AI Business

Shadow AI Code Is Outpacing Security: Why Governance Beats Lockdown

AI-generated scripts built by employees outside IT oversight are multiplying across finance, HR, and marketing teams, creating security gaps and budget drains that traditional controls cannot contain.

·4 min read
The 45% problem: How wild code Is pushing IT toward a security event horizon
The 45% problem: How wild code Is pushing IT toward a security event horizon

An analyst at an insurance firm spent a weekend building an automation tool with Claude Code to streamline vendor invoice reconciliation. The script worked so well she shared it with colleagues. Within weeks, the undocumented tool was running critical financial operations, complete with hardcoded API keys and no error logging—and IT had no idea it existed.

No malicious intent was involved. But the organization now hosts an unowned, unaudited script inside its financial systems. If it fails, exposes credentials, or surfaces during an audit, leadership will struggle to explain how such a tool operated invisibly within their infrastructure.

This scenario illustrates wild code: AI-generated scripts, agents, and applications built by employees beyond IT's visibility. The phenomenon is spreading across finance, HR, legal, and marketing departments—not just engineering teams—and it is expanding organizational attack surfaces faster than security teams can manage.

Mark Settle, a seven-time CIO, describes the dynamic plainly: "We potentially have a viral adoption phenomenon that's not being gated by IT or even by the operations teams within individual business departments."

The security bill comes due

IBM's 2026 Cost of a Data Breach Report reveals that security incidents tied to shadow AI more than doubled in the past year, climbing to 43% from 20% in 2025. These incidents carry an average cost of $5.39M, exceeding the overall average breach cost of $4.99M. Additionally, one in five breaches result in regulatory fines.

The code itself frequently serves as the initial attack vector. Veracode's 2025 GenAI Code Security Report determined that 45% of AI-generated code harbors security vulnerabilities. Escape's State of Security of Vibe-Coded Apps went deeper, examining over 5,600 publicly available applications and identifying more than 2,000 high-impact vulnerabilities and 400+ exposed secrets—including API keys, access tokens, and bank account information.

Untracked spend and duplicated tools are draining budgets

Beyond breach expenses, wild code depletes budgets through less obvious channels: undocumented AI and API spending with no clear ownership, unused software licenses for tools employees circumvent, and IT resources spent locating and fixing scripts that were never recorded. Gartner forecasts that over 40% of agentic AI projects will be abandoned by the end of 2027 as costs escalate and business value remains unclear.

Settle frames the issue directly: "Where things get a little crazy is when individuals decide to start building agents that duplicate the functionality of SaaS modules because they simply don't like the way the workflow has been implemented in the SaaS tool they are already paying for."

Why the usual fixes don't work

Blocking innovation isn't free either

Platforms like Claude Code and Codex enable non-technical staff to resolve operational problems without waiting for IT support. WalkMe's Global Study found that 88% of executives believe their workforce has adequate tools, yet only 21% of employees share that view. If organizations suppress wild code entirely, this gap persists—it simply moves underground.

IT is already stretched thin

Research on AI-assisted development shows that AI shifts responsibility downstream. Someone must still evaluate, comprehend, and support what gets constructed. This burden is substantial: Tines' Voice of Security 2026 reports that 76% of security professionals experienced burnout in the past year, while Auvik's data shows IT burnout at 60%. IBM's C-suite research found that only 11% of technology leaders feel ready for the scale of AI agent rollout expected in the next 12 months, and 77% report that AI adoption is already outpacing governance structures.

What actually works: governance that keeps pace

Settle contends that restriction is not the answer: "IT and security teams have a unique opportunity to avoid contentious downstream debates by introducing construction guidelines now." The objective is to provide every team—technical or otherwise—with a secure, governed environment for building from the outset. This principle underpins Tines 3B, an AI-native platform designed to bring wild code into the open without slowing development velocity.