
Just now, somewhere in your company, someone pasted a customer contract into an AI tool to summarize it. They got their summary. They moved on.
You’re never getting that data back.
It’s sitting on a server you don’t own. It may be training a model you’ll never see. It may be one misconfiguration away from someone else’s screen. And no alert fired, because nothing was wrong. Your best, most productive employee just exfiltrated company data to save ten minutes.
No malware. No policy tripped. No trace.
That’s shadow AI. And the uncomfortable part is that it runs in two directions at once: your data leaking out, and AI-armed attackers pushing in. Same technology. Opposite threats. Both getting worse every week.
The leak that looks like work
The outbound direction doesn’t look like a breach. It looks like productivity. A developer drops a function into a code assistant to ask why it’s slow. An analyst feeds draft earnings into a model to tighten the wording. A consultant uploads a client deliverable to pull out a few bullet points. Every one of those is a one-way door. No undo, no recall, no “delete it on their end.” The data is gone the instant it lands.
Your controls were built for a different kind of exit. DLP watches outbound traffic, but the inspection point sits upstream of an encrypted session it can’t read. CASB only knows the vendors on its list. The network sees an HTTPS connection and shrugs. These are good tools. They were just never built for a person quietly pasting secrets into a browser tab.
It gets worse when the model never touches the network at all. Open-weights models are small enough to run on a laptop now, and plenty of people run them. A local model generates no suspicious traffic. It looks like a process reading files on disk. It can work through the exact regulated data your strictest controls exist to protect, and not one of them will fire, because nothing left the building. Good luck explaining to an auditor that the PHI went unmonitored because it “ran locally.”
The attack that looks like a Tuesday
The inbound direction is coming for you, and it’s using the same technology your employees use to move faster. AI-crafted payloads that slide past signature and behavior detection. Malware that rewrites its own structure on every execution. Living-off-the-land attacks that borrow your own admin tooling and look exactly like normal operations, right up until the encryption step.
And it’s quick now. What used to be a multi-day intrusion runs at machine speed. The kill chain can move from first foothold to encrypted files before an analyst finishes reading the first alert. Detection built on known indicators is losing ground, for one blunt reason: the malicious and the legitimate have started to look identical.
That’s the asymmetry worth losing sleep over. Attackers get compounding upgrades every month, for free, from the same open models your own team is experimenting with. Your defenses get a budget cycle and a patch window. The gap between the two doesn’t hold steady. It widens.
Seeing it isn’t stopping it
Here’s the part most of the industry won’t say out loud. Even if you could see all of this, you still couldn’t stop it.
Visibility and enforcement are not the same thing. Visibility tells you a model read your customer database at 2:14. Enforcement is what would have stopped it at 2:13. Most of the AI-governance market is selling the first and calling it the second. A policy that can’t act at the endpoint isn’t a control. It’s a document with good intentions.
That distinction is the whole game. Everyone can write the policy. Almost no one can enforce it where the data actually lives.
This isn’t a knock on governance. Governance has its place. It describes what should have happened. Enforcement is the part that decides what happens next, and it only works if it can act at the moment the data is about to move.
Both directions run through the endpoint
Data leaving and attackers arriving pass through the same place. The endpoint. It’s the only layer that sees the whole picture at once: who is acting, what process is running, which file it touches, and where it’s headed. The network sees a sliver. The cloud sees a different sliver. Only the endpoint watches the loop close.
That’s the ground Arms Cyber was built on. We hide the data that matters, so when an attacker, or a rogue AI process, lands where it expects your crown jewels, they simply aren’t there. We set decoys that trip on behavior instead of signatures, so a real threat gives itself away before it touches anything real. And we keep backups in concealed enclaves, so recovery takes minutes, not a weekend of rebuilding from infrastructure you can no longer trust.
The same sensor already doing all of that is the natural place to see shadow AI, and to act on it before the data walks.
This is a this-quarter problem
None of this is hypothetical, and none of it is waiting for you. Every quarter you delay is exposure you can never scrub clean and an intrusion bar that keeps dropping. The clock doesn’t stop, and it doesn’t run backward.
The good news is that the foundation already exists, in production today, protecting critical data from the most destructive threats in the wild. Extending it to shadow AI isn’t a moonshot. It’s the next step, and it’s close.
Until then, sit with one thought. The most dangerous data leak in your company this year probably won’t come from an attacker at all. It’ll come from someone trying to do their job well.
Nick Graves is Vice President of Engineering at Arms Cyber, where he leads the team responsible for delivering the company’s preemptive security platform at speed and scale. With two decades of experience spanning software development, solutions architecture, and enterprise security, Nick brings both architectural vision and hands-on technical depth to one of the most consequential problems in cybersecurity.

