Shadow artificial intelligence (AI) is emerging as one of the fastest-growing cybersecurity threats as employees increasingly use unauthorised generative AI tools outside the oversight of corporate IT departments, exposing sensitive corporate information to public AI models and expanding the attack surface for cybercriminals, according to cybersecurity firm Kaspersky.
Shadow AI refers to unauthorised use of AI tools, models or features by employees in organisations without the approval by oversight teams.
In response, Kaspersky is set to launch AI Protect platform, designed to help organisations govern AI adoption and reduce emerging risks.
The company identified Thailand as its next strategic growth market in Southeast Asia as enterprise AI adoption accelerates.
"Organisations are increasingly adopting cloud-based AI services without the formal approval of chief information officers or IT teams, effectively creating a parallel technology environment outside corporate governance," said Andrian Hia, managing director for Asia-Pacific at Kaspersky, during the company's annual Cyber Security Weekend event.
Employees routinely upload financial records, proprietary source code and confidential business documents into public AI platforms, increasing the risk of data leakage and loss of control over sensitive corporate information, he said.
Cyberthreats are becoming AI-native while cybersecurity is evolving into an AI-powered discipline, ushering in a new era of digital defence, noted Mr Hia.
Kaspersky detected and blocked more than 500,000 unique malicious files daily last year, up 7% from 2024, reflecting the growing scale of cyberthreats.
"This year, Kaspersky has identified more than 15,000 malware samples disguised as agentic AI software," he said.
As AI agents increasingly rely on third-party frameworks, application programming interface, and plug-ins, a single compromised component can spread across downstream systems, significantly increasing the risks of cyber sabotage and cyber espionage.
The rapid adoption of AI is reshaping the threat landscape. While enterprises use AI to improve productivity, cybercriminals are exploiting the technology to automate attacks, accelerate malware development and identify vulnerabilities faster than ever.
Critical infrastructure, internet-connected devices and software supply chains have become prime targets.
"The shift from human-centric to machine-centric operations means cybercriminals are making attacks faster, more sophisticated and increasingly automated," Mr Hia said. Rather than treating AI solely as a new source of risk, organisations must also use AI as a core defensive capability.
NEW PLATFORM
According to Kaspersky, its AI Protect platform can scan AI agents and open-source AI components before deployment to detect malware, Trojan horses, backdoors and software vulnerabilities, preventing compromised AI tools from entering enterprise environments.
The platform also provides visibility into unauthorised AI usage and helps prevent sensitive corporate information from leaking into public AI platforms.
"Addressing shadow AI is no longer just about blocking unauthorised tools. Organisations need complete visibility into how employees interact with both public and private AI environments and how corporate data flows across them," he said.
The launch of the platform reflects a broader shift in enterprise cybersecurity as organisations move beyond traditional endpoint protection towards integrated platforms covering applications, software development, cloud infrastructure, operational technology (OT) and AI environments.
Kaspersky is also promoting its Open Single Management Platform, which consolidates protection across IT infrastructure, cloud environments, OT, Internet of Things devices, mobile endpoints and data centres through a single management console.
Kaspersky's enterprise business grew 60% in the latest financial year, driven by demand for managed detection and response, threat intelligence, extended detection and response and OT security.
Following investments in Vietnam and Indonesia, Thailand has been identified as Kaspersky's next strategic investment market in Southeast Asia.
Kaspersky is scheduled to host the OT Summit in Bangkok later this month, reflecting its expectation that industrial cybersecurity will become the company's next growth engine in Thailand.
The company is expanding deployment of Kaspersky Industrial CyberSecurity platform, designed to protect industrial control systems without disrupting critical operations.
Mr Hia said securing OT environments is far more critical than protecting conventional IT systems because attacks on critical infrastructure can disrupt electricity, water supply, telecom, transport networks and airports.
Without continuous monitoring and threat detection, attackers gain valuable time to infiltrate networks, move laterally, and compromise critical assets, he said.
A modern security operations centre has become business-critical because it provides the visibility, expertise and operational discipline needed to detect threats before they become major incidents, Mr Hia said.
As cybercriminals increasingly use AI to automate attacks, defenders must do the same. Kaspersky has embedded AI into its security platform for more than two decades, combining machine learning with human expertise through what it calls HuMachine Intelligence.
"The future of cybersecurity is about securing every connected device, every AI application and every critical system that powers modern businesses," he said.