GLOBAL RESEARCH ARCHIVE
Guilty Until Proven Durable: AI Casts A Long (Security) Shadow
Research evidence excerpt
Guilty Until Proven Durable: AI Casts A Long (Security) Shadow
Shadow AI = Shadow IT On Steroids
The Shadow AI market is still early, but we believe the control stack required to support GenAI
SaaS apps and autonomous agents will need to scale quickly as these tools gain access to
enterprise data, applications, and workflows. The Samsung ChatGPT source-code leak in March
2023 remains the most cited example: employees reportedly pasted confidential code and
internal notes into ChatGPT, creating a clear enterprise data-loss event. A more recent — and
more pointed — example is Anthropic’s Fable 5. Launched in June 2026, the model was briefly
pulled under a US export-control ban over its cyber capabilities before being reinstated in July
with a hardened safety classifier, underscoring how quickly frontier capability is outrunning the
controls meant to contain it.
We believe Shadow AI could become materially larger than Shadow IT because it builds on
existing unsanctioned-app risk while adding new vectors around model access, data leakage,
agent autonomy, prompt injection, governance, and observability. Demand should be driven by
three forces: rising regulatory pressure, expanding security and governance budgets, and the
need for new, Shadow AI-specific controls as enterprises deploy GenAI and LLMs — a
combination that opens up an incremental TAM opportunity.
Due to the speed at which threat vectors are evolving, regulation is building quickly on both sides
of the Atlantic. In the US, a June 2026 executive order established an early-access review
process for frontier models that materially advance national-security capabilities; FINRA’s
Regulatory Notice 24-09 already applies existing securities rules to GenAI and LLM use; and the
The English excerpt is extracted automatically from the cited source page and may contain layout or recognition errors. It is never batch translated.
Open report viewer