Employees are quietly feeding company data into AI tools every day — not to cause harm, but to work faster. Rubrik warns this everyday convenience is opening a data risk surface that most enterprises cannot yet see, let alone govern.
Shadow IT was a known problem: an unsanctioned app or device operating outside the visibility of IT teams, with exposure typically limited to that single tool. Shadow AI, according to Ananth Nag, General Manager and Vice President, Asia Pacific at Rubrik, is a different category of risk entirely.
“Employees are now actively feeding business information into AI systems that can process, store, and learn from that data,” said Nag. “Unlike traditional shadow IT, shadow AI can rapidly move sensitive information across multiple AI tools and third-party models with little visibility on where the data goes or how it is used.”
When AI agents start acting on their own
The risk compounds further with agentic AI, where systems do not just process data but act on it — retrieving information and executing tasks autonomously across connected business systems. Nag said this shifts the security challenge from simply blocking unauthorised tools to maintaining visibility, governance, and recoverability across AI systems that touch sensitive data directly.
Left unchecked, organisations lose track of what data their AI agents can reach, where that data ends up, and whether any controls are actually in place once it leaves.
It’s not malicious — that’s the problem
What makes shadow AI difficult to police is that it rarely looks like misconduct. Employees typically expose the data they already have legitimate access to — emails, internal documents, workplace chats — by feeding it into AI tools to summarise notes, draft content, or speed up analysis.
“Employees are often trying to work more efficiently rather than bypassing security policies,” Nag said.
That distinction matters. It means the fix isn’t punitive; it’s structural — giving employees legitimate, secure alternatives so the underlying productivity need doesn’t push them toward riskier workarounds.
Why traditional DLP falls short
Most Data Loss Prevention (DLP) frameworks were designed for an era when data movement followed predictable patterns. Shadow AI breaks that assumption. Nag said the speed and invisibility of AI-driven data movement means conventional DLP, on its own, is no longer sufficient.
“Organizations cannot govern what they cannot see,” said Nag.
Rubrik’s recommendation is to treat visibility as the prerequisite, not the afterthought: classify sensitive data, map which AI tools and models can access it, and — critically — test whether a clean copy of that data can actually be recovered if something goes wrong.
Three priorities for APAC organisations
For enterprises across Asia Pacific, where regulatory environments vary sharply from market to market, Nag outlined three areas of focus:
- Data visibility: Security teams need a clear map of where sensitive data sits across AI tools, cloud environments, and on-premise systems — and should actively hunt for unmanaged AI use rather than assume it isn’t happening.
- Secure AI pathways: Outright bans tend to push AI use further underground rather than eliminate it. Nag argues organisations should instead offer sanctioned tools, clear usage policies, and practical guidance on what data is safe to use.
- Recovery readiness: Because AI can accelerate both legitimate work and potential attacks, exposure can now happen at machine speed. Nag recommends organisations test recovery plans in peacetime, define clean recovery points, and regularly prove critical services can be restored within a set timeframe.
Bringing shadow AI out of the shadows
The uncomfortable conclusion, in Nag’s view, is that stopping employees from using AI altogether is not a realistic strategy. The more useful question for security leaders isn’t whether shadow AI is happening inside their organisation — it almost certainly is — but whether they would know if it went wrong, and whether they could recover from it.
“It is unrealistic to stop employees from using AI,” Nag said. “What organisations can do is bring Shadow AI out of the shadows before it becomes a data exposure and resilience problem.”



Share your thoughts