BANGKOK – Artificial intelligence is transforming how businesses operate today. It brings incredible speed and efficiency to the modern workplace. However, this rapid technological shift is also creating a massive, hidden security vulnerability. Cybersecurity firm Kaspersky is officially sounding the alarm on a rapidly growing corporate threat known as shadow AI.
This emerging crisis happens when employees use unapproved generative AI tools to do their daily work. These applications usually bypass the official oversight of corporate IT departments. As a result, businesses are unknowingly handing over private data to public AI models. This dangerous practice rapidly expands the attack surface for cybercriminals.
Key Takeaways
- Shadow AI risks are surging: Employees are increasingly using unauthorized AI tools, bypassing IT security and leaking sensitive business data.
- Hackers are weaponizing AI: Cybercriminals use artificial intelligence to automate attacks, accelerating malware development and system breaches.
- New defensive tools are emerging: Kaspersky is launching the AI Protect platform to help businesses safely govern AI usage and prevent data leaks.
Shadow AI is essentially the unauthorized use of artificial intelligence tools by everyday employees. Workers often turn to these convenient platforms to save time on projects. Unfortunately, they are usually completely unaware of the massive security risks involved. This ultimately creates a dangerous parallel technology environment outside of official corporate governance.
Andrian Hia is the managing director for Asia-Pacific at Kaspersky. He recently highlighted this specific issue during the company’s annual Cyber Security Weekend event. He noted that organizations are eagerly adopting cloud-based AI services without formal IT approval. This critical lack of official oversight leaves companies incredibly vulnerable to devastating data breaches.
Employees routinely upload highly confidential business documents and financial records into public AI platforms. They also frequently share proprietary source code with these unverified external systems. Once sensitive corporate information is shared publicly, the organization loses control over it. This directly increases the risk of data leakage and gives hackers easy access.
AI-Powered Cyberattacks on the Rise
The rapid adoption of artificial intelligence is fundamentally reshaping the global threat landscape. Legitimate enterprises are using AI to dramatically improve everyday employee productivity. However, cybercriminals are also heavily exploiting the same technology. Hackers now use AI to automate their attacks and identify network vulnerabilities instantly.
Cyberthreats are quickly becoming AI-native in today’s highly connected digital world. Traditional human-centric cyberattacks are rapidly becoming a thing of the past. Mr. Hia pointed out that operations are shifting heavily toward machine-centric tactics. To survive this era, corporate cybersecurity must also evolve into an AI-powered discipline.
The scale of this security problem is truly staggering right now. Last year, Kaspersky successfully detected and blocked more than 500,000 unique malicious files daily. This represents a massive 7 percent increase from the total numbers recorded in 2024. These statistics clearly highlight just how fast these digital threats are multiplying globally.
The dangerous situation has only intensified throughout this current year. According to Kaspersky, the company has already identified more than 15,000 distinct malware samples. These malicious files were specifically disguised as legitimate agentic AI software. A single compromised component can quickly spread across an entire corporate network.
Kaspersky Launches the AI Protect Platform
In response to this crisis, Kaspersky is introducing its highly anticipated AI Protect platform. This new security solution is designed to help organizations govern their AI adoption safely. It aims to reduce the emerging risks associated with unverified shadow AI programs. It provides full visibility into exactly how employees interact with artificial intelligence.
The AI Protect platform actively scans AI agents and open-source components before deployment. This highly proactive approach helps detect dangerous malware, Trojan horses, and digital backdoors. It also easily identifies hidden software vulnerabilities within complex corporate systems. Catching these threats early prevents compromised AI tools from entering secure enterprise environments.
However, fixing the shadow AI problem requires more than just blocking unauthorized tools completely. Mr. Hia stressed that organizations absolutely need complete visibility into their networks. They must understand how corporate data flows across both public and private AI environments. Companies must track how their employees use these tools to keep sensitive data secure.
Expanding Enterprise Defense Strategies
The launch of the AI Protect platform reflects a broader shift within the cybersecurity industry. Organizations are finally moving away from basic, traditional endpoint protection models. They are now embracing fully integrated security platforms for better overall protection. These modern solutions securely cover software development, cloud infrastructure, and complex AI environments.
To support this transition, Kaspersky is heavily promoting its Open Single Management Platform. This powerful system consolidates network protection across IT infrastructure and mobile endpoints. It also easily secures massive data centers and vulnerable internet-connected devices. Everything is efficiently controlled and monitored through a single, unified management console.
This strategic corporate approach is already paying off heavily for the cybersecurity giant. Kaspersky’s enterprise business experienced a massive 60 percent growth during the latest financial year. This impressive financial surge was primarily driven by rising global corporate demand. Companies desperately need better threat intelligence, managed detection, and operational technology security.
Safeguarding Critical Infrastructure in Thailand
As enterprise AI adoption accelerates globally, Kaspersky has identified Thailand as a strategic growth market. Following successful technology investments in Vietnam and Indonesia, the company is focusing on Southeast Asia. Later this month, Kaspersky is scheduled to host a major Operational Technology Summit in Bangkok.
Industrial cybersecurity is expected to become the company’s next massive growth engine in Thailand. Kaspersky is expanding the deployment of its specialized Industrial CyberSecurity platform locally. This tool protects complex industrial control systems without disrupting critical daily operations. It is uniquely designed to meet the rising demand for better regional security.
Protecting these operational technology environments is much more critical than securing conventional IT systems. Cyberattacks on critical infrastructure can easily disrupt essential services like electricity and water supply. They can also shut down regional telecommunications and massive public transport networks. Without continuous network monitoring, attackers gain valuable time to compromise these vital public assets.
The Future of Business Cybersecurity
To prevent major incidents, a modern security operations center has become an absolute business necessity. These centers provide the essential visibility and specialized expertise needed to detect digital threats early. They also enforce the operational discipline required to stop hackers in their tracks. As attackers increasingly rely on AI, human defenders must confidently adopt similar advanced technologies.
For over two decades, Kaspersky has been embedding artificial intelligence directly into its security platforms. The company utilizes a unique, hybrid approach called HuMachine Intelligence. This successfully combines advanced machine learning algorithms with real, highly trained human expertise. This balanced strategy ensures that security protocols remain both highly efficient and deeply insightful.
Ultimately, the modern threat landscape requires a completely revolutionized approach to digital safety. Traditional corporate governance is simply no longer enough to protect sensitive business data. According to Mr. Hia, the future of cybersecurity revolves around securing every connected device. Protecting the critical systems that power modern businesses is the only way forward.
Trending News:
The Top Artificial Intelligence Startups to Watch in 2026
Is AI Search Talking About Your Brand, or Skipping it Entirely?
The 5 Best AI Image Generators in 2026 (And How to Pick the Right One)




