普通外文研报
Guilty Until Proven Durable: AI Casts A Long (Security) Shadow
研报英文原文证据摘录
Guilty Until Proven Durable: AI Casts A Long (Security) Shadow
Shadow AI = Shadow IT On Steroids
The Shadow AI market is still early, but we believe the control stack required to support GenAI
SaaS apps and autonomous agents will need to scale quickly as these tools gain access to
enterprise data, applications, and workflows. The Samsung ChatGPT source-code leak in March
2023 remains the most cited example: employees reportedly pasted confidential code and
internal notes into ChatGPT, creating a clear enterprise data-loss event. A more recent — and
more pointed — example is Anthropic’s Fable 5. Launched in June 2026, the model was briefly
pulled under a US export-control ban over its cyber capabilities before being reinstated in July
with a hardened safety classifier, underscoring how quickly frontier capability is outrunning the
controls meant to contain it.
We believe Shadow AI could become materially larger than Shadow IT because it builds on
existing unsanctioned-app risk while adding new vectors around model access, data leakage,
agent autonomy, prompt injection, governance, and observability. Demand should be driven by
three forces: rising regulatory pressure, expanding security and governance budgets, and the
need for new, Shadow AI-specific controls as enterprises deploy GenAI and LLMs — a
combination that opens up an incremental TAM opportunity.
Due to the speed at which threat vectors are evolving, regulation is building quickly on both sides
of the Atlantic. In the US, a June 2026 executive order established an early-access review
process for frontier models that materially advance national-security capabilities; FINRA’s
Regulatory Notice 24-09 already applies existing securities rules to GenAI and LLM use; and the
本摘录由系统从所标注的 PDF 证据页直接提取并保留英文原文,不做批量翻译;登录后在阅读器切换中文时才按需翻译。
打开研报阅读器