Meetings are happening right now in boardrooms everywhere. Executives are talking about AI acceleration. They’re throwing around words like “token maxing” and “supercharging operations.” And they’re watching demos where a marketing manager spins up a working app in 40 minutes.
That’s exciting. The productivity gains are real. But here’s what they’re not talking about: every one of those apps creates a new attack surface that nobody owns.
Gartner says 41% of employees are now “citizen developers.” They build things outside IT’s view. The old friction — going through procurement, writing requirements, signing contracts — is gone. So is the accountability that came with it.
Microsoft’s Cyber Pulse report found over 80% of Fortune 500 companies have active AI agents built on low-code platforms. These things didn’t go through security review. Nobody signed a contract. No vendor accepted the risk. The risk just stayed inside the company, with nobody holding it.
IBM’s data breach report says shadow AI breaches took 247 days to detect on average. Among orgs that reported AI-related breaches, 97% lacked proper AI access controls. Not a typo.
Traditional vendor risk management assumed someone outside the company accepted your risk. That framework is dead. Now the risk lives inside your marketing department’s weekend project, and nobody’s watching.
The tools exist to scan for anomalous agent behavior. They treat symptoms, not the root cause. The real fix isn’t technical — it’s organizational. Someone has to own the accountability question. Right now, nobody does.
