In March 2026, Meta experienced a significant data exposure incident when an approved internal AI agent posted sensitive company and user data to an unauthorized audience. This event highlights a growing governance problem: shady AI, where employees use approved AI tools in unapproved or unexpected ways.
Unlike shadow AI, which involves unsanctioned tools, shady AI occurs within the organization’s approved stack, making it harder to detect and control. A July 2026 SANS survey found that 76% of security teams now have a role in governing enterprise AI, yet traditional governance models struggle to keep pace with rapidly evolving AI capabilities.
Key drivers include the proliferation of approved AI tools, broad default permissions, and usage patterns that evolve faster than policies. Traditional controls like Acceptable Use Policies (AUPs) and one-time training cannot anticipate every AI use case, leading to workarounds and increased risk.
The article advocates for governance by default: embedding security controls, access management, and visibility into the environments where employees build and deploy AI-assisted workflows. This approach enables faster innovation while maintaining security oversight, transforming governance from a blocker into a strategic enabler.
The piece is sponsored by Tines, which offers Tines 3B, a platform designed to provide secure AI app and automation building with built-in governance.
Companies: Meta, Tines, SANS Institute
Products: Tines 3B
Original source: thehackernews.com