With the rise of AI, employees in various roles are building and shipping their own tools, often without IT involvement. This has led to a significant increase in builder-type roles, with a 311% growth year over year. However, this trend has also created a security gap, as these tools are not being properly reviewed for security risks.
Security Risks
The use of AI-powered tools has introduced new security risks, including the potential for data breaches and cyber attacks. According to Vanta’s analysis, organizations with builder roles use 42% more software vendors than those without, increasing the risk of security breaches. Furthermore, the rise of AI has led to a new category of security alerts, with hundreds being generated per month.
The security gap is exacerbated by the fact that many of these tools are being built without formal approval, with 70% of organizations having “shadow AI” tools that are not being properly reviewed. This lack of oversight creates an environment where security risks can go undetected, putting organizations at risk of cyber attacks and data breaches.
Addressing the Gap
To address the security gap, organizations need to implement tools that can automate the review process for AI-powered tools. This can include continuously scanning for new vendors and scoring their risk. Additionally, organizations need to establish policies that treat AI agents wired into company systems with the same scrutiny as traditional software purchases.
By taking a proactive approach to security, organizations can mitigate the risks associated with AI-powered tools and ensure that they are being used in a secure and responsible manner.
Original reporting: KEYT (Ventura/Santa Barbara) — read the source article.