Vanta reports a rise in unapproved AI tools at work, with 70% of companies experiencing "shadow AI," leading to security risks and challenges for IT teams.
The long-standing issue of 'Shadow IT'—unapproved software used within a company—is being significantly amplified by the rapid proliferation of AI tools. Data from Vanta reveals a 36% year-over-year increase in such unvetted technologies. On average, companies discover approximately 140 unauthorized AI tools accessing their systems within just 90 days of connecting to Vanta's platform. This surge is primarily driven by employees facing intense pressure to accelerate their work, often leading them to bypass official, slower procurement processes when seeking AI solutions to meet their performance demands. Consequently, when internal approval mechanisms are sluggish, employees frequently resort to implementing AI tools without proper authorization, exacerbating security and compliance challenges.
The strategy of simply blocking unapproved AI tools has proven largely ineffective in curbing their usage. Vanta's analysis indicates a persistent 'security whack-a-mole' phenomenon: for an average customer, employees reinstall revoked tools more than 100 times within a 30-day period, and this figure can rise to roughly 1,000 times over a year. Critically, these reinstalled tools are not new alternatives but predominantly the same applications that were previously removed. This consistent re-introduction of restricted AI applications highlights their perceived indispensability by workers, who are willing to circumvent security measures to maintain access to tools they believe are essential for their daily tasks.
The AI tools most frequently involved in this 'remove-and-reinstall' cycle are not obscure applications but prominent names in the industry, including Anthropic, OpenAI, and Cursor. This pattern is understandable given that employees' daily workflows often become dependent on specific AI functionalities; losing access to such a tool creates an immediate and impactful gap, which workers tend to resolve themselves by re-installing the software. Furthermore, these particular AI tools pose higher risks than standard unapproved apps because they typically require deep access to sensitive company data. Vanta's data shows that Large Language Model (LLM) vendors are 62% more likely to be flagged as 'high risk' compared to traditional software vendors. This elevated risk stems from their interaction with sensitive company data, potential connections to source code, and their classification as critical components for business operations. The combination of broad data access, high operational stakes, and inadequate security oversight significantly increases the potential for data leaks or unauthorized access, especially in the absence of clear vetting rules for AI tools.
A significant security vulnerability lies in the fact that a vast majority of 'shadow IT' vendors, particularly those involving AI, evade proper security vetting. Vanta's data reveals that only a meager 2% of these vendors ever undergo a formal security review. This means that a staggering 98% of these tools remain unvetted, despite being in active daily use by employees. This oversight is contributing to a concerning trend where over half—55%—of an average organization's entire vendor ecosystem now falls under the 'shadow IT' classification. This proportion is steadily climbing as the pressure for AI adoption within companies continues to intensify, further widening the gap in security oversight.
Recognizing the futility of a strict 'ban-it-all' approach, security teams are evolving their strategies. Historical precedents, such as the widespread adoption of iPhones, Dropbox, and more recently, AI note-taking tools like Granola, demonstrate that tools embraced by employees often eventually find their way inside the corporate security perimeter rather than remaining permanently blocked. Learning from this, companies are now focusing on implementing faster, yet still rigorous, review processes for new tools as soon as they appear, rather than attempting indefinite exclusion. Many organizations are leveraging third-party risk management tools for this purpose. These solutions integrate with a company's identity provider to automatically detect which vendors employees are actively using and assess them against predefined risk frameworks, thereby enabling proactive and efficient security oversight before human intervention is required.
The findings presented in this article are derived from anonymized usage data collected across Vanta's extensive Third-Party Risk Management customer base, encompassing thousands of businesses. Data was gathered and analyzed from February 2023 through April 2024. Vanta's methodology involved comparing various metrics, including discovered vendor counts, security review rates, and inherent risk levels. This analysis was conducted across diverse industries and company sizes. The data was obtained by integrating with customers' identity providers, which are the software systems responsible for managing employee logins. For year-over-year comparisons, point-in-time snapshots from January 2023 and January 2024 were utilized from the same cohort of customers, ensuring consistency in the comparative analysis.