Start Here · AI Security
AI systems concentrate context, credentials and the ability to act in places traditional security models never had to defend. This page is the map: what to read first, which tools to run against your own systems, and where the deep work lives.
Source: IBM Cost of a Data Breach 2025
The field guide organises the whole problem around six questions. They work for a chatbot, a coding assistant or a fleet of agents, and they expose the gaps a tooling checklist misses.
Read the research, or test your own systems first
The research hub. Worked incidents like EchoLeak and postmark-mcp, the recurring patterns behind them, and the controls that actually held. Grounded in primary sources and direct testing.
Field GuideA guided security check of one MCP server or a whole agent tool set. Answers three of the six questions about your own setup in about ten minutes, in your browser.
Browser ToolHow every risk moved between the 2025 and 2026 editions, and how the LLM list maps to the Agentic Top 10. Useful for repointing control mappings that reference stale identifiers.
Interactive DataDetection, controls, maturity and the budget conversation
Shadow AI is employees using AI tools like ChatGPT, Claude, Gemini or niche AI services without IT approval or oversight. 68% of organisations have employees using unsanctioned AI platforms, often with sensitive data. Unlike traditional Shadow IT, these tools process and learn from your data in ways you cannot see or control.
The risk is not theoretical. IBM's Cost of a Data Breach report puts the average breach at $4.88 million globally. When employees paste customer data, source code or financial records into public AI tools, you have handed your crown jewels to a third party with unknown security practices.
Traditional Shadow IT involved unauthorised software or cloud services. Shadow AI adds three dimensions:
Start with network monitoring. Most AI services use distinctive API endpoints you can track through your firewall or SIEM. Look for traffic to openai.com, anthropic.com, claude.ai and similar domains. Do not stop there: many tools offer local deployments or browser extensions that bypass network monitoring.
Build in this order: policy first, discovery second, controls third.
Start with a clear AI Acceptable Use Policy that lists approved tools, prohibited use cases and data classification guidelines. Be specific; "no unauthorised AI" is not a policy.
The goal is not to stop AI usage but to channel it safely.
Maturity is not binary. Organisations typically progress through three stages: Foundational (policies exist, enforcement is minimal), Developing (active monitoring with some technical controls) and Adaptive (comprehensive governance with continuous validation).
Score yourself honestly across four domains; the gaps are your roadmap:
Quick wins, 2 to 4 weeks: publish your AI policy, configure basic DLP rules, block the riskiest AI domains.
Detection capability, 1 to 3 months: SIEM alert integration, SOC team training, baselining normal behaviour.
Full maturity, 6 to 12 months: endpoint agents, identity provider integration for user-level controls, automated incident response workflows, continuous monitoring.
Most organisations see measurable risk reduction within the first 90 days if they prioritise ruthlessly.
Lead with business risk, not technical controls. Frame it as protecting competitive advantage, not buying more security tools. A concrete scenario lands harder than any slide: right now, any employee can paste your product roadmap into a public AI tool, and you would not know until a competitor announces the same features.
Then quantify the exposure. If 68% of organisations have Shadow AI and you employ 500 people, that is potentially 340 people with unsupervised access to AI tools. Price the breach using IBM's $4.88M average and a $100K investment in controls starts to look reasonable.
Labs, career roadmaps and the rest of what we build live in one place.
Browse Tools & Resources