Tag: Information Security

  • Shadow AI grows in the gap Gallup just measured

    Shadow AI grows in the gap Gallup just measured

    Table of contents

    Ask a US employee whether their own employer has rolled out AI. A decent share of them cannot answer, and shadow AI grows in exactly that kind of confusion.

    Gallup changed the question because of it. The methodology note says, “Starting in Q3 2025, Gallup added a ‘don’t know’ option to this question to capture uncertainty about AI adoption.” Results from Q3 2025 onward are no longer directly comparable with earlier measurements.

    A polling company broke its own time series because too many people had no idea what was happening inside the building they work in.

    The second number nobody quotes

    As of May 2026, 47% of US employees say their organization has implemented AI. Only 25% say the organization communicated a clear plan.

    Every headline takes the first number, but the second one is the story.

    Between “we have this thing” and “somebody told me how to use it” sits a gap, and in that gap are contracts, patient records, draft tenders, source code, whatever your people happen to be pasting today.

    Shadow AI is the default state of that gap.

    shadow AI

    Adoption is the wrong argument

    There is a long running fight about how many people use AI. Gabriel Weinberg of DuckDuckGo summed up the skeptical side in June 2026 as “one third actively using AI, one third occasionally using AI, and one third never using AI”. He cites Microsoft telemetry putting it at “more than 30 percent of the US working-age population is using AI, an increase of 3 percentage points from the end of 2025”.

    Gallup’s workplace numbers run higher. 15% of US employees use AI daily. Weekly or more is 30%, and 52% touch it at least a few times a year.

    Pick whichever camp you like, it changes nothing for my job.

    Move the user base up or down, the 25% who got a clear plan stays where it is. That fight pulls attention away from the only question that matters, which is who wrote the rulebook and who read it.

    Shadow AI is a confidentiality problem with no attacker

    Strip the vocabulary and that is all this is.

    No phishing mail, no exploit, no command and control, nothing that trips an alert. An employee opens a browser tab and pastes a client document into a chatbot to get a summary. The data leaves the organization. Most of what you bought assumes somebody is trying to break in. Shadow AI walks out the front door during working hours, moved by people who just want to finish faster.

    OWASP keeps an entry for sensitive information disclosure in its Top 10 for Large Language Model Applications, and almost all of that guidance assumes an application you built. The tab your sales team opened this morning is nobody’s application.

    Scott Brinker named the shape of this back in 2013 and called it Martec’s law. Technology changes exponentially, organizations change logarithmically. Your staff adopted AI in an afternoon, your document set moves at the speed of a committee.

    The Gallup manager numbers show the same thing from the other side. 36% strongly agree their manager supports the team using AI. Where that support exists, employees are 1.7x more likely to use AI weekly or more and 8.7x more likely to report a transformational change in how they work. Encouragement travels by conversation and rules travel by document. Shadow AI takes the faster route.

    What shadow AI looks like on a Tuesday

    Nobody sits down and decides to run shadow AI. It shows up as small, reasonable moves.

    A sales rep pastes a signed contract into a chatbot to pull the renewal dates out of it. An HR assistant drops a salary spreadsheet into a chatbot to reformat the columns. A developer sends a stack trace holding a production connection string to a free tier account. A clinic receptionist rewrites a referral letter with the patient name still in it.

    None of those people are careless. All of them were told AI makes them faster, and none of them were told where the line sits.

    Deleting the client name before pasting does not turn the text into anonymous data either, and I went through the research on that in ChatGPT privacy leak.

    Every one of those actions is invisible to the security team, because nothing was breached and nothing alerted.

    Low numbers are not safe numbers

    Daily use runs at 42% in technology, 27% in finance, 22% in professional services, and 9 to 15% everywhere else.

    Read the low end carefully, because a law firm or a clinic sitting in that bottom band is not in a better position. It is a place where a smaller group does the same thing with far more sensitive material, and with less chance that anyone in IT has ever looked at it. Low usage hides shadow AI.

    The 65% of employees in AI-implementing organizations who report a positive effect on productivity are not lying either. It works, and that is exactly why nobody is going to stop when you ask them to. A ban moves shadow AI further out of sight.

    One page before you buy anything

    Do not start with a tool. Start with one page that answers four things.

    1. Which categories of data never go into an external model.
    2. Which tools are approved, listed by name.
    3. Who an employee asks when the answer is not obvious.
    4. What happens when something has already gone in, and who hears about it first.

    That page will not cover a regulated environment or replace a contract with the vendor. It covers what is leaking today.

    I keep the editable template for it behind my shadow AI risk calculator, so you do not have to start from a blank file.

    Then do the boring part and send it to everyone, with one person named as the owner. A rule nobody can find works the same as no rule at all, and that is where shadow AI restarts. It is not fancy work and it does not need a consultant.

    One page beats a procurement cycle. If you cannot write it, you do not have an AI program, you have 47% and hope.

    So remember, if you write only one line on that page, write this one. Never put anything into an LLM that you would not email to a stranger.

    Source: https://www.gallup.com/699797/indicator-artificial-intelligence.aspx


    Want More? Subscribe to The Dossier

    Every week in your inbox:

    📡 THE INTELLIGENCE FEED – 3-5 curated links: [Research] [Policy] [Tools] [Incidents]
    💡 ONE ADVICE – One actionable AI/cybersecurity tip you can use today

  • 272 experts built an AI risk ranking. Cybersecurity made the top five.

    272 experts built an AI risk ranking. Cybersecurity made the top five.

    Table of contents

    Two hundred seventy-two international AI experts just built an AI risk ranking based on probability instead of guesswork. Most regulators still haven’t managed that in three years.

    The study, “Prioritization of Risks From Artificial Intelligence,” comes from MIT FutureTech and the University of Queensland. The paper lists 188 co-authors. Core authorship goes to Peter Slattery, Alexander Saeri, Jess Graham, Michael Noetel and Neil Thompson. They used the Delphi method, a research process that gathers expert judgment over multiple rounds until agreement and disagreement both become visible. The same method shows up in the International AI Safety Report 2026, which cites this same body of work. The underlying data lives in the MIT AI Risk Repository, a running catalog of more than 1,600 documented threats used by policymakers and technologists.

    Experts scored 24 risk domains across a five-year horizon, 2025 to 2030, under two scenarios. One scenario assumed business as usual, where organizations and governments keep doing what they’re doing now. The other assumed pragmatic mitigation, where everyone makes cost-effective efforts to reduce harm. Under business as usual, 18 of the 24 domains had at least a 10% probability of catastrophic outcomes. Catastrophic meant more than a million deaths or more than $100 billion in losses, with damage at a comparable civilizational scale in either case. That’s the baseline nobody wanted written down until now. It’s a sharper, numbers-first cut at the risk spectrum this blog already maps.

    Why most people are reading this wrong

    Most people hear “AI risk” and picture something years out, like rogue models or autonomous weapons in some future conflict. That’s not what this AI risk ranking found. Even under pragmatic mitigation, five domains still cleared 10% probability of catastrophe. Dangerous capabilities and AI-enabled weapons or cyberattacks each sat at 12%. So did environmental harm, a domain most people wouldn’t put anywhere near cybersecurity. Inequality and unemployment came in a point lower at 11%, right alongside power centralization. Two of the five are cybersecurity’s problem, and they didn’t drop much even when everyone tries.

    AI risk ranking

    Security work comes down to one job, pushing the attacker’s cost high enough that the attack isn’t worth it anymore. No system stays secure forever, so the alternative just needs to be expensive enough to matter. AI doesn’t invent a new phase of attack. It collapses the cost of the phases that already exist. Reconnaissance gets automated.

    Weaponization gets templated, and delivery gets more convincing because a generated phishing email or a cloned voice doesn’t need a skilled operator anymore. It’s the same mechanism behind the AI-enabled cyberattacks already hitting ordinary companies today. As Slattery putand hacking are where AI capability is moving quickest, and that growth shows up on the cost side of the equation more than the probability side.

    Competitive pressure works as the mechanism that keeps the other four risks running. When a company or a country believes AI confers an advantage, slowing down for safety just hands that advantage to whoever doesn’t slow down. Nobody wants to be the one who raises their own costs while the competition doesn’t, so the race to the bottom on governance keeps going. It’s the same dynamic that keeps patch cycles too slow and security budgets too small, just running at AI speed instead of IT speed.

    Treating this AI risk ranking as a one-time compliance project misreads what the data says. It isn’t something you finish once and file away.

    What this means if you’re the one holding the risk

    The study also names who’s exposed and who’s responsible, and the two lists don’t overlap. Developers and regulators carry most of the responsibility for addressing these risks. Users and the people affected by AI systems carry most of the exposure. That mismatch is why nobody feels urgency at the right level. The people who could slow the collapse aren’t the ones who’d get hurt by it.

    Exposure doesn’t spread evenly. Information absorbs it through misinformation and manipulation, the sort that erodes trust in what people see and read, while national security picks up cyberattacks and weapons development, with surveillance going to whichever hostile actor moves first. Finance isn’t spared either, where fraud and market manipulation get easier and privacy failures ripple into the wider economy on top of that. AI makes doing harm cheaper for anyone who was already capable of it, and possible for people who weren’t.

    Slattery framed the findings as a list of what’s worth paying attention to now, drawn from probability rather than certainty. The response belongs in the governance conversation companies already run for cybersecurity and privacy. It needs a place in business continuity planning too, not a separate checkbox with its own deadline.

    If you run security for an organization deploying AI, the number that should stick with you about AI risk isn’t 272 experts or 24 categories. It’s that even in the best-case scenario the researchers modeled, cyberattacks and dangerous capabilities didn’t fall out of the top five. Mitigation lowers the odds. It doesn’t remove cybersecurity from the list.

    Source: https://mitsloan.mit.edu/ideas-made-to-matter/these-are-most-urgent-ai-risks-according-to-272-experts


    Want More? Subscribe to The Dossier

    Every week in your inbox:

    📡 THE INTELLIGENCE FEED – 3-5 curated links: [Research] [Policy] [Tools] [Incidents]
    💡 ONE ADVICE – One actionable AI/cybersecurity tip you can use today

  • Cyberattacks in 2026: How Algorithms Made Life Easier for Hackers

    Table of contents

    We are currently facing a situation where cyberattacks in 2026 have completely shifted the balance of power, and the barrier to entry for digital crime has essentially ceased to exist. In the past, we worried about organized groups of hackers with deep technical knowledge. Today, anyone with internet access and the right prompt can cause multi-million dollar damage. It is the fact that you simply can no longer trust what you see and hear on your monitor screen.

    Automated Breaches and Cyberattacks in 2026

    Writing a convincing phishing email used to require at least a little effort from a scammer, a dozen hours of work. Today, language models generate a targeted attack in five minutes. When analyzing cyberattacks in 2026, we clearly see that already 1 in 6 security breach incidents directly involves generative tools. The quality of these messages is so good that they smoothly bypass traditional anti-spam filters.

    Add to this the problem on the side of the employees themselves, who paste company code and client data into external chatbots to make their work easier. Just one naive query about optimizing a script is enough to hand over intellectual property into the wrong hands.

    cyberattacks in 2026

    The Arup Case and CEO Fraud

    The break-in at the engineering firm Arup shows how brutal cyberattacks in 2026 can be in the corporate sector. They lost 25.6 million dollars because an employee believed what he saw and heard. Scammers generated live images of the Chief Financial Officer and several managers during a video conference. The employee succumbed to group pressure and simply transferred 200 million Hong Kong dollars to the criminals’ accounts.

    What is most terrifying is how little information the perpetrators needed. A few public recordings from the company’s LinkedIn profile were enough. Your smile on a promotional recording is today a free weapon for an attacker.

    To Pay or Not to Pay? Defensive Strategies

    I always remind about what happened with MGM Resorts and Caesars Entertainment. Two companies and two completely different approaches to a crisis.

    MGM refused to pay the ransom. The result was painful. Systems stopped, and the company recorded a 100 million dollar loss in the short term. But the markets appreciated the transparency, their stock grew by 8.41%. On the other hand, Caesars quietly paid a 15 million dollar ransom. They avoided media downtime, but they did not block the leak of their customers’ loyalty program data. Personally, I will always defend MGM’s approach, because cyberattacks in 2026 finance themselves precisely from the submission of victims.

    When the Entire Medical Industry Stops

    The attack on Change Healthcare paralyzed the processing of insurance payments across the entire United States. Estimated losses ranged from one billion to over 2.45 billion dollars.

    The incident affected 94% of American hospitals. Imagine a situation where 55% of doctors take out loans against their homes just to pay nurses’ salaries. Systems were being restored to full functionality for nearly six months. This proves that cyberattacks in 2026 deliberately target critical infrastructure to cause maximum paralysis.

    Mistakes That Cannot Be Undone

    You can reset a password. You cannot reset a genetic code. After the breach into 23andMe and the leak of sensitive genetic data of 6.9 million people, the company simply filed for bankruptcy and was sold for 305 million USD. As it was accurately put after the incident itself, DNA is not a password.

    Another problem is ignoring the basics. 109 million records leaked from AT&T. The problem lay with the company, which did not enforce multifactor authentication. Ultimately, it cost them 177 million dollars in court settlements. Over in Europe, the Dutch operator Odido recently admitted to a data leak affecting 6.2 million people. Seeing these statistics, we understand that cyberattacks in 2026 rely mainly on human laziness.

    What Actually Works Against Network Threats

    The average cost of a data breach in the US has already exceeded a record 10.22 million dollars. Ignoring the use of public AI by employees adds another 670 thousand USD per incident to this bill. On the other hand, companies that invest in defense lose noticeably less—an average of 1.9 million dollars.

    Instead of producing more vague procedures, I require companies to implement four specific steps to block cyberattacks in 2026:

    • Complete resignation from SMS-based logins in favor of hardware FIDO2 security keys. You buy a hardware key for 50 dollars for each employee and cut off 99% of vectors based on standard phishing.
    • Blocking network traffic that prevents employees from pasting code into public chatbots.
    • An absolute requirement for two-channel verification for every transfer over 10 thousand dollars. If a director asks for an urgent transfer on video, the accountant must pick up the phone and call his private mobile number.
    • Reviewing and adjusting cyber insurance policies to include frauds based on deepfake technology.

    We have stopped living in a world where you can trust anyone’s word. If you do not verify something physically, assume there is no human on the other side.


    Want More? Subscribe to The Dossier

    Every week in your inbox:

    📡 THE INTELLIGENCE FEED – 3-5 curated links: [Research] [Policy] [Tools] [Incidents]
    💡 ONE ADVICE – One actionable AI/cybersecurity tip you can use today


    FAQ

    What are the cyber threats in 2026?

    In 2026, the primary threats are AI-generated deepfake frauds targeting executives and automated phishing campaigns that easily bypass standard filters. Criminals also heavily exploit “shadow AI,” where employees accidentally leak corporate data into public language models.

    Have cyberattacks increased in 2025?

    Yes, attacks surged significantly, pushing the average data breach cost in the US to a record $10.22 million per incident in 2025. Generative AI allowed criminals to multiply their strike force, with one in six breaches directly involving AI tools.

    What are the top 10 security threats?

    The top threats include AI-generated phishing, deepfake CEO fraud, critical infrastructure ransomware, shadow AI data leaks, and cloud misconfigurations lacking hardware MFA. Rounding out the list are SMS-login exploits, biometric data theft, third-party vendor breaches, unpatched software vulnerabilities, and insider threats.