Artificial Intelligence (AI) or LLMs are here to stay. They have revolutionized the speed of execution of many business teams. With the help of AI coding assistants, developers can now ship new features, bug fixes, and entire products at record speeds. Pitch decks, presentations, and proposals can be generated within minutes. While AI exceeds efficiency expectations, uncontrolled adoption and tool sprawl can dramatically increase the risk of data loss and cyber-attacks.
You have probably read about incidents involving users pasting sensitive information and source code into AI chatbots and tried implementing a data loss prevention (DLP) program to fix it. Similarly, organizations using cloud-based AI tools implement cloud access security brokers (CASB) for access control. While DLP and CASB are important tools in securing the organization, organizations often overlook the AI tools that are installed directly on the endpoints. This article explores how this overlooked share of shadow AI can expose the organization to cyber threats and how you can mitigate the risks.
Shadow AI is the younger, meaner sister of Shadow IT. They are the artificial intelligence tools installed outside the approval of IT teams. They operate outside the scope of your organization’s governance and lifecycle management policies. Adding to the risks involved with shadow IT tools, shadow AI tools bring its own set of IT risks.
The risk caused by unauthorized use of AI tools is far more potent than those risks caused by apps and tools that do not have AI capabilities. The risk is higher because Shadow AI tools don’t just access and store sensitive information. They ingest proprietary data, generate unverified outputs, and use them for unsanctioned activities.
The real risk of allowing unauthorized AI tools to gain excessive permissions is the speed with which it operates. A human moves one step at a time; AI agents can launch multiple operations through child processes and coordinate with unparalleled efficiency. If one malicious agent is accidentally deployed by the users in a bid to improve their output, the entire network can be compromised.
Most users interact with artificial intelligence tools through web browsers and mobile applications. While this is true when accounting for domestic and personal use of AI chatbots for generating Ghibli images and demand generated by social media trends, significant use of AI tools in a corporate setup is through AI tools and agents that are directly installed and run on employee endpoints.
These tools have direct access to your network through the endpoint. What security measures do you have against these tools that reside within the network walls?
AI Agents and desktop clients of AI tools have access to local data, index files, memory, and code repositories directly. Unmanaged AI agents and MCP servers can run scripts, access databases, and take actions autonomously - without any human prompting specific actions explicitly.
If you don’t have security frameworks and systems in place to prevent users from installing unapproved AI tools on their machines, you must learn about the risks of Shadow AI and the security measures available to prevent users from installing unauthorized tools.
Most of these risks are caused by unsanctioned and uncontrolled use of AI tools. Shadow AI can be curbed using a mixed approach of limiting what each employee can do on their endpoints and providing a pre-approved stack of AI tools for users, allowing them to improve their efficiency while ensuring data security and compliance.
To control what employees can do at their endpoints, you must scope their permissions to the specific tasks their job requires them to do. Even today, many organizations grant local admin rights to employees or have systems that grant and revoke broad permissions by directly sharing local admin account credentials.
Eliminating local administrator privileges from user accounts and granting permissions to run specific applications with elevated privileges allows them to complete their tasks seamlessly and securely. This also prevents users from installing unapproved AI tools and agents that require admin rights.
To control what AI tools are sanctioned for different teams in an organization, an allowlist-based application control system can be implemented. An allowlist will prevent users from running any other app or tool apart from the pre-approved list. By combining these two solutions into a single control plane, Securden Endpoint Privilege Manager helps mitigate the risks of shadow AI at the endpoint level.
Continuous AI Application Discovery
Gain instant visibility into every AI tool being run by users on their Windows and macOS endpoints. Discover installed AI apps, portable executables, scripts, and unknown binaries, along with metadata like file hash, publisher, and file path.
Just-in-Time Privilege Elevation
AI agents and tools do not need local admin rights to function. Eliminate local admin rights across endpoints and servers. Elevate individual applications on a just-in-time basis through granular policies and approval workflows.
Allow Trusted AI Tools
Control what AI agents and tools users can run on their endpoint with granular application control. Allowlist approved AI tools and applications. Everything else is automatically blocked.
Complete Activity Tracking
Monitor which applications and AI tools are run on endpoints and continuously feed data to SIEM tools. Prove compliance with regulatory compliance using drilled down reports for GDPR, HIPAA, PCI-DSS, NERC-CIP, and Essential Eight.
These controls matter because they help you control the shadow AI tools that run on endpoints connected to your network. Local admin rights can amplify the blast radius of minor security incidents; AI agents and tools can amplify the intensity of the blast. The safest course is to prevent the agents from gaining any administrative access unless it is absolutely required. Even then, you must time-box the administrative access and enforce strict auditing during elevated access.
Book a demo and get a free Proof of Concept for Endpoint Privilege Manager.