A new ThreatDown report finds that 74% of organizations face exposure to shadow AI, where workers deploy unsanctioned artificial intelligence tools outside the view of IT and security departments. The research highlights a widening governance gap as employees adopt AI applications, browser features, and automated agents that haven't been approved or audited by corporate oversight teams. The disconnect creates security and data risks that most organizations don't know they have.
The tool count mismatch reveals the scale of the problem. Among surveyed companies, 60% anticipated running between one and five AI tools, but only 26% actually operated within that range. In reality, 44% of firms are running between six and 15 tools, while 30% are operating over 16 AI applications. Workforce adoption also outpaced expectations: companies estimated that roughly 33% of their employees were using AI tools, when the actual figure reached 58%. The gap between expected and actual use means most AI activity is happening without oversight, the report notes.
Shadow AI refers to unauthorized deployment of AI tools, models, and browser capabilities by staff members without organizational approval or IT visibility. According to the report, "Someone on your team pasted a customer contract into a chatbot last week to save a few minutes. Someone else dropped in a chunk of source code to debug it faster." Neither employee gave it a second thought, but both moved company information onto infrastructure that security teams have never examined, never vetted, and can't control—and once that data leaves, there's no way to retrieve it. Different departments pick their preferred tools and make independent choices about what information enters and exits the corporate environment.
The threat landscape has shifted because tools no longer just accept input—they take action. Many now run as agents with ongoing permissions to read files, write and execute code, and make autonomous decisions, ThreatDown explains. These agents also connect to other systems through MCP, creating what the report calls a new stealth supply chain that lacks oversight. When a threat actor compromises a shadow agent, they inherit access to everything that agent was authorized to touch, from files to credentials. To address these challenges, ThreatDown developed AI Detection & Response (AIDR), a governance tool that gives IT and security teams visibility into AI use across the organization, identifies unauthorized applications, and surfaces newly discovered tools for review—with the option to label new tools as unauthorized by default. The platform provides an AI tool inventory, endpoint activity monitoring, and a unified dashboard that consolidates usage trends and real-time events without switching between consoles.
The stakes go beyond inventory control. As agent-based workflows become standard and employees continue adopting tools faster than IT can track them, the gap between perceived and actual AI deployment will likely widen further unless organizations implement continuous discovery and governance frameworks. Organizations that expected to manage a handful of vetted applications now face a reality where dozens of unvetted tools process sensitive data, execute code, and connect to external systems—all beyond the scope of traditional security controls, making real-time visibility and automated governance essential to closing the exposure window.

