Enterprise AI adoption is outpacing governance, leaving many organizations unable to track AI activity, data movement, or the use of unauthorized tools.

Key facts
- •Cisco’s 2025 Cybersecurity Readiness Index reports that 60% of organizations lack visibility into employee requests made to GenAI tools.
- •Shadow AI differs from traditional shadow IT because rogue AI usage is often invisible to standard discovery tools.
- •AI agents can act across systems at machine speeds, making them difficult to manage with manual review processes.
- •Effective AI security requires continuous asset tracking rather than periodic, one-time audits.
- •Platforms using behavioral analysis can identify threats without needing to predefine attack signatures.
Enterprise AI adoption has grown faster than security governance, creating significant visibility gaps. According to Cisco’s 2025 Cybersecurity Readiness Index, 60% of organizations cannot track the specific requests employees make to generative AI tools. This lack of oversight prevents security teams from monitoring data movement and enforcing policies effectively.
Structural Challenges in AI Monitoring
Traditional security tools are designed to track known software in fixed locations, making them ineffective at identifying AI usage patterns. Because these systems were not built to monitor how AI moves through a network, they often fail to detect 'Shadow AI'—tools used by employees without formal approval. This issue is compounded by AI features embedded into already-approved platforms, which often bypass initial security reviews.
Risks of Unmonitored AI Agents
AI agents present a unique risk because they can perform actions within systems rather than just answering questions. These agents are frequently deployed rapidly to solve immediate workflow problems without formal review. Because they operate at machine speed, an unmonitored agent can affect data and systems faster than human review processes can intervene.
Strategies for Securing AI Ecosystems
To regain control, organizations are encouraged to move away from one-time audits toward a 'living inventory' that tracks AI assets continuously. Security teams are advised to use platforms that employ behavioral analysis to identify anomalies in real time, rather than relying on signature-based detection. Additionally, implementing the principle of least privilege—granting agents only the minimum access required for their specific tasks—is essential to limiting potential damage.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by AI News.

