Decoding the world of cybersecurity

The AI builder boom is creating a shadow IT crisis

Gil Geron, CEO of Orca Security, argues that AI-built applications and agents are expanding shadow IT into production cloud environments faster than governance can keep up.

The AI builder boom is creating a shadow IT crisis
Summary
  • AI-assisted development is expanding software creation beyond engineering teams and into business functions.
  • AI agents, cloud services, APIs, and vector databases are increasing complexity and attack surface exposure.
  • Governance must treat AI-built applications as production infrastructure from day one.

Contributed article

Gil Geron

CEO, Orca Security

For years, organisations worried about shadow IT in the form of unsanctioned SaaS applications. Employees signing up for file-sharing tools or project management software created governance headaches, but the scale of the problem remained relatively contained. Today, AI has fundamentally changed that equation.

Employees are now building software and that’s a completely different ballgame. With a few prompts, anyone can create applications, automate business processes, deploy AI agents or connect multiple cloud services together. Software development has become dramatically more accessible, allowing organisations to innovate at speed.

AI is doing more than making software development faster; the economics of enterprise software are changing. As more organisations can rapidly build applications tailored to their own needs, the decades-old “buy versus build” equation is being recalculated. Starbucks recently announced it is developing its own AI-assisted tools to replace Microsoft and IBM systems, aiming to cut its $400 million annual software spend. This example is a perfect illustration of the shift that will play out across every enterprise application category.

However, while AI is democratising software creation, it is also democratising risk. Security teams are increasingly responsible for applications and AI agents they never knew existed, often built outside established development processes on platforms such as Replit and Vercel. The result is a new generation of shadow IT that is more powerful, interconnected and harder to govern than anything organisations have faced before.

A typical organisation may have marketing teams building customer-facing automations, HR teams experimenting with AI assistants, and finance departments connecting AI services to internal data. Business users who would never have written code a few years ago can now build production-ready workflows in hours, making innovation spread beyond engineering teams. Security, however, hasn’t spread with it.

A recent report by Orca Security, which analysed more than 1,200 production cloud environments, found that more than half (56%) of organisations have already deployed AI agents into production, while 51% are using AI to build custom applications. AI no longer sits in isolated sandboxes. It is embedded into production systems that interact with enterprise data, identities and business-critical workflows, dramatically expanding the attack surface.

The modern AI environment rarely consists of a single model. Today’s applications rely on interconnected services, vector databases, APIs, cloud platforms and autonomous agents that make decisions and perform tasks independently. According to the research, 64% of organisations using AI now operate vector databases, while 55% run four or more AI services simultaneously. Each new connection creates another opportunity for misconfiguration, excessive permissions or unintended data exposure.

This complexity also explains why traditional security approaches struggle to keep pace. Conventional application security assumes engineering teams build software through established pipelines with clear governance and review. AI-driven development doesn’t always follow those rules.

For example, applications can emerge from business teams rather than software engineers, or AI agents are deployed rapidly to solve operational problems. Moreover, low-code platforms and AI coding assistants allow experimentation to become production far faster than governance processes were designed to handle. By the time security teams discover these new workloads, they’re often already connected to sensitive business systems.

The problem becomes even greater when identities and permissions are involved. AI agents often require access to cloud services, internal systems and corporate data to perform useful tasks. If those permissions are overly broad, or simply forgotten after deployment, they create attractive targets for attackers. For instance, a compromised AI agent can provide a pathway into wider cloud infrastructure.

Encryption presents another example of the maturity gap. As AI systems increasingly process proprietary business information, customer records and intellectual property, these configuration decisions become increasingly important. But the answer is not to slow AI adoption, which sounds counterintuitive, but it isn’t. Because the organisations gaining the greatest advantage from AI are often those empowering employees to innovate quickly. Restricting that innovation risks undermining one of AI’s biggest competitive benefits.

Instead, the answer is that organisations need to rethink how they approach governance. Rather than viewing AI applications as separate from traditional IT, they need to be treated as production infrastructure from day one. That means applying the same operational discipline organisations already expect across the rest of their cloud estate. This includes continuous visibility, vulnerability management, least-privilege access, encryption, identity governance and ongoing monitoring.

Security needs visibility into who is building AI-powered applications, not to prevent innovation, but to understand where new risks are emerging. In an environment where almost anyone can become a software builder, manual reviews are no longer enough. Organisations need automated visibility across dynamic cloud environments so they can innovate confidently while maintaining appropriate guardrails.

The number of builders inside every organisation will only continue to grow. Software creation has expanded beyond engineering, and security must evolve alongside it.

×