Illumio is a Customers’ Choice in the 2026 Gartner Peer Insights for Network Security Microsegmentation.

Shadow AI Opens a Huge Can of Worms. Zero Trust Is the Lid.

Raghu Nandakumara
VP, Industry Strategy

Ask expert security advisor Dr. Anton Chuvakin what AI has done to breach detection, and his metaphor is worrying. “It’s a bathtub of worms — a gallon drum of worms — not just a can of worms,” he said on the latest episode of The Segment podcast.

Anton has spent 20 years naming and mapping the detection and response category, so when he says the problem has outgrown our containers for it, it’s a big deal.

Anton advises CISOs at Google Cloud and spent years at Gartner watching each technology wave arrive ahead of its controls. Erik Bloch joined us on the episode and brought the practitioner’s view, having run security at Salesforce, Cisco, Atlassian, and now Illumio.  

Between the two, they made a case that detection only covers what you’ve inventoried, and shadow AI is precisely what you haven’t. Employees adopt tools faster than security governance can name them. When one causes a breach, the way in will be something basic like an open storage bucket or a hardcoded password.

Zero Trust matters for shadow AI because its foundational principles, including least-privilege access and microsegmentation, will automatically contain AI tools without anyone having to identify them first.

Your employees aren’t waiting around for AI security rules

Every security team I speak with is drafting AI usage guidelines. But employees haven’t waited for them to start using new AI tools.

“Everyone’s trying to throw spaghetti at the wall and see what sticks, and they’re applying AI to everything, giving everybody access to all the things," Erik said.

The tooling gap makes that harder to govern. “You can’t go buy an off-the-shelf product today that’s going to secure all your AI usage for the company,” he said. That’s why he believes teams should expect “the wild west for a minute.”

Erik’s point is that AI adoption happens with or without a strategy to secure it. The security policy to protect AI use gets written on one timeline, and the adoption happens on another. Shadow AI is the gap between them.

AI security risks are a blast from the past

Anton described four layers of AI adoption that need watching — model, application, infrastructure, and data — and warned that “people who over-pivot to securing one layer typically pay the consequences.”  

Teams fixated on adversarial testing leave storage buckets open, while teams hardening infrastructure get hit through prompt injection.

His prediction? “Your AI tools will probably suffer from the types of attacks we saw in the 1990s or 2000s first before any kind of attacks on the model itself.” He said that AI apps are getting compromised through old-school SQL injection and hardcoded passwords more often than new attack patterns.

Anton believes that we already covered this ground with cloud risk, but we didn’t learn the lesson. “People are making all sorts of classic, basic mistakes with securing AI,” he said. “We learned these lessons with the cloud, but now it seems like we’ve unlearned them.”

In other words, the attack surface is new, but attackers’ way into it is old. Attackers are having success with the easy, tried-and-tested attack patterns we should already be prepared for.

Guardrails belong in the architecture

Most AI guardrails live in policy. But acceptable use documents, approved tool lists, and system prompts asking a model to behave all depend on cooperation. Unfortunately, an AI agent operating on borrowed credentials doesn’t consult your policy before it acts.

An agent that’s been granted broad access will use all of it. Its credentials look legitimate to everything watching, and it moves fast enough to leave no real window between a wrong turn and the consequence. Governance written for humans deciding in hours struggles to constrain software deciding in milliseconds.

Zero Trust is the security architecture that solves this problem, and microsegmentation is how the architecture gets enforced. When AI workloads can only reach what they’ve been explicitly permitted to reach, an unapproved tool carrying borrowed credentials runs out of room fast.

Microsegmentation extends Zero Trust’s least-privilege principle to the network itself. It doesn't care what a tool is called — it only controls what that tool can talk to. When attackers try to move laterally from a breached AI app, they find all the paths already closed.

The AI wave won’t wait for your security roadmap

Shadow AI is already inside your network. It arrives without approval or procurement, and every month spent maturing an AI security program is another month of employees connecting unapproved tools into systems holding critical data. Governance moves in quarters, while adoption moves in days.

That gap is why Zero Trust matters now.  

A Zero Trust architecture that includes least-privilege access and microsegmentation doesn't need to wait on an inventory, a policy, or a name for the tool to start securing your environment. They contain what you haven’t found yet.  

Zero Trust is the only AI security control keeping pace with the adoption curve.

So here’s a timely question for your team. If someone handed corporate credentials to an AI tool you’ve never heard of, what could it reach? With a Zero Trust security strategy, you don’t have to worry about the answer.

Zero Trust Resources

GUIDE

Zero Trust Segmentation for Dummies

Breaches are inevitable, but the damage isn’t. Zero Trust Segmentation for Dummies simplifies how to stop threats from spreading, protecting your organization before they cause harm.

Read now
REPORT

The Containment Gap

Most security teams trust their detection. They shouldn't. New research from a global survey of 700 IT and cybersecurity leaders reveals a massive gap between spotting threats and stopping them — with only 17% able to isolate a compromised asset in near real time.

Read now
REPORT

2025 Global Cloud Detection and Response Report

Discover how 1,150 global cybersecurity leaders are tackling alert fatigue, blind spots, and lateral movement in the hybrid multi-cloud.

Read now

Ready to learn more about breach containment?