Shadow AI, Cloud Sprawl, and the New Supply Chain Reality.

  March 6, 2026, AI

There seems to be no holding back AI with companies and employees adopting it faster than they can fully understand it. While the productivity payoff might be worth it, the pace creates visibility gaps where AI use appears outside governance (if there is any), aka shadow AI. Many security teams report growing blind spots as AI traffic increases and traditional tools struggle to keep up; a pattern repeatedly highlighted in recent industry analyses of hybrid environments.

The Australian Signals Directorate (ASD) has warned that AI/ML systems introduce new supply‑chain vulnerabilities like hidden dependencies, new attack paths, and data flowing into unknown third‑party AI providers embedded in your AI stack. With the rapid rise of agentic AI systems (AI capable of taking actions, calling tools, and self‑initiating workflows) and the adoption of Model Context Protocols (MCPs) to connect AI agents to internal tools, the supply‑chain footprint has expanded dramatically.

In other words, AI risk is now agent‑risk, integration‑risk, and supply‑chain risk, and visibility across that chain matters more than ever.

 

Stephen has seen IT and cybersecurity from every angle: corporate, integrator, and vendor so he’s seen the good and the bad across the industry. Today, he helps organisations lock down their data across cloud and AI.

Shadow AI doesn’t appear in one place; it appears everywhere through different touch points including users, workloads, developers, and machine-to-machine AI agents. Below is a practical, vendor‑neutral way to think about it.

1) When users adopt AI tools directly

Employees are often encouraged to use sanctioned tools like Copilot, but that doesn’t stop many of them also experimenting with unsanctioned (or shadow AI) generative AI tools. And now the emergence of agentic browser assistants (local copilots, automation agents, MCP-enabled plugins) that can automatically perform more complex tasks is complicating the environment even further.

This means the “user” isn’t always the initiator — agentic tools act on their behalf, often invisibly.

The right control point here remains the access layer:  SASE/secure web gateways can identify AI tools in use and prevent sensitive data being sent to unvetted providers. Many platforms now include:

  • AI‑application risk scoring
  • detection of agentic browser assistants
  • visibility into MCP‑enabled browser extensions
  • real‑time coaching (inline prompts nudging safer behaviour)

Additionally, email protection can be used to intercept the emails that get sent for application sign up when they are not using SSO.  By intercepting those authorisation confirmation emails, signups can be blocked, or approved once a valid justification and risk analysis has been performed

The goal isn’t to kill innovation; it’s to keep usage visible and guided. Thought‑leadership from the Cloud Security Alliance continues to emphasise AI asset inventories and continuous monitoring, something modern SASE solutions now extend to agentic user tools.

 

2) When developers integrate AI behind the scenes

A rapidly growing area of shadow AI comes from developers integrating to:

  • AI APIs and 3rd party models
  • agentic frameworks (LangChain-style, AutoGen, guidance frameworks)
  • MCP clients that allow AI agents to call internal tools automatically

This is where ASD’s concerns hit hardest: AI components can introduce poisoned datasets, malicious upstream libraries, compromised container images, or backdoored agentic toolchains.

A practical example is a developer adding an MCP-enabled function so an AI agent can query an internal database or trigger a workflow.  The objective was legit but now an unvetted third‑party agent can indirectly perform actions or access data deep inside the environment.

This behaviour bypasses endpoints and gateways because it originates from the application itself, not the user.

What works here:
  • Cloud Detection & Response (CDR) to surface unexpected outbound AI calls, agentic orchestration behaviours, or unapproved model downloads
  • Workload‑level telemetry and dependency mapping to expose: agentic frameworks hidden inside dependencies MCP toolchains pulled in through libraries nested model or dataset pulls
  • Detection for agentic behaviour patterns, e.g.: autonomous retries hidden tool invocation sequential planning loops background API calls

This aligns tightly with industry guidance on detecting shadow AI in software supply chains. [datadoghq.com]

 

3) When cloud workloads call AI services

In hybrid cloud, the most dangerous shadow AI isn’t user or developer‑initiated, it’s workload‑driven, usually via:

  • background agentic orchestration
  • serverless functions calling AI autonomously
  • containers pulling models or agent tools
  • libraries invoking MCP‑exposed endpoints
  • third‑party SaaS making chained AI calls

These calls often originate inside the workload, bypassing browser‑based controls entirely.

ASD notes that modern AI ecosystems include interdependent models, toolchains, and cloud infrastructure, creating multiple hidden vulnerability points. The agentic layer amplifies this: an AI agent might call one MCP endpoint, which calls another tool, which sends data to a cloud service in a way that may inadvertently go around DLP controls.

What works here:
  • Microsegmentation, enforcing that workloads only talk to explicitly approved AI endpoints
  • Flow mapping, revealing: MCP‑triggered tool calls unexpected AI inference requests east‑west agentic traffic autonomous outbound connections

 

4) Why a holistic approach is essential (especially with agentic systems)

Shadow AI can enter through browsers, libraries, agentic orchestrators, cloud workloads, SaaS and 3rd party AI Providers – that’s a huge potential attack surface.  And Agentic AI introduces action, not just inference. MCP introduces toolchains that expose internal interfaces to AI. Both expand the attack surface even further. No single control covers all of this, which is why ASD positions AI risk as a form of supply‑chain risk across the entire environment.

A layered strategy to approach this complex and wide attack surface therefore looks like this:

  • SASE & access‑layer controls → user tools + agentic browser assistants
  • CDR & telemetry → developer/API-level integrations + agentic frameworks + MCP usage
  • Microsegmentation & flow mapping → workload‑level AI calls + agentic/inference behaviour

 

5) The missing piece: a formal, risk‑based AI policy

But technology alone doesn’t solve shadow AI and as with the wider Cyber challenges, people are critical.  Hence, organisations need policy that explicitly governs:

  • which AI, agentic, and MCP-enabled tools are allowed and what systems can be integrated through MCP endpoints
  • what data can be processed by AI agents
  • guardrails for tool invocation (what AI agents can and cannot execute)
  • review requirements for third‑party agentic providers, and regularly audit
  • escalation paths for suspicious or unknown AI behaviour

A robust AI policy ensures:

  • SASE controls map to approved AI & agentic tools
  • CDR detections align with documented developer expectations
  • Micro-segmentation reflects allowable communication flows and contains breaches
  • Risk decisions remain consistent and defensible

Without policy, agentic systems can operate unpredictably — and invisibly.

 

6) Bringing it all together: end‑to‑end visibility, detection & response

As they say, it takes a village, and there is no single way to gain visibility and protect your AI supply chain.  It’s a risk-based decision to determine the path forward, but at an end-to-end level, integrating SASE insights with CDR telemetry and micro-segmentation data gives you something few organisations have today: visibility of how AI and agentic systems move through your environment, from endpoint → workload → internal toolchain → third‑party AI provider.

Accelerate your Cyber Defence today.

Whether you’re curious about the latest in cyber security, or you just want to know more about what we do – we’re all ears and ready to chat.