Site navigation

AI Visibility Crisis Fuelling Security Nightmare

Elizabeth Greenberg

,

SOC-as-a-Service
“AI has redrawn the enterprise attack surface overnight,” said Adam Arellano, Field CTO at Harness. 

As organisations race to embed AI into every product and workflow, most have lost sight of where and how those AI components are actually being used – creating a new class of security vulnerabilities that traditional tools were not built to secure.

This is what Harness, an AI DevOps Platform firm, describes as the AI visibility crisis.

According to The State of AI-Native Application Security 2025 report, 75% of security practitioners say shadow AI will eclipse the risks once caused by shadow IT, with the majority of organisations already reporting security incidents tied to the use of AI capabilities.

The findings highlight a deeper shift: shadow AI isn’t just a new risk category, it’s a symptom of lost visibility and control as AI-native applications rapidly multiply across organisations. Security teams are struggling to monitor their tool sprawl, and communication breakdowns between development and security teams exacerbate the problem even further.

AI’s Expanding Attack Surface

As enterprises rush to adopt AI, security teams are struggling to understand and govern what is being built.

Based on responses from 500 security practitioners and decision-makers across the US, UK, France, and Germany, the study revealed a sprawling security landscape as AI continues to proliferate.

Shadow AI is the new shadow IT, as 62% of those surveyed say they have no visibility into where LLMs are in use across their organisation.

AI sprawl is also outpacing control, with about three in four (74%) respondents saying AI sprawl will “blow API sprawl out of the water” when it comes to risk.

Beyond this, the threat landscape is evolving, as 82% of respondents believe AI-native applications are the new frontier for cyber-criminals, and 63% consider those apps more vulnerable than traditional IT applications.

AI-native apps appear to already be under attack, as enterprises have already experienced incidents involving LLM prompt injection (76%), vulnerable LLM code (66%), and LLM jailbreaking (65%).

Adding to the problem is a lack of responsibility – 62% of those surveyed say developers aren’t taking responsibility for security AI-native apps, and only 43% say developers build with security from the start.

“Shadow AI has become the new enterprise blind spot,” said Adam Arellano, Field CTO at Harness. “Traditional security tools were built for static code and predictable systems – not for adaptive, learning models that evolve daily. Security has to live across the entire software lifecycle – before, during, and after code – so teams can move fast without losing visibility or control.”

The AI Security Divide

While AI adoption continues to surge, with almost two-thirds (61%) of new enterprise applications now designed with AI components. The challenge is that most teams have not dedicated the time for security training or provided the oversight required to secure these apps effectively.

Developers say they don’t have the time (62%) to implement comprehensive AI-native security, while 62% say they lack the necessary expertise.

Two-thirds (75%) report that AI applications evolve faster than security can keep up, revealing a mismatch between speed and defence.

Further, collaboration breakdowns are widening the gap, with only 34% of developers notifying security before starting AI projects, and just 53% before going live.


Recommended reading


This could be all down to perception, as 74% of security leaders say developers view security as a blocker to AI innovation.

“AI has redrawn the enterprise attack surface overnight,” Arellano added. “Where teams once monitored code and APIs, they now must secure model behaviour, training data, and AI-generated connections. The only way forward is for security and development to operate as one – embedding governance directly into the software delivery process.”

Building AI Security Resilience

Without immediate visibility into where AI is being used – and by which teams – organisations face an accelerating cycle of risk. Untracked models, exposed APIs, and unsanctioned AI tools are becoming the new shadow infrastructure, making it nearly impossible to enforce policy or detect compromise.

To build AI-native security resilience, Harness recommends that enterprises:

  • Build security in from the start through shared governance between security and development.
  • Discover all new AI components as they appear and ensure they are monitored and logged.
  • Gain real-time visibility into AI components, APIs, and model outputs to detect anomalies early.
  • Dynamically test applications against AI-specific threats to identify security risks prior to production
  • Protect AI-native applications in production to reduce risk of sensitive data disclosure

Elizabeth Greenberg

Staff Writer

Latest News

Cybersecurity

Hackers Message Asos Users in Alleged Data Breach

Funding

Scottish BioTech MiAlgae Secures £2.5m for Grangemouth Expansion

Social Media

Ofcom Investigates Meta’s Instagram Instants Over Online Safety

AI Cybersecurity

Nearly 2/3s of UK Workers Have No Training on Spotting AI Cyber Threats