Shadow AI complicates enterprise digital defense

The inadvertent practice of Shadow AI within companies creates security gaps and demands strengthening digital defense through effective policies and controls.
The inadvertent practice of Shadow AI within companies creates security gaps and demands strengthening digital defense through effective policies and controls.

 


The use of generative artificial intelligence (GenAI) in the corporate environment is no longer a promise of the future—it is a rapidly expanding reality. However, its widespread adoption is generating new cybersecurity threats.

This is the warning highlighted in The State of Generative AI 2025 report, published by Unit 42, the threat intelligence team at Palo Alto Networks.

According to the study, which analyzed data from over 7,000 organizations worldwide, GenAI-related traffic increased by more than 890% in 2024.

This surge has had consequences: so far in 2025, data loss incidents linked to these technologies have multiplied by 2.5 and now account for 14% of security incidents on SaaS platforms such as email, storage, and cloud collaboration.

Growing Adoption in Colombia.

Colombia is not immune to this trend. Local organizations are actively adopting these digital tools. In terms of transaction volume, the most widely used are Grammarly (43.41%) and Google Workspace (29.98%).

By data volume, Microsoft 365 Copilot leads with 55.53%, followed by Grammarly (21.76%) and Microsoft Power Apps (11.58%).

According to Germán Rincón, Country Manager of Palo Alto Networks Colombia:

“The use of GenAI tools without IT department oversight—known as ‘Shadow AI’—poses a new challenge for organizations. In Colombia, where these technologies have been gradually adopted over time, it is crucial to establish clear usage policies and control mechanisms to leverage their benefits without compromising security.”

Unsupervised use of these tools may seem harmless—such as drafting an email, consulting a chatbot, or generating code using free platforms.

However, if these activities occur without proper controls, they can lead to exposure of sensitive information, regulatory breaches, and even loss of intellectual property.

AI Control and Security.

To address this landscape, Palo Alto Networks proposes a security approach that enables organizations to govern third-party GenAI usage.

With its AI Access Security technology, companies can identify in real time which tools are in use, enforce controls based on risk level, and prevent data leaks without hindering productivity. The report recommends a comprehensive security strategy based on multiple layers of protection.

These include the use of conditional access controls that restrict GenAI use according to user profile, device type, or tool risk.

For example, a legal department employee might have limited access to prevent confidential documents from being processed by unauthorized services.

Another key measure is real-time content inspection.

This feature enables blocking sensitive data—such as financial information, intellectual property, or personal data—before it is transmitted to external platforms. This is especially critical in high-data-flow SaaS environments.

Prevention and Training.

The strategy also incorporates the Zero Trust model, which assumes no interaction is inherently safe. This allows detection of hidden threats, such as malicious links or manipulated instructions embedded within AI-generated responses.

Finally, the report highlights the importance of continuous staff training. Having advanced technology alone is insufficient: users must understand the risks and be prepared to use these tools responsibly and securely.

With increasing digitalization in sectors like healthcare, education, manufacturing, and financial services, Colombia is establishing itself as a strategic market for the secure adoption of GenAI.

Unit 42 emphasizes that with the right strategy, incidents can be prevented before they occur. Therefore, Palo Alto Networks urges organizations not to let the pace of innovation outstrip their capacity for protection.


Share:
Hosting Web
Most Read