
I contributed to an editorial on AI Security, Shadow AI and Governance which got released today.
The report is available for download at https://www.coriniumintelligence.com/content/our-new-threat-landscape-ai-security-shadow-ai-and-governance
How Australian and New Zealand security leaders are navigating the security risks created by the rapid adoption of artificial intelligence
AI tools are now part of daily work. Employees use chatbots, browser plugins, meeting assistants and coding tools to move faster. In many cases, these tools are being used without approval or oversight.
Vendors are embedding AI features into platforms organisations already pay for and trust. And attackers are using the same technology to find and exploit weaknesses at speeds security teams have never had to contend with.
This report examines the exposure on three fronts:
- Unsanctioned AI tools employees are using without organisational approval, and the corporate data leaving through them
- AI being embedded into the approved corporate stack, creating a shadow AI problem inside tools that have already passed procurement
- A changing threat environment in which the window from vulnerability identification to active exploitation has compressed from roughly a year in 2021 to potentially under an hour by the end of 2026
The report considers what practical AI governance looks like today, how organisations can build it with the frameworks already available, and what the wait for regulation is likely to cost.