Smart60 · Issue One
The AI nobody approved
A contract goes into a chatbot at the end of the day and makes the deadline. Nobody did anything wrong, and nobody can prove it happened. A field note on shadow AI, and what to do before you legislate it.
It's late in the day. A large contract needs reviewing, redlines and an approval before legal leaves for the long weekend. So it goes into a chatbot, the key terms come back in twelve seconds, and everybody makes the deadline. Come on. That's a reasonable person under a deadline.
Nothing goes wrong. No event alert, no “incident,” not yet anyway. The document is just somewhere else now. No record it ever happened, and tomorrow it happens again, because it worked. The industry calls this shadow AI, which makes it sound a great deal more deliberate than it is.
Meanwhile the AI policy has been written, circulated and signed, and the DNS logs look exactly the same as they did the week before it. Same number of trips to the same handful of sites. Leadership believes AI use is governed. IT suspects otherwise. And nobody can really prove it one way or the other, partly because nobody has a number, and partly because nobody wants to be the corporate Killjoy. That's Security's job title.
The instinct is to block it. That fails, and you know this already. People move to their phones, the same document leaves on hardware you don't own, and now you can't see any of it.
Look before you legislate, I guess. Sorry, I'm not good with catchphrases. Thirty days of monitoring, nothing blocked, nobody told to stop. Then write the policy against evidence, and know before you say no. Or before you say yes, for that matter. The surprise is almost never the volume, and it isn't really the who either. You can guess the who. It's what they're feeding it and what those particular people have access to, and that pairing usually turns up in a department nobody thought to check.
And if you're already past that, if the tools are licensed and the policy is real, the question changes shape. Now it's what the spend is returning: which teams touch the seats you bought, which projects the tokens burn against, and whether any of it shows up as work that got done faster. Most people I talk to can answer the first question and not the second. Either way, that gap is the conversation worth having, and it's the one we run with clients.
Trade shows: worth the flight?
Black Hat was last month. The read from people I trust was consistent: four hundred-odd vendors claiming complete coverage of agentic security, which is roughly 399 more than can currently do it. Full disclosure, I go for the CPE credits like half the room, and I finished mine early this year, so I skipped Vegas altogether. Sounds like I didn't miss much, and if you skipped it too, neither did you. DEF CON I'll leave alone, except to admit I've never worked up the nerve to walk that floor with my phone turned on. I know what I said above about blocking things being the wrong instinct. Different threat model. I hear myself.
Two on the fall calendar I'd flag. Proofpoint Protect is in San Diego on September 21, and the agenda is the thing I just spent four paragraphs on: securing a workspace where people and AI tools are already collaborating, approved or not. It's Proofpoint's own show, so calibrate the claims accordingly, but the topic is the right one and the room will be full of people wrestling with it. I haven't registered yet, and it's a short drive, so I'm running out of excuses. If you're going, say so and that'll probably decide it.
Authenticate is October 19 to 21 at the Omni La Costa in Carlsbad, and this is the one I can actually vouch for, because I went last year. The speakers were good, which I don't say about most conferences, and the resort is a pleasant place to be stuck for three days. This year leans hard into non-human authentication and AI agents, which is the story at the top of this issue wearing a different hat: something is authenticating on your behalf and it is not a person. Worth the trip if identity is anywhere on your roadmap.
Both of these land in my backyard this year, so I'm out of excuses. My rule either way: go if you have three named conversations booked before you fly. Skip it if you're planning to walk the floor. Nobody has ever discovered anything useful walking a floor.
From the water
I surf and spearfish. This part has nothing to do with your network.
I love an El Niño year. Marie brought the best south swell we've had all year over the long weekend, along with some damage from waves this coast doesn't usually see. The warm water is turning up fish that have no business being this far north, and somebody just landed a 500-pound bluefin off San Diego. Commercial boat, so no record. Nothing o-fish-ial, which bothers me a lot less than 500 pounds of sashimi.
Anything you liked, anything you didn't, anything you want covered next time? Or have a better Fish Pon… Let minnow.
Sean Mooney, CISSP
SmartVantage · I.T. and Cybersecurity
More from SmartVantage: AI Governance