{"id":88821,"topic":"ai","source":"IBM","title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","url_hash":"6c3168d62c31da614b979429370cd52ce2385afb","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMikAFBVV95cUxNMHBneUk1SDBqbVYyQm9PTmlraml3TjlTT1VHUVloSGJfNWNCb3BBaDQ1VUFvV1RLVVJQM2R2emxMcnJJOGZNOGp6ckV1a2tBOHRoak9yeG9sTEE0OWtOYzBudm1NZEhzRlk2RmJJQWdILWgxeGFJSkhLYXliSkZCMUZWYWwwaTloVWRXbHNUbzc?oc=5\" target=\"_blank\">Shadow AI has reached the SOC: Why security teams are becoming their own blind spot</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">IBM</font>","content":"It is 2 AM on a night shift. An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand. There is a faster way and everyone on the shift knows it.\nOpen a personal chatbot, paste the command, ask what it does. The answer comes back in seconds. The ticket gets closed. Nobody thinks about where that command just went.\nNow think about what it was inside. An internal hostname. A service account name. A file path that shows how the environment is set up. Small pieces of exactly the type of information an attacker would want, sent by hand to an outside service the company has never reviewed, under a personal account nobody can check.\nThis is shadow AI. And the uncomfortable part is not that it is happening across companies in general. That much is well known. The uncomfortable part is that it is happening inside security teams themselves, the very people whose job is to stop sensitive data from leaving the building.\nThe industry has spent two years worrying about employees pasting customer data into chatbots. Far less attention has gone to the analysts pasting incident data into them.\nThe numbers on general shadow AI use are hard to ignore. Industry research through 2025 and 2026 keeps finding that employees use AI tools that their company has not approved, with a large share admitting they have put sensitive information into them.\nThe cost is real now. It’s not just a worry.\nThat gap between worrying and doing something is where the problem lives.\nIt is easy to assume that security professionals would be the last people to leak data into a chatbot. The daily reality of SOC work points the other way.\nThe work is repetitive, always against the clock and full of text that begs to be pasted somewhere, such as:\nA general AI tool is genuinely good at every one of these jobs and analysts with a full queue know it.\nWhat gets pasted is also far more sensitive than most office work. A marketing employee might leak a campaign plan. An analyst can leak internal hostnames, usernames, IP ranges, detection rules and the exact indicators tied to a live incident.\nIn the wrong place that is not just a privacy problem. It is free homework for an attacker. And in a managed security setup, it might be a client’s data rather than your own, which turns a bad habit into a broken contract.\nThere is also a quieter risk that rarely gets talked about. Analysts who rely on unapproved AI for their verdicts can inherit its mistakes. A tool that confidently misreads a command can send an investigation down the wrong path and a wrong verdict pasted into a ticket looks exactly as convincing as a right one.\nThe first instinct is a ban. Block the chatbot sites, publish a policy, move on. In practice, this fails for the same reason shadow IT bans failed ten years ago. The tools are too useful, the pressure is too real and the workarounds are too easy. Personal phones sit next to work keyboards on every SOC floor. A blocklist of AI sites goes stale within weeks as new tools appear.\nBans also push the habit somewhere worse. An analyst who cannot use a monitored work connection will use an unmonitored personal one, and the security team loses the one thing the team needs, which is visibility. The lesson from a decade of shadow IT is simple. When a useful tool is banned instead of managed, people do not stop using the tool. They just hide the usage.\nThe teams handling this challenge well are not the ones with the strictest policies. They are the ones that made the safe path the easy path.\nShadow AI in the SOC is not a story about careless analysts. It is a story about capable people under pressure reaching for the best tool available because nobody gave them an approved one. That makes it a leadership problem before it is a user problem and it has a leadership fix.\nThe SOC that gets this right does three things:\nSecurity teams hold themselves to a higher standard on data handling. AI arriving at the analyst’s desk tests whether we meet that standard. The teams that pass the test are able to use the technology in the open.\nNone of this is theory. IBM’s own answer was to build the approved path at scale. IBM Consulting® Advantage, launched in 2024, puts AI assistants powered by watsonx® into the daily work of roughly 160,000 consultants, inside a platform with proper data handling, logging and controls. The same thinking has reached the SOC: the Autonomous Threat Operations Machine brings AI agents into alert triage and investigation through a managed workflow, alongside the wider portfolio including QRadar®. The approved route is fast and genuinely useful, which is the only thing that ever wins against a personal chatbot.","image_url":"https://www.ibm.com/content/dam/worldwide-content/stock-assets/adb-stk/ul/g/ca/c4/adobestock_420662187.jpeg/_jcr_content/renditions/cq5dam.web.1280.1280.jpeg","lang":"en","published_at":"2026-09-23T12:54:13+00:00","fetched_at":"2026-09-23T13:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4740,"summary_length":138,"usable_text_length":4740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4740,"summary_length":138}},"news_item":{"id":88821,"canonical_url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","source_url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","source_name":"IBM","author":null,"published_at":"2026-09-23T12:54:13+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMikAFBVV95cUxNMHBneUk1SDBqbVYyQm9PTmlraml3TjlTT1VHUVloSGJfNWNCb3BBaDQ1VUFvV1RLVVJQM2R2emxMcnJJOGZNOGp6ckV1a2tBOHRoak9yeG9sTEE0OWtOYzBudm1NZEhzRlk2RmJJQWdILWgxeGFJSkhLYXliSkZCMUZWYWwwaTloVWRXbHNUbzc?oc=5\" target=\"_blank\">Shadow AI has reached the SOC: Why security teams are becoming their own blind spot</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">IBM</font>","full_text":"It is 2 AM on a night shift. An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand. There is a faster way and everyone on the shift knows it.\nOpen a personal chatbot, paste the command, ask what it does. The answer comes back in seconds. The ticket gets closed. Nobody thinks about where that command just went.\nNow think about what it was inside. An internal hostname. A service account name. A file path that shows how the environment is set up. Small pieces of exactly the type of information an attacker would want, sent by hand to an outside service the company has never reviewed, under a personal account nobody can check.\nThis is shadow AI. And the uncomfortable part is not that it is happening across companies in general. That much is well known. The uncomfortable part is that it is happening inside security teams themselves, the very people whose job is to stop sensitive data from leaving the building.\nThe industry has spent two years worrying about employees pasting customer data into chatbots. Far less attention has gone to the analysts pasting incident data into them.\nThe numbers on general shadow AI use are hard to ignore. Industry research through 2025 and 2026 keeps finding that employees use AI tools that their company has not approved, with a large share admitting they have put sensitive information into them.\nThe cost is real now. It’s not just a worry.\nThat gap between worrying and doing something is where the problem lives.\nIt is easy to assume that security professionals would be the last people to leak data into a chatbot. The daily reality of SOC work points the other way.\nThe work is repetitive, always against the clock and full of text that begs to be pasted somewhere, such as:\nA general AI tool is genuinely good at every one of these jobs and analysts with a full queue know it.\nWhat gets pasted is also far more sensitive than most office work. A marketing employee might leak a campaign plan. An analyst can leak internal hostnames, usernames, IP ranges, detection rules and the exact indicators tied to a live incident.\nIn the wrong place that is not just a privacy problem. It is free homework for an attacker. And in a managed security setup, it might be a client’s data rather than your own, which turns a bad habit into a broken contract.\nThere is also a quieter risk that rarely gets talked about. Analysts who rely on unapproved AI for their verdicts can inherit its mistakes. A tool that confidently misreads a command can send an investigation down the wrong path and a wrong verdict pasted into a ticket looks exactly as convincing as a right one.\nThe first instinct is a ban. Block the chatbot sites, publish a policy, move on. In practice, this fails for the same reason shadow IT bans failed ten years ago. The tools are too useful, the pressure is too real and the workarounds are too easy. Personal phones sit next to work keyboards on every SOC floor. A blocklist of AI sites goes stale within weeks as new tools appear.\nBans also push the habit somewhere worse. An analyst who cannot use a monitored work connection will use an unmonitored personal one, and the security team loses the one thing the team needs, which is visibility. The lesson from a decade of shadow IT is simple. When a useful tool is banned instead of managed, people do not stop using the tool. They just hide the usage.\nThe teams handling this challenge well are not the ones with the strictest policies. They are the ones that made the safe path the easy path.\nShadow AI in the SOC is not a story about careless analysts. It is a story about capable people under pressure reaching for the best tool available because nobody gave them an approved one. That makes it a leadership problem before it is a user problem and it has a leadership fix.\nThe SOC that gets this right does three things:\nSecurity teams hold themselves to a higher standard on data handling. AI arriving at the analyst’s desk tests whether we meet that standard. The teams that pass the test are able to use the technology in the open.\nNone of this is theory. IBM’s own answer was to build the approved path at scale. IBM Consulting® Advantage, launched in 2024, puts AI assistants powered by watsonx® into the daily work of roughly 160,000 consultants, inside a platform with proper data handling, logging and controls. The same thinking has reached the SOC: the Autonomous Threat Operations Machine brings AI agents into alert triage and investigation through a managed workflow, alongside the wider portfolio including QRadar®. The approved route is fast and genuinely useful, which is the only thing that ever wins against a personal chatbot.","excerpt":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 4740 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4740,"summary_length":138,"usable_text_length":4740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4740,"summary_length":138}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","summary":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","source":"IBM","date":"2026-09-23T12:54:13+00:00","content":"It is 2 AM on a night shift. An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand. There is a faster way and everyone on the shift knows it.\nOpen a personal chatbot, paste the command, ask what it does. The answer comes back in seconds. The ticket gets closed. Nobody thinks about where that command just went.\nNow think about what it was inside. An internal hostname. A service account name. A file path that shows how the environment is set up. Small pieces of exactly the type of information an attacker would want, sent by hand to an outside service the company has never reviewed, under a personal account nobody can check.\nThis is shadow AI. And the uncomfortable part is not that it is happening across companies in general. That much is well known. The uncomfortable part is that it is happening inside security teams themselves, the very people whose job is to stop sensitive data from leaving the building.\nThe industry has spent two years worrying about employees pasting customer data into chatbots. Far less attention has gone to the analysts pasting incident data into them.\nThe numbers on general shadow AI use are hard to ignore. Industry research through 2025 and 2026 keeps finding that employees use AI tools that their company has not approved, with a large share admitting they have put sensitive information into them.\nThe cost is real now. It’s not just a worry.\nThat gap between worrying and doing something is where the problem lives.\nIt is easy to assume that security professionals would be the last people to leak data into a chatbot. The daily reality of SOC work points the other way.\nThe work is repetitive, always against the clock and full of text that begs to be pasted somewhere, such as:\nA general AI tool is genuinely good at every one of these jobs and analysts with a full queue know it.\nWhat gets pasted is also far more sensitive than most office work. A marketing employee might leak a campaign plan. An analyst can leak internal hostnames, usernames, IP ranges, detection rules and the exact indicators tied to a live incident.\nIn the wrong place that is not just a privacy problem. It is free homework for an attacker. And in a managed security setup, it might be a client’s data rather than your own, which turns a bad habit into a broken contract.\nThere is also a quieter risk that rarely gets talked about. Analysts who rely on unapproved AI for their verdicts can inherit its mistakes. A tool that confidently misreads a command can send an investigation down the wrong path and a wrong verdict pasted into a ticket looks exactly as convincing as a right one.\nThe first instinct is a ban. Block the chatbot sites, publish a policy, move on. In practice, this fails for the same reason shadow IT bans failed ten years ago. The tools are too useful, the pressure is too real and the workarounds are too easy. Personal phones sit next to work keyboards on every SOC floor. A blocklist of AI sites goes stale within weeks as new tools appear.\nBans also push the habit somewhere worse. An analyst who cannot use a monitored work connection will use an unmonitored personal one, and the security team loses the one thing the team needs, which is visibility. The lesson from a decade of shadow IT is simple. When a useful tool is banned instead of managed, people do not stop using the tool. They just hide the usage.\nThe teams handling this challenge well are not the ones with the strictest policies. They are the ones that made the safe path the easy path.\nShadow AI in the SOC is not a story about careless analysts. It is a story about capable people under pressure reaching for the best tool available because nobody gave them an approved one. That makes it a leadership problem before it is a user problem and it has a leadership fix.\nThe SOC that gets this right does three things:\nSecurity teams hold themselves to a higher standard on data handling. AI arriving at the analyst’s desk tests whether we meet that standard. The teams that pass the test are able to use the technology in the open.\nNone of this is theory. IBM’s own answer was to build the approved path at scale. IBM Consulting® Advantage, launched in 2024, puts AI assistants powered by watsonx® into the daily work of roughly 160,000 consultants, inside a platform with proper data handling, logging and controls. The same thinking has reached the SOC: the Autonomous Threat Operations Machine brings AI agents into alert triage and investigation through a managed workflow, alongside the wider portfolio including QRadar®. The approved route is fast and genuinely useful, which is the only thing that ever wins against a personal chatbot.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 4740 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4740,"summary_length":138,"usable_text_length":4740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4740,"summary_length":138}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/88821","export_markdown":"/api/items/88821/export?format=markdown","export_json":"/api/items/88821/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots"},"formats":{"full":{"id":88821,"title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","source":"IBM","author":null,"published_at":"2026-09-23T12:54:13+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","full_text":"It is 2 AM on a night shift. An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand. There is a faster way and everyone on the shift knows it.\nOpen a personal chatbot, paste the command, ask what it does. The answer comes back in seconds. The ticket gets closed. Nobody thinks about where that command just went.\nNow think about what it was inside. An internal hostname. A service account name. A file path that shows how the environment is set up. Small pieces of exactly the type of information an attacker would want, sent by hand to an outside service the company has never reviewed, under a personal account nobody can check.\nThis is shadow AI. And the uncomfortable part is not that it is happening across companies in general. That much is well known. The uncomfortable part is that it is happening inside security teams themselves, the very people whose job is to stop sensitive data from leaving the building.\nThe industry has spent two years worrying about employees pasting customer data into chatbots. Far less attention has gone to the analysts pasting incident data into them.\nThe numbers on general shadow AI use are hard to ignore. Industry research through 2025 and 2026 keeps finding that employees use AI tools that their company has not approved, with a large share admitting they have put sensitive information into them.\nThe cost is real now. It’s not just a worry.\nThat gap between worrying and doing something is where the problem lives.\nIt is easy to assume that security professionals would be the last people to leak data into a chatbot. The daily reality of SOC work points the other way.\nThe work is repetitive, always against the clock and full of text that begs to be pasted somewhere, such as:\nA general AI tool is genuinely good at every one of these jobs and analysts with a full queue know it.\nWhat gets pasted is also far more sensitive than most office work. A marketing employee might leak a campaign plan. An analyst can leak internal hostnames, usernames, IP ranges, detection rules and the exact indicators tied to a live incident.\nIn the wrong place that is not just a privacy problem. It is free homework for an attacker. And in a managed security setup, it might be a client’s data rather than your own, which turns a bad habit into a broken contract.\nThere is also a quieter risk that rarely gets talked about. Analysts who rely on unapproved AI for their verdicts can inherit its mistakes. A tool that confidently misreads a command can send an investigation down the wrong path and a wrong verdict pasted into a ticket looks exactly as convincing as a right one.\nThe first instinct is a ban. Block the chatbot sites, publish a policy, move on. In practice, this fails for the same reason shadow IT bans failed ten years ago. The tools are too useful, the pressure is too real and the workarounds are too easy. Personal phones sit next to work keyboards on every SOC floor. A blocklist of AI sites goes stale within weeks as new tools appear.\nBans also push the habit somewhere worse. An analyst who cannot use a monitored work connection will use an unmonitored personal one, and the security team loses the one thing the team needs, which is visibility. The lesson from a decade of shadow IT is simple. When a useful tool is banned instead of managed, people do not stop using the tool. They just hide the usage.\nThe teams handling this challenge well are not the ones with the strictest policies. They are the ones that made the safe path the easy path.\nShadow AI in the SOC is not a story about careless analysts. It is a story about capable people under pressure reaching for the best tool available because nobody gave them an approved one. That makes it a leadership problem before it is a user problem and it has a leadership fix.\nThe SOC that gets this right does three things:\nSecurity teams hold themselves to a higher standard on data handling. AI arriving at the analyst’s desk tests whether we meet that standard. The teams that pass the test are able to use the technology in the open.\nNone of this is theory. IBM’s own answer was to build the approved path at scale. IBM Consulting® Advantage, launched in 2024, puts AI assistants powered by watsonx® into the daily work of roughly 160,000 consultants, inside a platform with proper data handling, logging and controls. The same thinking has reached the SOC: the Autonomous Threat Operations Machine brings AI agents into alert triage and investigation through a managed workflow, alongside the wider portfolio including QRadar®. The approved route is fast and genuinely useful, which is the only thing that ever wins against a personal chatbot.","reading_time_min":4,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 4740 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4740,"summary_length":138,"usable_text_length":4740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4740,"summary_length":138}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4740,"summary_length":138,"usable_text_length":4740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4740,"summary_length":138}},"actions":{"read":"/item/88821","export_markdown":"/api/items/88821/export?format=markdown","export_json":"/api/items/88821/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots"}},"digest":{"id":88821,"title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","source":"IBM","topic":"ai","published_at":"2026-09-23T12:54:13+00:00","excerpt":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 4740 characters.","reading_time_min":4,"cluster_id":null},"card":{"display_title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","subtitle":"IBM · 2026-09-23","summary":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","badges":["quality:high"],"links":{"read":"/item/88821","original":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","diagnose":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots"},"quality_warning":null},"export":{"title":"Shadow AI has reached the SOC: Why security teams are becoming their own blind spot - IBM","url":"https://www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","summary":"An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand.","source":"IBM","date":"2026-09-23T12:54:13+00:00","content":"It is 2 AM on a night shift. An analyst is looking at a PowerShell command pulled from an alert. It is long, scrambled and would take twenty minutes to decode by hand. There is a faster way and everyone on the shift knows it.\nOpen a personal chatbot, paste the command, ask what it does. The answer comes back in seconds. The ticket gets closed. Nobody thinks about where that command just went.\nNow think about what it was inside. An internal hostname. A service account name. A file path that shows how the environment is set up. Small pieces of exactly the type of information an attacker would want, sent by hand to an outside service the company has never reviewed, under a personal account nobody can check.\nThis is shadow AI. And the uncomfortable part is not that it is happening across companies in general. That much is well known. The uncomfortable part is that it is happening inside security teams themselves, the very people whose job is to stop sensitive data from leaving the building.\nThe industry has spent two years worrying about employees pasting customer data into chatbots. Far less attention has gone to the analysts pasting incident data into them.\nThe numbers on general shadow AI use are hard to ignore. Industry research through 2025 and 2026 keeps finding that employees use AI tools that their company has not approved, with a large share admitting they have put sensitive information into them.\nThe cost is real now. It’s not just a worry.\nThat gap between worrying and doing something is where the problem lives.\nIt is easy to assume that security professionals would be the last people to leak data into a chatbot. The daily reality of SOC work points the other way.\nThe work is repetitive, always against the clock and full of text that begs to be pasted somewhere, such as:\nA general AI tool is genuinely good at every one of these jobs and analysts with a full queue know it.\nWhat gets pasted is also far more sensitive than most office work. A marketing employee might leak a campaign plan. An analyst can leak internal hostnames, usernames, IP ranges, detection rules and the exact indicators tied to a live incident.\nIn the wrong place that is not just a privacy problem. It is free homework for an attacker. And in a managed security setup, it might be a client’s data rather than your own, which turns a bad habit into a broken contract.\nThere is also a quieter risk that rarely gets talked about. Analysts who rely on unapproved AI for their verdicts can inherit its mistakes. A tool that confidently misreads a command can send an investigation down the wrong path and a wrong verdict pasted into a ticket looks exactly as convincing as a right one.\nThe first instinct is a ban. Block the chatbot sites, publish a policy, move on. In practice, this fails for the same reason shadow IT bans failed ten years ago. The tools are too useful, the pressure is too real and the workarounds are too easy. Personal phones sit next to work keyboards on every SOC floor. A blocklist of AI sites goes stale within weeks as new tools appear.\nBans also push the habit somewhere worse. An analyst who cannot use a monitored work connection will use an unmonitored personal one, and the security team loses the one thing the team needs, which is visibility. The lesson from a decade of shadow IT is simple. When a useful tool is banned instead of managed, people do not stop using the tool. They just hide the usage.\nThe teams handling this challenge well are not the ones with the strictest policies. They are the ones that made the safe path the easy path.\nShadow AI in the SOC is not a story about careless analysts. It is a story about capable people under pressure reaching for the best tool available because nobody gave them an approved one. That makes it a leadership problem before it is a user problem and it has a leadership fix.\nThe SOC that gets this right does three things:\nSecurity teams hold themselves to a higher standard on data handling. AI arriving at the analyst’s desk tests whether we meet that standard. The teams that pass the test are able to use the technology in the open.\nNone of this is theory. IBM’s own answer was to build the approved path at scale. IBM Consulting® Advantage, launched in 2024, puts AI assistants powered by watsonx® into the daily work of roughly 160,000 consultants, inside a platform with proper data handling, logging and controls. The same thinking has reached the SOC: the Autonomous Threat Operations Machine brings AI agents into alert triage and investigation through a managed workflow, alongside the wider portfolio including QRadar®. The approved route is fast and genuinely useful, which is the only thing that ever wins against a personal chatbot.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.ibm.com/think/insights/shadow-ai-has-reached-soc-security-teams-blind-spots","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 4740 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4740,"summary_length":138,"usable_text_length":4740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4740,"summary_length":138}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}