Shadow AI as a Business Risk
cepExecutive

Artificial Intelligence

Shadow AI as a Business Risk

Dr. Anselm Küsters, LL.M.
Dr. Anselm Küsters, LL.M.
  •     SMEs are increasingly vulnerable to AI-enabled attacks. Company-wide cyber resilience must therefore be a top priority in future.
  •     ‘Shadow AI’ – that is, AI applications and agents that enter the organisation via private accounts – is regarded as a gateway for AI-driven cyber attacks.
  •     The EU AI Act has so far provided only inadequate protection against risks posed by AI agents

With its new ‘cepExecutive’ format, the Centre for European Policy (cep) aims to target businesses specifically and provide them with quick and clear information on current technological, regulatory and geopolitical developments that impact the market, competition and strategy. To kick off the new series, we provide information on shadow AI as a growing business risk and offer guidance on what businesses and policymakers can do to prevent cyberattacks.

cepExecutive

Attackers who use artificial intelligence specifically target the weakest links in the chain – and these are often small and medium-sized enterprises. In the age of models such as ‘Claude Mythos’, anyone who lacks robust security measures and does not keep a detailed log of what is happening in their IT systems becomes easy prey. This is particularly true in areas where staff use AI technology without supervision. Examples of such ‘shadow AI’ include, above all, private ChatGPT accounts. In the near future, however, personal agents with far-reaching powers will also join the fray.

‘The latest AI models significantly lower the cost threshold for multi-stage autonomous network attacks. For instance, the depth of attacks has increased sixfold in less than two years, and a full attack attempt now costs only around 75 euros. The attacker’s skill level is thus becoming increasingly less decisive, which could dramatically alter the balance between cyber offence and cyber defence,” says AI expert Anselm Küsters, who authored the cepExecutive report. It is to be expected that Chinese AI models with comparable capabilities will follow suit within the next 12 months, which will significantly increase the attack surface once again.

Although the EU AI Act fundamentally covers AI agents, it remains ineffective in practice. Whilst model providers must actively address the risks of misuse, providers of agents are subject only to general cybersecurity requirements. Companies should therefore promptly assess which AI applications are actually in use, raise awareness of so-called prompt injection attacks, and establish clear guidelines for the use of AI in critical areas such as software development.

It is not only AI itself, but also the cyber risks it poses, that will have a significant impact on market structure, competitive dynamics and innovation. Companies must develop scenarios today to adapt their strategies to these developments.  

Download PDF

Shadow AI as a Business Risk (publ. 06.30.2026) PDF 641 KB Download
Shadow AI as a Business Risk