140 AI tools in use, 12 approved: what security teams found when they went looking for what was actually running
When Cloud Box Technologies checked which artificial intelligence tools its employees were using, it found more than ten times as many as it had approved. "During a sweep of our technology stack, we came across 140 AI tools being used by different teams, compared to only 10 to 12 sanctioned by the IT teams, such as Copilot, Gemini and Canva AI," said Biju Unni, Vice President at Cloud Box Technologies. "It was the result of a thorough audit of network and data usage that led us to these findings."
What worried the company more was where some of those tools had been plugged in. "We came across at least 15 AI integrations that were unauthorised and connected to internal corporate systems," Unni said. Those systems included customer records, finance software, client email and cloud storage. On average, each unapproved tool had been in use for one to three months before anyone noticed it.
Few companies say publicly what they found when they looked, and the wider figures suggest Cloud Box Technologies is typical. Verizon's 2026 Data Breach Investigations Report, which studied more than 22,000 breaches worldwide, found that 45% of professionals now use AI at work regularly, and that 67% of them do so through personal accounts their employers never approved. Cases in which staff exposed company data by mistake, with no intention of causing harm, were four times more common than a year earlier. In 28% of the cases where security software caught sensitive data leaving a company, an employee had pasted software code into an AI tool.
"What I've observed is that AI adoption almost always outpaces governance," said Meriam ElOuazzani, Vice President for Middle East, Turkey and Africa at Censys. "By the time organisations start asking what AI is being used, employees have already found their own ways of working. What surfaces then are tools nobody approved, mapped, or claimed responsibility for."
Most company data reaches these tools through everyday tasks
Employees rarely set out to leak anything. They paste in a contract they need summarised, a spreadsheet their manager wants turned into a to-do list, or a long email chain they have no time to read. "Think about how you can copy-paste an email thread to understand what's going on in that particular topic without going through each email one by one," Unni said. "This raises a huge security issue."
ElOuazzani sees the same behaviour with software code, passwords and internal technical documents. "Nobody makes a deliberate decision to expose the organisation," she said. "They make a convenient one."
At Cloud Box Technologies, the logs showed habits getting deeper over time. "Employees went from experimenting with an unsanctioned tool to a full-blown dialogue by uploading crucial documents to generate templates and responses," Unni said. In the company's closest call, a developer uploaded some of its software code to a free online AI tool to check it for errors. The security team spotted the upload by watching network traffic and stopped it. "Luckily, there was no sensitive customer data breach," Unni said.
Senior leaders are among the heaviest users. "Most organisations can tell you how many AI tools they approved. They cannot tell you how many are actually in use," ElOuazzani said. "More than 80% of workers use unapproved AI tools. Among executives, that figure reaches 93%. The people sponsoring governance policies are often the same people bypassing them."
Personal accounts put company data beyond the security team's reach
At Cloud Box Technologies, most of this activity ran through staff members' own logins. "Approximately 80% of AI activities take place using personal accounts such as Gmail or Yahoo," Unni said. That leaves the company unable to see or stop what happens in those accounts. "They won't have any ownership, lack the privilege to revoke access, and have no other administrative rights."
Malicious software that steals saved passwords from computers is now widespread, and it collects work and personal logins alike. "Your perimeter now includes every device your employees personally own," ElOuazzani said.
Art Gilliland, Chief Executive Officer of Delinea, described how his company deals with this. Staff can use their own phones and laptops for work only if they install Delinea's management software, and removing that software wipes all company data from the device. Without that separation, a company is exposed under data protection laws in Europe, the United States and the Middle East as soon as an employee leaves with customer records on a personal phone. "If you are not doing that, you are hoping the person will behave the right way when they leave, and that hope is not a strategy," Gilliland said. "Most people, I like to believe, actually are good, even though I work in a very cynical industry. If you have one person who is not, it puts the company at risk."
Security teams can usually tell which AI services employees are visiting and how much data they send. After that, the trail stops. "In the case of sanctioned AI tools, organisations know exactly what's happening," Unni said. "When it comes to third-party AI tools, the visibility stops dramatically, especially when these platforms are accessed using personal accounts or browsers. The visibility stops right when the data reaches the tool's servers."
After that point, he added, "security teams may not know what models were used, how the input was analysed, how the AI tool came up with the output, and whether the data fed will be used for training future models."
Censys can examine what an AI provider exposes to the internet and check whether it matches what the provider claims. What an employee types into the service is out of reach. "You cannot see what an employee submitted in a prompt, or whether that tool retains inputs your legal team has never reviewed," ElOuazzani said. "Visibility stops the moment someone logs in from a personal device outside corporate controls, and that gap carries real consequences."
AI tools linked to company systems create the biggest risk
A chatbot sees only the paragraph someone pastes into it. A tool with ongoing access to a customer database or a shared inbox can read far more, and sometimes change it. "Without being vetted by security teams, such integrations will have a totally different risk profile compared to public tools without such integrations," Unni said. Cloud Box Technologies now gives AI tools only the access a task requires, "ensuring even these can be revoked if needed."
Asked how many AI tools are connected to company systems before anyone reviews them, ElOuazzani said nobody in the industry keeps count. "The honest answer is: most of them," she said. "Asset discovery has never kept pace with asset creation. Subsidiaries spin up cloud infrastructure. Acquisitions bring in unknown environments."
Attackers keep a list of their own. "Attackers build their own inventory of your organisation," she said. "They don't care whether an asset is officially documented. If it's reachable from the internet, it's already on someone else's map."
This summer showed how quickly that can matter. The criminal group Cl0p broke into companies through a previously unknown flaw in Windchill and FlexPLM, software from PTC that manufacturers use to manage product designs. The flaw let attackers take control of the servers without logging in. PTC began releasing fixes on 17 June, and BleepingComputer reported that Philips and GE were among the companies investigating whether they had been hit. "Fewer than 100 instances of Windchill were exposed to the internet, yet Cl0p found them," ElOuazzani said. The group took "product designs, bills of materials and supplier data," she said. "That is intellectual property that takes years to build and cannot be recovered once it leaves."
Censys researchers also found controllers that run machinery in plants and utilities which could be reached over the internet through remote desktop software. When ElOuazzani showed the finding to infrastructure operators, she asked them one question. "What does your operational technology estate look like to someone who does not work there? Most could not answer with confidence. That is the part that stayed with me."
Delinea's chief executive says searching for AI agents wastes money
AI agents are programs that carry out tasks by themselves. Some last only a few minutes, and Gilliland believes that makes listing them pointless. "This whole idea of visibility and discovery is a waste of time," he said. "You will never find everything, and it is not going to matter at all. You do something and five agents spin up, they do something for ten minutes, and then they are gone. If you are not scanning at that moment, you will never find them."
He would put checkpoints in front of the company's most valuable systems and data. "What we talk about instead is how you get in front of the assets that matter. This database, this service over here, this customer information set, because that is what AI wants to get access to," he said. "As AI tries to talk to them, you create an inventory of the actions. Then you can decide on every interaction, every action, whether to allow it." He added that most companies already know which systems matter to them. "I know what my 100, or depending on how big it is, 1,000 things I care about are."
Attackers, and the AI tools they now use, move from one system to the next by finding passwords that have been left lying around. Delinea's answer is to remove permanent logins, so that access is granted for a specific task and then withdrawn. "One of the things AI is so good at is going through the environment looking for those credentials," Gilliland said. "If you eliminate those standing privileges in the environment, then the AI cannot move. It may still break in, though it is very difficult for it to move."
ElOuazzani's view is that "you cannot govern what you cannot see." The two positions deal with different problems. Censys looks at what a company exposes to the internet, where a forgotten server stays put and can be found. Gilliland is talking about programs that run inside a company for a few minutes and then disappear.
Every AI agent needs a named person responsible for it
Even if agents cannot all be listed, someone has to answer for what they do. Joe Gonyea, Executive Vice President and Chief Legal Officer at Trellix and Skyhigh Security, said companies should treat each agent as they would a new employee. "Companies really have to start thinking about them like a unique identity, giving them defined ownership, tightly scoped permissions, inventory registries, and then mechanisms to revoke all credentials if one starts behaving unexpectedly," he said.
Mohamed El Yahya, Managing Partner, Global Infrastructure Services, Middle East and Africa at DXC Technology, pointed to a practice that already exists. Some built-in administrator accounts cannot be switched off without breaking the system they run, so companies assign each one to a single person. "There is one owner of that account who has the password for it, and anything that happens through that account is that person's responsibility," he said. He does not yet see agents handled the same way across the industry, though he expects them to be. "With time and with specific agents, there will be some sort of attribution of specific agents to specific people."
At Delinea, which uses Claude Enterprise as its main AI platform alongside Copilot, every agent is linked to the employee who started it. "If Art does a project and I ask my agent to do something, the company needs to know it is Art's agent," Gilliland said. "I cannot ask my agents to go and do crazy stuff without some level of personal accountability as an employee of Delinea." He also asked for some leeway for the employee. "Agents will do pretty much whatever they need to do to be able to finish the task I ask them to do. We need to have some grace around that for the human also."
That leeway matters because companies are creating a new kind of job: checking the cases an AI agent cannot settle by itself. In those cases, El Yahya said, the agent will "flag it to a human agent to take the call on what needs to be done." The person checking often carries the consequences without being able to see how the software reached its answer. Gonyea said that is the wrong way to set it up. "If you have a system where you have one person that you have now offloaded the entire responsibility of risk onto, that person is going to have the darkest circles under their eyes you have ever seen," he said. "You have a cybersecurity vendor that is going to own software integrity, you have customers that own operational authority, you have model developers that are going to own how they develop the models. If all of those things are working together toward a common purpose, then you do not end up in the world of finger-pointing, saying I have now offloaded all of my risk to this one person because he did not push this button, or she did not push this button. That is a scary world to be in."
Responsibility is also unclear at the top. "When I look at how organisations assign ownership of AI security, responsibility is scattered across the chief technology officer, chief information officer, chief data officer, infrastructure and the chief information security officer simultaneously," ElOuazzani said. "No single function holds the line."
Regulators will want a record made at the time of each decision
Gonyea said new AI rules will require companies to keep records created when each decision is made, and will not accept accounts pieced together after something goes wrong. "Regulators want to be able to see how decisions are being made by these tools," he said. "With new regulations coming out now, you have to be able to show contemporaneous evidence, and then you have to be able to demonstrate human oversight."
El Yahya said companies need both limits on what an AI system can do and a record of what it did, because the limits will sometimes fail. "You cannot have one without the other," he said. "You cannot assume that your guardrails are always 100% proof. We need to find a way to check whether these guardrails are holding the model in or not." Large companies already collect activity logs from all their systems into one central store that intruders cannot alter. "There will be something similar for agents," he said.
Gilliland wants every exchange between an agent and a company system recorded. "You need to be able to rewind the tape and say, what was actually asked, what was returned, and what happened," he said. Delinea uses AI to go through those recordings and flag moments such as "something weird that happened at minute 32 of this long session," and it can cut off a session while it is happening.
Kurt Muehmel, Head of AI Strategy at Dataiku, pointed to the European Union's AI Act as a workable model because it sorts each use of AI by how much harm it could cause. "For the most part, these types of risks really focus on human liberties, on human rights, and the potential abuses against those, which I think is probably a pretty good firewall," he said.
Security tools that never raise false alarms are missing real threats
AI-based security tools raise false alarms, and staff sometimes act on them. Gonyea said a system with no false alarms is looking at too little. "You want false positives. If you do not have any false positives, then you do not have a system that has expansive enough coverage," he said. The problem comes when there are too many. "If 70%, 80% or 90% become false positives, then your analysts are going to be fatigued, and no amount of coffee is going to help them do their job."
El Yahya said the fix is the same one companies already use for their own staff. "When a human agent picks up and acts on a false positive, you go and coach them on what the steps are and what they missed," he said. "It is the same with the AI agent."
Muehmel said the hardest mistakes to catch are the ones that look correct. "Probably the hardest errors from AI to catch are the ones that don't look like errors," he said. Companies need an agreed picture of what a good answer looks like, and then need to check large numbers of answers against it. "It's important for any one individual to keep a clear eye on what's going out, especially if they are the human in the loop," he said. "The real solution long term is to test the responses against what's expected and to confirm whether they are accurate."
Security leaders disagree on who should pay when AI causes harm outside the company
For now, courts and contracts are settling most disputes. "We're finding that out right now, and primarily it's being handled through the court system," Muehmel said. Traditional software gives the same result every time it gets the same instruction, which makes a fault easy to pin down. AI models can give different answers to the same question. "Organisations are in somewhat uncharted territory in terms of liability," Muehmel said. He advised companies to read their AI suppliers' contracts closely "and to make sure that when they're signing those contracts, liability is clearly assigned and the notion of what is an error from one of the systems is clearly defined."
Gonyea sees responsibility shared between the company that built the AI model, the security firm that deployed it and the customer using it. He warned against rules that would make companies pay for harm even when they did nothing wrong. "It could discourage companies from investment, and also encourage them to further isolate and shield themselves in a way that might not be good for the industry as a whole, or for the customers," he said. He also doubts that deciding who pays solves much. "If an insurance company writes a cheque, if a generative AI developer pays some fine, it does not restore customer trust. It does not make the customer whole, it does not roll back the clock," he said.
Gilliland wants the companies building the most powerful AI models held responsible for damage they cause. He said some of them are asking for regulation in "a slightly disingenuous way," hoping that following a set of rules will clear them of blame. "If an oil company creates a spill, they are accountable for cleaning it up. Their cost is high, so obviously there is a lot of money and expense put into safety," he said. "That same kind of assignment of risk is super important in my opinion."
Inside a company, Muehmel said, responsibility depends on how the tool is used. "In some cases, it may rest with the end user to make sure that they're appropriately using the technology. In other cases, it might be higher up the chain," he said. "Organisations need to be designing systems that are safe for their employees to use, where the employee essentially can't use it irresponsibly, and if they're not doing that, then of course that accountability is on leadership as well."
Banning every unapproved tool would have pushed staff further out of view
When Unni took his findings to Cloud Box Technologies' leadership, the company chose not to ban unapproved AI outright. "The findings were shocking, especially with the data exposure and the potential operational concerns," he said. "The remedial steps helped without imposing a blanket ban, which may have escalated the problem." Within 72 hours, every tool had been sorted by risk and either approved, restricted or blocked. The company then added monitoring of web traffic, company laptops and the websites staff visit. "Technically, we have reduced the detection time to less than 24 hours for most of these applications," Unni said.
ElOuazzani said how a security chief explains the findings decides what happens next. "If the CISO has already translated threat intelligence into business language before walking in, the discussion moves quickly. If they haven't, the executive team hears statistics and feels nothing," she said. The figures she cited point to more pressure: attackers who get into a company now typically go unnoticed for 14 days, up from 11 a year earlier. "Start with what the business loses. Then trace it back to the gap. That is the entry point that produces decisions," she said.
Muehmel said companies also need to talk about failures internally, even if they never discuss them in public. "Even if organisations are not sharing publicly that there are failures, they absolutely need to be sharing those failures internally so that there can be shared learnings from them, so that you don't repeat those same failures over and over again," he said.
At Cloud Box Technologies, the 140 tools came from employees trying to get their work done faster. They used software the company had not given them and accounts it could not close, and they connected some of it to systems nobody had checked. "Organisations are treating AI adoption as a speed problem and AI security as a later problem," ElOuazzani said. "Later is already here."