{"data":{"id":"0e8e491b-875d-4964-b1d2-01f82c6fbca4","title":"Why \"Shady AI\" is Security's Next Big Governance Problem","summary":"Shady AI refers to employees using approved AI tools in unapproved or unexpected ways, unlike shadow AI (completely unauthorized tools). A March 2026 Meta incident exemplified this when an approved internal AI agent publicly posted a response it wasn't supposed to, exposing sensitive data to unauthorized employees. Shady AI is harder to control than shadow AI because security teams can't simply block tools they've already approved and deployed across the organization.","solution":"N/A -- no mitigation discussed in source.","labels":["security","policy"],"sourceUrl":"https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html","publishedAt":"2026-08-20T11:45:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Meta"],"affectedVendorsRaw":["Meta"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-20T11:45:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}