most Urgent Challenges ELKHART, Ind. and GARDEN GROVE, Calif., July 16, 2025 /PRNewswire/ -- THOR Industries (NYSE: THO), the recreational vehicle (RV) industry innovation leader, and Harbinger, the leading medium-duty electric and hybrid vehicle manufacturer, are proud to announce that they have been named winners of Fast Company's 2025 World Changing Ideas Awards for their Hybrid RV. This annual recognition honors bold and transformative efforts that tackle the world's most pressing issues—from fresh sustainability initiatives and cutting-edge AI developments to ambitious pursuits of social equity that are helping mold the world. THOR Industries collaborated with Harbinger to create the world's first hybrid electric Class A motorhome, combining Harbinger's advanced electric vehicle (EV) chassis with a low-emissions gasoline range extender that can recharge the electric batteries. The vehicle, which is designed specifically for RV use, is capable of delivering an estimated 500 miles of range, including 150 all-electric miles. This innovative platform simplifies vehicle operation and supports flexible charging, including grid integration, as well as solar power and off-grid capabilities, while elevating the on the road experience with added range and driving comfort. Together, the companies have set a new standard for simple, sustainable, long-range RV travel while solidifying the THOR Family of Companies' innovation leadership. "We're honored that THOR Industries and Harbinger have received Fast Company's 2025 World Changing Ideas Award for the world's first hybrid Class A motorhome. This achievement underscores the collective commitment and partnership between THOR and Harbinger that is dedicated to pioneering an electrified RV ecosystem—from innovative chassis technology to enhanced design and comfort. It's a milestone that reflects our shared vision of delivering an RV experience that meets the needs of today's owners and inspires tomorrow's travelers," shared Todd Woelfer, Chief Operating Officer at THOR Industries. "We committed to investment in long term innovation to drive competitive advantage. Our work to innovate with Harbinger is a great example of the strategic advantage that investment drives for THOR." This year's awards, featured on showcase 50 winners across 12 categories and 50 additional winners across industries, for a total of 100 outstanding projects. A panel of Fast Company editors and reporters selected the winners from a pool of more than 1,500 entries and judged applications based on their impact, sustainability, design, creativity, scalability, and ability to improve society. "This recognition validates the work we're doing with THOR to help lead the RV industry forward," said John Harris, Co-Founder and CEO, Harbinger. "By building a plug-in hybrid specifically for RVs, we are giving customers peace of mind for long-distance travel while also enabling fully electric operation whenever possible. THOR and their visionary team share our belief in a future defined by cleaner, more sustainable transportation. Together, we have proven what is possible when cutting-edge innovation meets real-world needs." "The World Changing Ideas Awards have always been about showcasing the art of the possible," says Fast Company editor-in-chief Brendan Vaughan. "We're proud to recognize the organizations and leaders that are making meaningful progress on the biggest issues of our time." About THOR IndustriesTHOR Industries is the sole owner of operating companies which, combined, represent the world's largest RV manufacturer. For more information on the Company and its products, please visit About HarbingerHarbinger is an American commercial electric vehicle (EV) company on a mission to transform an industry starving for innovation. Harbinger's best-in-class team of EV, battery, and drivetrain experts have pooled their deep experience to support the growing demand for medium-duty EVs. Leveraging a foundation of proprietary, in-house developed vehicle technologies designed specifically for commercial and specialty vehicles, Harbinger is bringing a first-of-its-kind EV platform to market, priced at acquisition parity to traditional diesel vehicles. Harbinger: Familiar Form, Revolutionary Foundation. To learn more about Harbinger, please visit You can find the company press kit HERE. About Fast CompanyFast Company is the only media brand fully dedicated to the vital intersection of business, innovation, and design, engaging the most influential leaders, companies, and thinkers on the future of business. Headquartered in New York City, Fast Company is published by Mansueto Ventures LLC, along with our sister publication Inc., and can be found online at THOR Media ContactRenee JonesVP Marketing, THOR Industries425-503-8268rjones@ Harbinger Media Contact Kylee KeskerianPR Manager419-822-6417kylee@ View original content to download multimedia: SOURCE Harbinger Sign in to access your portfolio