Urgent.News

What's breaking now, across thousands of outlets.

Tech

Why employees, not threat actors, are 2026’s biggest risk

Shadow AI is exposing businesses to hidden employee-led risks, demanding stronger identity security and visibility.

Why employees, not threat actors, are 2026’s biggest risk

Despite the hype surrounding nation-state threats, organizations often overlook the risks that originate from within. The introduction of Generative AI tools has brought efficiency gains for employees, yet these platforms have also created a new class of risk. Two-thirds of UK organizations report being unable to track if employees share data using approved tools.

This is primarily due to employees uploading sensitive information, such as contracts or client proposals, to AI models like ChatGPT or Claude to expedite routine tasks. A majority (93%) of global CEOs have adopted generative AI to some extent in the past year (PwC). The issue lies in the fact that this activity often occurs without oversight, directly in the browser, making it difficult for organizations to monitor the flow of company information.

There are two major risks stemming from this behavior. Firstly, employees may unintentionally share credentials or access details with public AI models, which could lead to unauthorized access if the model is compromised. Secondly, sharing personal data with AI models can violate data protection regulations like GDPR, leading to fines and reputational damage.

To address this issue, leaders must implement tools and technologies that provide visibility and control over usage at both the browser and application levels. Employee behavior is not solely driven by a lack of cybersecurity training; the real issue is incentives. While most employees understand the risks, 35% of UK businesses admit to data sharing through external tools, indicating that many would prefer to bypass slower, more secure options for convenience.

In highly regulated sectors like finance, these practices could result in hidden breaches, capable of causing catastrophic damage, such as exposing customer transaction histories or credit scores. Combating this "Shadow AI" use within enterprises starts with designing approved AI tools that seamlessly integrate with existing platforms like Microsoft 365 and Google Workspace.

These tools should be continuously refined based on user feedback, avoiding excessive restrictions that make the tool cumbersome to use. However, currently, nearly two-thirds of organizations remain in the pilot stage of their AI initiatives, without scaling across the enterprise (McKinsey). So, how can organizations gain control of the Shadow AI problem today?

The answer lies in tools that bring unsanctioned AI usage under control. Real-time visibility into employee interactions with consumer AI tools is crucial. Next-gen identity security platforms can provide immediate insight into who or what is accessing what data, from which devices, and where it's being shared. Once high-risk behavior is identified, organizations can automate corrective actions, redirect users to secure AI alternatives, or seek justification for their business use case before proceeding.

As AI agents evolve, with multiple underlying agents, visibility becomes even more critical. An identity security tool can create a 'discoverable' ledger that acts as a complete, unchangeable trace of all agent activities and interactions, applying controls to each agent based on a minimum privilege requirement. This approach, known as agent permissions, ensures that permissions aren't automatically cascaded.

By closing the visibility gap, organizations can tackle the root cause of Shadow AI – an identity problem. The solution lies in adaptive identity security platforms that move from static to dynamic, real-time approaches to access, effectively operationalizing zero trust and ensuring no identity, human or non-human, is trusted by default.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 13 August →