Cloud shattered the perimeter. Non-human identities quietly became the majority in most enterprises. And then AI turbocharged the attacker side.
That three-beat sequence is the cleanest summary of why AI security has become a defining problem for enterprise security teams. Not because AI introduced a new category of threat, but because it accelerated every structural vulnerability that already existed and outran the governance tools designed to manage them.
The gap isn't theoretical. It's already in your environment. Your employees are using it right now.
Stephen Harrison, Abnormal AI’s VP of Product and a former CISO, puts it plainly: workers follow the path of least resistance. When an employee needs to convert a spreadsheet, transcribe a call, summarize a document, or draft a proposal faster, they find a tool. They try it. They grant whatever OAuth permission it asks for. And when it doesn't work, they close the tab and try something else, leaving a trail of abandoned entitlements, forgotten tokens, and shadow credentials that the security team has no visibility into.
"Workers are like lightning—they follow the path of least resistance. And this is how sprawl occurs. If you want to discover this, you need to do it in a behavioral way."
— Stephen Harrison, VP Product, Abnormal AI
Harrison describes the scale of this plainly: "People are signing up for random AI tools and grabbing products they think will help them get their job done faster. That sort of wide sprawl—tool, trial and error, trying to find out who's going to win out—creates a large landscape of risk." Most of this never gets reported to IT or security. Users don't think they've done anything wrong. They're just trying to get things done.
The shadow AI problem is a governance and visibility failure. But it's also an attack surface—one that adversaries have already figured out how to exploit.
Harrison maps the malvertising attack chain in detail: an attacker identifies the AI tools knowledge workers are actively searching for, buys ad placement against those searches, and sets up a lookalike that delivers an OAuth grant rather than a product. "I'm going to build a lightning rod, not try to capture lightning in a bottle," he says. "I want to attract knowledge workers." The employee clicks what looks like a product ad, signs up for a trial, grants access. The attacker now has an OAuth entitlement into that employee's environment.
7 in 10 employees already use AI tools at work; fewer than 2 in 10 companies have written a policy for them. (ISACA)
From there, the path leads directly to the organization's internal AI infrastructure. "Once you get in, you go right to your internal AI knowledge base and figure out how the company works." Every enterprise knowledge base, every agent with standing permissions, every automated workflow becomes reachable from what looked like a product trial.
Mick Leach, Abnormal AI’s Field CISO, has watched a version of this play out at scale with Microsoft Copilot. When Copilot rolled out broadly, it surfaced a problem that had been hiding in plain sight: over-privileged access that users didn't know they had. "If somebody had access to a document but didn't know it, they would never access it—they just wouldn't think to look. Once Copilot rolled out, if you asked the right question, it would go and find you the answer—with access you may have had but didn't know about."
The tool didn't create the vulnerability. It made the existing one impossible to ignore.
