Moshe Ben Simon
Opinion

The AI tools already inside your company that no one approved

"The organizations that will define enterprise security in 2027 won't necessarily be the ones with the biggest budgets," writes Axonius CPO Moshe Ben Shimon, "they'll be the ones that decided total visibility was non-negotiable before a breach decided it for them."

This year, I encountered a security team at a Fortune 500 company that made a chilling discovery: more than 400 distinct AI tools and services were in active use across the organization, feeding on everything from meeting notes to proprietary code, and not one of them appeared in the company's official asset inventory. They were completely blind to them.
This scenario isn't an anomaly. It's what I see in enterprises regularly. AI has dismantled the foundational assumptions of legacy security programs. For decades, we built our defenses believing that our digital assets were known, our data flows were visible, and risk could be measured by counting hardware and vulnerabilities. Today, every one of those assumptions is breaking down.
1 View gallery
Moshe Ben Simon
Moshe Ben Simon
Moshe Ben Simon
(Axonius)
Operational blindness is only part of the problem; regulation is closing in. The EU AI Act's AI-literacy obligations are already in force, and its requirements for higher-risk systems, human oversight, logging, and documentation are phasing in over the coming years. Every one of those obligations assumes you know which AI systems are running in your environment and what data they touch. Visibility isn't the compliance requirement itself; it's the precondition for meeting one.
The Death of Static Visibility
Traditional security programs were designed for a static world. We assumed devices had fixed IP addresses, cloud servers had predictable lifecycles, and humans were the primary actors interacting with our data.
At the heart of this crisis is shadow AI, the unsanctioned use of AI tools by employees. Today, workers are adopting ChatGPT, Claude, Copilot, Gemini, and hundreds of other AI applications faster than security teams can track them. These tools are spun up, fed confidential business data, and abandoned without ever registering in the company's IT asset database. Gartner's November 2025 “Critical GenAI Blind Spots” research predicts that by 2030, more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI.
But the next wave is even more concerning: autonomous AI agents. These act without waiting for a prompt. They have browser access, file-system permissions, and the ability to operate other software without human initiation. In this reality, real-time, continuous AI asset discovery is the precondition for any meaningful risk calculation. Put simply: if you cannot see the asset, you cannot score the risk.
Measuring What Actually Matters
Because the technological landscape has shifted, the way we measure success has to shift with it. “Time to patch” assumes you know exactly which systems you're protecting. “Number of unpatched endpoints” assumes endpoints are your primary attack surface. Both assumptions fail in an AI-driven environment, where the most damaging data leaks often don't involve a traditional software vulnerability at all.
This doesn't mean patch counts and time-to-patch stop mattering; they still measure real operational discipline. It means they're no longer the whole picture. On their own, they say nothing about the AI systems now touching your most sensitive data. Security teams need to add three KPIs built for that reality:
  • AI Asset Discovery Latency: How quickly is a new AI tool detected and classified once it touches your environment?
  • Data Flow Integrity Score: What percentage of your sensitive data interacting with external AI systems is actively visible, logged, and governed?
  • Crown-Jewel Exposure Paths: How many distinct routes run from the public internet to your most sensitive data — counting the access now delegated to autonomous AI agents as part of the attack surface?
Stop only counting what is broken, and start measuring how fast you can see what is changing.
From Compliance Engine to Posture Intelligence
For CISOs, the AI era requires a shift in both strategy and budget. In my conversations with security-forward leaders, I'm seeing them reallocate meaningful portions of their security spend on the order of 15% to 20% away from redundant perimeter defenses and overlapping static scanners, and toward continuous AI asset discovery, data-flow monitoring, and identity governance built for non-human AI agents.
Security can no longer function as a periodic audit or a compliance checklist. It has to operate at the same cadence as the AI workloads it governs: continuous, automated, and built into the development and procurement lifecycle.
This also changes the boardroom conversation. Executives no longer need to hear, “We have X unpatched vulnerabilities.” They need a truer picture of risk: “We have Y AI tools touching Z classes of sensitive data, with N% visibility, and here is exactly what we still don't know.”
The Line Is Being Drawn Now
On one side are enterprises adapting to continuous AI visibility and dynamic risk posture. On the other are those still running quarterly vulnerability scans against a database that hasn't registered a single new AI tool since it was deployed.
If you want to know where your company stands, try this on Monday morning. Run a 30-minute shadow AI audit: pull your firewall or proxy logs and count how many distinct AI service domains your organization contacted in the last seven days. Compare that number with your list of officially sanctioned AI tools. That gap, in plain numbers, is your current blind spot.
The organizations that will define enterprise security in 2027 won't necessarily be the ones with the biggest budgets. They'll be the ones that decided total visibility was non-negotiable before a breach decided it for them.
Moshe Ben Simon is CPO at Axonius.