Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026

Here’s what you should know

February 6, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Gartner: 40% of Firms to Be Hit By Shadow AI Security Incidents
News

Gartner: 40% of Firms to Be Hit By Shadow AI Security Incidents

Team-CWDBy Team-CWDNovember 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


By 2030, more than 40% of global organizations will suffer security and compliance incidents due to the use of unauthorized AI tools, Gartner has predicted.

The analyst said a survey of cybersecurity leaders earlier this year revealed that 69% have evidence or suspect that employees are using public generative AI (GenAI) at work.

It warned that such tools can increase the risk of IP loss, data exposure and other security and compliance issues. These should be well understood by now. As far back as 2023, Samsung was forced to ban the use of GenAI internally after staff shared source code and meeting notes with ChatGPT.

“To address these risks, CIOs should define clear enterprise-wide policies for AI tool usage, conduct regular audits for shadow AI activity and incorporate GenAI risk evaluation into their SaaS assessment processes,” said distinguished VP analyst Arun Chandrasekaran.

Gartner’s findings chime with several similar studies.

Last year, Strategy Insights reported that over a third of organizations in the US, UK, Germany, the Nordics and Benelux have faced challenges monitoring for unauthorized AI use. The same year, RiverSafe claimed that a fifth of UK firms have had potentially sensitive corporate data exposed via employee use of GenAI.

Separately, 1Password revealed last month that 27% of employees have worked with non-sanctioned AI tools.

Read more on shadow AI: Over a Third of Firms Struggling with Shadow AI

Technical Debt Mounts

Even legitimate use of GenAI could have unintended consequences, Gartner warned.

The analyst predicted that by 2030 50% of enterprises will face delayed AI upgrades and/or rising maintenance costs due to unmanaged technical debt associated with GenAI usage. Delayed upgrades in particular can create security risks if not properly managed.

“Enterprises are excited about GenAI’s speed of delivery. However, the punitively high cost of maintaining, fixing or replacing AI-generated artifacts such as code, content and design, can erode GenAI’s promised return on investments,” said Chandrasekaran.

“By establishing clear standards for reviewing and documenting AI-generated assets and tracking technical debt metrics in IT dashboards, enterprises can take proactive steps to prevent costly disruptions.”

The analyst also warned about ecosystem lock-in and the erosion of skills that could result from over-eager use of GenAI.

“To prevent the gradual loss of enterprise memory and capability, organizations should identify where human judgment and craftsmanship are essential, designing AI solutions to complement, not replace, these skills,” Chandrasekaran said.

He added that CIOs should prioritize open standards, open APIs and modular architectures when designing their AI stack, in order to avoid over-dependence on a single vendor.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNpm Package Targeting GitHub-Owned Repositories Flagged as Red Team Exercise
Next Article CISO’s Expert Guide To AI Supply Chain Attacks
Team-CWD
  • Website

Related Posts

News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
News

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026
News

Chinese-Made Malware Kit Targets Chinese-Based Edge Devices

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.