DOP 349: Shadow AI Is Going to Be a Thousand Times Worse Than Shadow IT
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “DOP 349: Shadow AI Is Going to Be a Thousand Times Worse Than Shadow IT” inside PodZeus.
In this episode of DevOps Paradox, hosts Darren Pope and Victor Farson dive deep into the emerging threat of 'Shadow AI,' arguing it will be a thousand times more dangerous than the previously problematic 'Shadow IT.' With Ben Wilcox, CTO and CISO at ProArc, they explore how AI is rapidly infiltrating development pipelines without proper governance, leading to uncontrolled data exposure, security blind spots, and unpredictable behavior. The conversation highlights the failure of reactive security models and the urgent need for pre-planned, secure foundations—like landing zones and standardized tooling—before developers even begin coding. The hosts and guest stress that while AI promises massive productivity gains, it also introduces new risks, especially around model drift, data leakage, and agentic behavior. They emphasize that security must evolve from a gatekeeping role to a proactive, embedded function, with guardrails built into platforms from the start. Despite the challenges, there's cautious optimism that AI can be harnessed safely through better governance, automation, and a shift toward proactive risk modeling. Key takeaways include: 1) Treat AI as a foundational platform component, not an afterthought; 2) Build secure, pre-configured environments (landing zones) to eliminate developer guesswork; 3) Shift from reactive security to proactive, embedded guardrails; 4) Inventory all AI usage across teams, including commoditized tools like Copilot; 5) Plan for model drift and sunsetting by choosing stable, smaller models when possible; 6) Use AI to automate security testing and monitoring, not just development; 7) CISOs must become fluent in AI’s risks and use cases; 8) The future of security lies in 'AI for security' and 'security for AI' as co-evolving disciplines. The episode ends on a note of cautious hope, urging leaders to act now before AI sprawl becomes unmanageable.
Shadow AI will be a thousand times worse than Shadow IT—assume every platform has AI, and plan accordingly.
Build secure foundations (landing zones) before developers start coding to eliminate guesswork and reduce risk.
Shift from reactive security to proactive, embedded guardrails that don’t slow down development.
Inventory all AI usage across teams, including internal tools like Copilot and Power Platform agents.
Plan for model drift and sunsetting by choosing stable, smaller models and monitoring output consistency.
…and 3 more takeaways available in PodZeus
Shadow AI: The Next Big Threat
“Shadow AI is going to be a thousand times worse than Shadow IT.”
The Failure of Reactive Security
The hosts and guest critique the current state of security, particularly the reactive approach where security is bolted on after development. Ben Wilcox shares examples of developers being forced into security conversations too late, leading to costly retrofits.
Pre-Planning and Secure Foundations
“Once that's configured, right, you turn it over to the developer. Now they don't have to think about that standard control...”
AI’s Impact on Security and Development
“AI is going to that direction, right? And so the conversations now are who's going to govern this? Who's going to control it?”
The CTO and CISO Dilemma
Ben Wilcox discusses the tension of holding both CTO and CISO roles, emphasizing the need to balance business speed with security. He advocates for guardrails, not gatekeeping, and warns against the risks of combining both roles in regulated industries.
“Shadow AI is going to be a thousand times worse than Shadow IT.”
“I think that there's going to be foundations for safe AI adoption.”
“It's like, I just joined your company. You did not tell me anything and I know how to deploy to Azure and I will deploy to Azure.”
Hosts
Guest
Ben Wilcox
person
LLM
product
Microsoft
organization
DevOps
other
ProArc
organization
Azure
product
Agentic AI
other
OpenAI
organization
GitHub
product
Copilot
product
DOP 344: KubeCon EU 2026 Review
DevOps Paradox • 53m • 4/1/2026
DOP 345: From Chat Prompt to Working Software with Kiro
DevOps Paradox • 38m • 4/8/2026
DOP 346: Fighting AI in Your Project Is a Terrible Mistake
DevOps Paradox • 55m • 4/15/2026
DOP 347: Cozystack Turns Bare Metal Into a Managed Services Platform
DevOps Paradox • 47m • 4/22/2026
DOP 348: Now It's Time to Panic
DevOps Paradox • 50m • 4/29/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “DOP 349: Shadow AI Is Going to Be a Thousand Times Worse Than Shadow IT” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
