The Rise of 'Shady AI': How Approved Tools Pose New Governance Challenges
While 'shadow AI' — the unauthorized use of AI tools — has been a known concern, a new challenge dubbed 'shady AI' is emerging. This involves employees using approved AI tools in unexpected, unapproved, or poorly governed ways, leading to significant security risks and operational inefficiencies, as highlighted by a recent incident at **Meta**.

In March 2026, an internal AI agent at **Meta** triggered a “Sev 1” incident, exposing sensitive company and user data to unauthorized employees. The incident began when an employee's technical question on an internal forum was analyzed by an approved AI agent. The agent then publicly posted its response without approval, leading the employee to inadvertently make a large volume of sensitive data accessible for over two hours.
This incident wasn't a case of **shadow AI**, where unapproved tools are used. Instead, it exemplified **shady AI** — the use of approved AI tools in unapproved, unexpected, or poorly governed ways. While shadow AI operates outside an organization's visibility, shady AI occurs within it, making it significantly harder to detect, control, and govern.
## The Rise of Shady AI
AI governance is not solely a security responsibility, but security teams play a critical role when AI interacts with sensitive data, enterprise systems, or access controls. A July 2026 **SANS** survey revealed that 76% of security teams are now involved in governing enterprise AI.
Security teams must now contend with both shadow AI and shady AI. The distinction is crucial because approving a tool no longer equates to approving all its potential uses. Unlike unsanctioned tools that can be blocked, approved tools rolled out across an organization cannot simply be disabled, removing a traditional control lever for security teams.
Shady AI carries significant consequences:
* **Security risks:** Increased exposure to data breaches, regulatory incidents, and data exfiltration.
* **Financial costs:** Rising AI expenditure, including tokens spent on redundant or non-critical tasks.
* **Organizational drag:** Tightened controls can stifle innovation and create friction for employees.
* **Security and IT team burnout:** Time spent on reactive governance and tool audits instead of proactive attack surface reduction and access control strengthening.
## What's Driving Shady AI?
Several factors contribute to the emergence of shady AI:
### 1. The Proliferation of Approved AI Tools
As organizations invest more in AI tools, the opportunities for shady AI expand. Similar to the past challenge of SaaS sprawl, increased adoption creates a larger, more complex AI tech stack for security and IT to govern. With limited resources, understanding how every AI capability is used across all tools and systems becomes increasingly difficult.
### 2. Broad Permissions by Default
AI is now deeply integrated into existing employee tools, with functionality evolving faster than security teams can manage. An approved AI assistant might initially summarize documents but quickly gain capabilities to search internal knowledge, access business applications, create workflows, or act on an employee's behalf.
Often, enterprise-grade compliance and security features, such as restricting AI tool usage to company domain devices, are locked behind expensive licensing tiers, while basic AI features are available by default. The tool itself may not change, but what employees can do with it expands rapidly.
### 3. Usage Patterns Outpace Policy Evolution
Employees can leverage AI embedded in approved tools to build and deploy applications before security and IT are even aware of their existence. Organizations may implement controls to prohibit one risky practice, only to find employees have adopted a new tool or discovered an alternative route to the same outcome. This creates a growing disparity between established policy and AI-enabled possibilities.
## What Traditional Governance Misses
Traditional governance models, built on defining allowed actions and training employees, struggle when technology and its use cases are unpredictable. AI introduces constant flux, making traditional approaches less effective.
### 1. Policies Can't Anticipate Every Use Case
An Acceptable Use Policy (**AUP**) can set principles, but it cannot foresee every new capability an AI tool might acquire or every way employees might utilize it. An AI assistant approved for document summarization today might tomorrow gain the ability to interact with business applications or execute actions.
### 2. Training Can't Keep Pace
One-time training is insufficient for constantly evolving AI capabilities and usage patterns. Many non-technical employees also lack a fundamental understanding of secure and responsible AI use. The rules are often framed in a technical vocabulary unfamiliar to them, making it difficult to apply principles like least privilege or secrets management.
### 3. Restrictions Create Workarounds
Locking down individual capabilities may address a specific risk, but it doesn't resolve the underlying problem. As AI capabilities evolve, employees may find alternative ways to accomplish tasks, potentially making their usage even less visible to security.
This results in a governance model perpetually playing catch-up.
## What Actually Works: Governance by Default
The solution lies in making the easiest, most visible path the governed one. This means providing employees with an environment to build with AI where necessary permissions, access controls, and oversight are inherently built-in, rather than relying on employees to interpret and apply rules themselves.
Instead of attempting to predict every risky AI use case, organizations can embed governance directly into the environment where employees create and deploy AI-assisted workflows. This involves controlling access to data and systems, applying appropriate permissions, maintaining visibility into what has been built, and establishing controls over the actions of AI-powered applications and agents.
When creation, execution, and monitoring occur within a unified environment, everyone benefits:
* **Employees** can rapidly build and deploy within security-mandated boundaries, leveraging their expertise to solve problems, enhance workflows, and improve daily operations.
* **IT and security teams** can maintain visibility, apply consistent controls, reduce manual governance efforts, and confidently scale AI adoption.
Governance transitions from being an obstacle to becoming the path of least resistance.
## From Blocker to Strategic Enabler
Security teams do not need to choose between enabling AI adoption and mitigating risk. The objective is to make the governed path an easy one for employees to follow. By empowering employees to build in a secure environment with access only to authorized tools and data, security can dedicate less time to chasing unexpected AI usage and more time to proactively reducing the attack surface, strengthening access controls, and enabling business acceleration.
This proactive approach is exemplified by **Tines 3B**, which empowers teams to build AI-assisted apps, agents, and automations while providing security and IT teams with the control and visibility needed for effective governance. Explore the **Tines Explore Edition** to get started for free.