TL;DR: Hidden data, shadow IT, and unmanaged AI use are creating security gaps that discovery tools alone cannot close, according to Safetica's analysis of how visibility, policy, and employee behaviour intersect across devices, cloud services, and third-party access. The practical issue is not finding data once, but sustaining control over where it flows, who can reach it, and which channels employees use by default.
NHIMG editorial — based on content published by Safetica: Effective data discovery, shadow IT, and visibility in the age of AI
By the numbers:
- The 2019 breach at Capital One resulted in 100 million stolen credit applications after a misconfigured AWS server exposed data.
- The 2019/2020 SolarWinds supply chain attack affected 18,000 organizations, including federal departments and multiple Fortune 500 companies.
Questions worth separating out
Q: How should security teams govern Shadow IT without slowing users down?
A: Start with visibility, not prohibition.
Q: Why do unmanaged devices create such a large data security gap?
A: Because the organisation cannot reliably enforce the same monitoring, configuration, and containment on devices it does not own.
Q: What do teams get wrong about fourth-party risk?
A: Teams often assume that if the direct vendor is approved, the access chain is controlled.
Practitioner guidance
- Define data-sharing boundaries for AI use Publish explicit rules for what data may be entered into chatbots, coding assistants, transcription tools, and embedded AI features.
- Apply conditional access to unmanaged devices Restrict access to sensitive systems when the session originates from personal or otherwise unmanaged endpoints.
- Review third-party entitlements on a lifecycle basis Inventory external integrations, support accounts, and delegated access paths, then remove access that no longer has a live business justification.
What's in the full article
Safetica's full article covers the operational detail this post intentionally leaves for the source:
- Examples of how DLP, virtual workspaces, and cloud-based controls are positioned for managed and unmanaged devices.
- The article's practical guidance on safe enablement, including how to build approved sandboxes for employee experimentation.
- The specific ways shadow IT and AI adoption change expectations for visibility, policy, and employee education.
- The author's discussion of third-party risk scenarios, including how visibility changes decisions about vendor access and privilege.
👉 Read Safetica's analysis of shadow IT, AI use, and data visibility gaps →
Data visibility gaps and shadow IT: are your controls keeping up?
Explore further
Hidden-data visibility is now a governance requirement, not a discovery feature. Discovery that does not extend across shadow IT, unmanaged AI use, and third-party channels leaves the organisation blind to where sensitive information actually lives. The control failure is not lack of tooling alone, but lack of policy enforcement across the full data path. Practitioners should treat visibility as a lifecycle control for data, access, and behaviour.
A question worth separating out:
Q: Who is accountable when shadow IT creates access risk?
A: Accountability sits with the teams that approved the business process, the owners of the unsanctioned tool, and the identity governance function that failed to detect the gap. If access was never inventoried, no one can prove it was properly governed. That makes ownership and evidence retention essential.
👉 Read our full editorial: Data visibility gaps now define shadow IT, AI use, and third-party risk