Shadow AI is a security risk now and it’s only going to get bigger

As a journalist, I’m somewhat cynical about the rise of AI, what with the impact it is having on the media business. But when I’m wearing my cybersecurity consultant hat, my lack of enthusiasm turns into genuine concern. While AI does, without any shadow of a doubt, represent the future, right now it’s a security risk. And shadow is a keyword here. The latest research from Mindgard has confirmed just what a problem shadow AI actually is to enterprises.

Rather mind-bogglingly, the villains of the piece identified in the survey – carried out during the RSA Conference 2025 – are cybersecurity professionals themselves. Yes, the shadow AI threat is right there inside your security operations centre, it would seem.

It’s not at all surprising that security teams use AI tools to help with their workflows. They are ideally suited to helping with the writing of policy, incident reports, research, code debugging, and even the creation of threat detection rules. It’s what AI does best: enhance efficiency while supporting professionals in their work.

But that doesn’t mean it is safe.

Specifically, when 87% of cybersecurity practitioners say they incorporate AI tools in their workflows, yet a quarter of them admit that they do so using personal ChatGPT accounts or AI extensions that have not been approved, that have not met with the formal compliance procedures for the enterprise that they are responsible for maintaining.

As Mindgard said in the report: “These are not unaware end users; they’re the people who write and enforce corporate security policy.” 56% of those same security professionals admitted that other employees are bypassing those compliance policies as well.

“Shadow AI is widespread within organisations,” the report concluded, “with usage going largely unmonitored.”

Security professionals and shadow AI risk

You don’t need to be a security professional to see why that is a problem, but it probably helps.

Just as the issues with shadow IT before it, shadow AI introduces risk. Not just any risk, but red flag waving, klaxons sounding, running around with your hair on fire risk.

Heck, when that shadow AI is being used, as Mindgard notes, to “process sensitive code, proprietary business data, and regulated customer information,” there is no other logical conclusion to be drawn.

And here’s the kicker: it’s only getting worse. The researchers found that AI use is accelerating within enterprises at such a speed that security teams don’t stand a chance of controlling it adequately.

“Nearly 90% of security practitioners have used AI tools,” the report said, “but only 32% of organisations have formal controls in place.” As Peter Garraghan, CEO and Co-Founder of Mindgard put it: “Shadow AI isn’t a future risk. It’s happening now, often without leadership awareness, policy controls, or accountability.”

WormGPT variants on the rise

It’s not just cybersecurity professionals who are introducing risk with the use of AI, cybercriminals are as well. We all know how AI-powered phishing has become the norm as a method of gaining initial access during an attack, but do you appreciate just how advanced the AI being used to assist with this has become?

The Cato Networks threat intelligence team has discovered that threat actors are jailbreaking well-known LLMs to power their latest “WormGPT” criminal AI variants. WormGPT tools are designed to provide responses no matter how unethical or illegal they might be. “By manipulating system prompts and potentially employing fine-tuning on illicit data,” Cato security researcher Vitaly Simonovich said, “the creators offer potent AI-driven tools for cybercriminal operations under the WormGPT brand.”

“What’s really concerning is that these aren’t new AI models built from scratch,” said J Stephen Kowski, Field CTO at SlashNext Email Security+, “they’re taking trusted systems and breaking their safety rules to create weapons for cybercrime.”

Which means that enterprises must start thinking beyond blocking known bad tools and start dealing with how AI-generated content behaves, regardless of which platform created it.

“The best defense is real-time analysis that can spot malicious AI content the moment it hits your network,” Kowski concluded, “before it can do damage.”

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.