Episode Categories:
Resources:
Join the discussion: Got something to say? Let us know on LinkedIn and network with other AI leaders
Upcoming Episodes: Check out the upcoming Everyday AI Livestream lineup
Connect with Jordan Wilson: LinkedIn Profile
Managing AI Sprawl: Strategies to Control Risks and Unlock ROI
Three years after the major breakthroughs in generative AI, many companies are still grappling with a sprawling landscape of AI tools, models, and experimental projects. Despite enormous investments, many organizations are not only struggling to manage this explosion but are also failing to capture the expected business value. This article lays out what AI sprawl really looks like on the ground, the specific risks it introduces, and actionable approaches to bring clarity, control, and ROI into AI strategy.
AI Sprawl and Business Risk: Moving Beyond Experimentation
The post-ChatGPT landscape has created what can best be described as "AI spaghetti." Organizations face hundreds of different models, tools, and agents—often adopted without central oversight or a unified strategy. Despite leaders’ efforts to introduce guidelines, employees frequently deploy their own AI solutions, sometimes using unsanctioned or free tools that present significant data privacy and security vulnerabilities.
The consequences of this decentralized proliferation are concrete: enterprises end up with overlapping software, redundant capabilities, and a host of shadow IT issues where nobody has a complete inventory of what's running. Security teams regularly discover agents that operate with excessive privileges, introducing the risk that sensitive company data might be improperly managed or accessible to malicious actors.
Recent high-profile security incidents—including prompt injection attacks—demonstrate that the lack of a cohesive AI management approach only amplifies an organization’s exposure, with some companies unaware of risks until it’s too late.
Shadow AI: Undetected Exposure in Everyday Workflows
Well-intentioned employees often drive shadow AI activity, uploading confidential data or granting broad permissions to personal agents or tools. This risk becomes acute when employees use free, consumer-facing versions of AI products, which may explicitly disclaim any guarantee of confidentiality or compliance with enterprise-grade security standards.
Further complicating this, organizations are contending with over 2 million AI models on platforms such as Hugging Face—many developed outside established security frameworks. Coupled with aggressive industry innovation, this makes it nearly impossible for IT or security leaders to track which models and vendors are actively integrated across an enterprise.
AI Model Management: The Need for Agility and Vendor Autonomy
Exclusive reliance on a single AI model or vendor is increasingly impractical. New models or updates can surpass previous benchmarks within weeks, and the financial ramifications can rapidly escalate. For example, model upgrades such as from GPT-4 to GPT-4.1 have resulted in as much as an 800% decrease in token costs, but many organizations remain stuck on older, costlier implementations due to integration inertia.
Major model providers, each with proprietary tokenization and billing frameworks, add operational complexity for larger organizations juggling multiple projects and departments. Outages across these providers are not rare, sometimes lasting several hours. Enterprise leaders who cannot dynamically route between models risk a complete halt to critical applications.
Effective management calls for a modular, vendor-agnostic control plane to allow rapid benchmarking and switching between best-fit models, optimizing both costs and performance and preventing vendor lock-in and operational bottlenecks.
Enterprise Security in the Age of Agentic and Autonomous AI
Security postures built for deterministic APIs are ill-suited for the era of autonomous agents empowered by large language models. These agents, designed to execute complex, multi-system tasks with natural language directives, magnify vulnerabilities when granted excessive privileges or left unsupervised. The threat extends beyond unintentional data exposure: swarms of malicious agents can now undertake coordinated, dynamic cyberattacks at speeds unmanageable by traditional monitoring systems.
Additionally, business continuity risk grows when AI workloads become dependent on a single provider or inadequately segmented operational environments. Without rigorous inventory, observability, and control mechanisms, organizations cannot reliably shut down AI agents when employees leave, nor can they ensure agents execute only as intended.
Quantifying the Financial Impact: The Hidden Cost of AI Pilots
Substantial investments in AI are often squandered before reaching production. Recent industry analyses have put the failure rate of AI pilots at 95%, with wasteful duplication and isolated procurement actions driving costs. As cited, enterprise expenditures in this domain can reach tens of billions. CFOs and COOs are increasingly tasked with assessing whether these investments actually yield productivity gains or if they fuel silent value erosion through unmanaged sprawl.
Budgetary controls, centralized procurement, and clear ROI metrics are non-negotiable. Without these, organizations silently lose value month-over-month as AI sprawl grows unchecked.
Practical Steps for Reining in AI Chaos
Containment starts with awareness. Organizations must systematically discover and inventory all AI models and tools—including those embedded in third-party vendor solutions or acquired independently by employees. This provides the visibility required to apply controls, enforce security protections, and streamline overlapping solutions.
Centralized orchestration and security platforms can help organizations:
Benchmark and monitor model performance, latency, and costs in real-time.
Automate failover between models to safeguard business continuity during outages.
Maintain strict access controls and auditing around agent permissions.
Empower users at any skill level to build or adapt workflows using approved models, reducing shadow IT risk.
Continuous review and fortification of in-production tools, rather than blocking experimentation, ensure that AI delivers durable business value instead of just technological novelty.
Conclusion
AI sprawl is not a theoretical challenge—it is an operational, financial, and security reality impacting organizations today. Business value from AI is achievable only through deliberate inventory, modular model management, strict access controls, and real-time oversight. Addressing sprawl with a unified, platform-driven strategy keeps innovation productive while protecting enterprise interests and paving the way for tangible returns on AI investment.
Topics Covered in This Episode:
- AI Sprawl Challenges for Enterprises
- Shadow AI and Security Risks
- Centralized AI Management Platforms
- Model Agility and Vendor Lock-In Solutions
- Secure Sandbox for Model Testing
- Financial Impact of AI Sprawl
- Agentic AI Security Concerns
- Steps to Discover and Control Shadow AI
Episode Transcript
Jordan Wilson [00:00:17]:
Here we are three years past the chat g p t moment that has redefined how the majority of people work, yet It's still kind of AI chaos and that's coming from the guy that talks about AI every single day. That's because the models are always changing. The players are always changing. The capabilities are over are always changing. And it's almost created just this AI sprawl because, yeah, some companies have approved AI tools, others don't. And sometimes, you have entire departments, using unsanctioned AI, kind of this shadow AI, that's casting a huge shadow over, are you even getting a return? It is extremely difficult for decision makers in organizations to not just know, hey. What's the right platform to use? Maybe take advantage of the best models regardless of the provider, but also how to do it in a secure way that can manage the chaos and actually lead to a positive ROI. So that's exactly what we're gonna be tackling on today's episode of Everyday AI.
Jordan Wilson [00:01:30]:
What's going on y'all? Welcome. If you're new here, my name is Jordan Wilson. I'm the host. We do this every single day, at least Mondays through Friday, bringing you an unedited, unscripted livestream podcast and free daily newsletter helping everyday business leaders like you and me make sense of the AI chaos and leverage the best there is to offer to grow our companies and our careers. That's what you're trying to do. It starts here, but make sure you go to our website at youreverydayai.com. We're gonna be recapping the highlights from today's podcast as well as giving you all of the other AI news that you need to know. Alright.
Jordan Wilson [00:02:04]:
Enough of me. Let's talk to someone that's actually a global leader in this, and I'm excited for today's conversation. I talk about this concept all the time, but we have yet to have a dedicated episode just tackling how to manage AI sprawl and, actually show ROI. So I'm excited for today's guest. Livestream audience, please help me welcome to the show, Kevin Kiley, the CEO of Aria. Kevin, thank you so much for joining the Everyday AI Show.
Kevin Kiley [00:02:33]:
Hey, Jordan. Really excited to be here.
Jordan Wilson [00:02:35]:
Alright. Let's let's get into it. Well, actually, first, for those that don't know, and you probably should know because Aria has been on the airways for the last week or two here on Everyday AI. But explain a little bit about what Aria is and what you all do, Kevin.
Kevin Kiley [00:02:49]:
Aria is an AI orchestration and security platform. We're a global company about 400 customers now around the world and growing very quickly all around this idea of how
Jordan Wilson [00:03:00]:
do we help enable organizations to move faster, more securely with AI. So AI sprawl, it seems like has kind of gotten out of control. Right? If I would rewind to the chat chikat moment and then look where we are today, I never would have imagined. Right? There's literally hundreds of models that companies are using. The agent's capabilities are extremely impressive, yet there's huge security risks. How are you all tackling, this this concept of AI sprawl?
Kevin Kiley [00:03:33]:
Yeah. A great question. And so relevant right now, as you say, about three years ago that the CHAD should be key three five came out. And with that gauntlet thrown down, everyone saw what was possible or saw some version of what could be done. And, in the years since, it's been a a race to go employ AI as much as you can, anywhere you can, almost a a reckless sort of FOMO that happened across the industry, right, where every organization felt like they had to be showing they were doing something with AI. That also meant that your vendors were gonna start throwing a lot of AI at you and and AI washing some of their existing products, trying to launch new products, maybe turning on capabilities that they didn't really communicate to you that they were enabling. You had departments doing their own thing, even employees doing their own thing. Shadow AI, as you mentioned, where oh, and perhaps a well intended employee wants to be more productive.
Kevin Kiley [00:04:30]:
They wanna be more impactful. So they're bringing their own, chat GPT or perplexity or something to work with them and and using it, with their company data. Well, all of that sprawl has created the spaghetti mess that we're in now where you've got, all these different tools, each with their own management needs that may or may not be met. Yeah. And that's huge security risks. You've got agents that are being created by employees often being given the employees individual permissions, which, are very broad versus maybe the agent was supposed to go do this one thing, but instead now it's been given all these capabilities to do a lot of other things that could create risk. And then there's the financial aspect that you sort of touched on as well, where all these different purchases have been made without one sort of unifying direction, a lot of overlap, redundancy, and capability and need. And it means that the companies are being drowned in different invoices from different vendors, without really any clarity as to whether those projects are performing for them and they're really getting return on it.
Kevin Kiley [00:05:33]:
So that is the mess that we've set out to to try to address, to bring some clarity by providing kind of a central control plane, if you will, across the organization. Help them understand what AI has been employed, who's using it, how they're using it, create some record or observability of it all. And then once we know where it is to apply some controls, some guardrails, and then ultimately help them build more efficiently. So you can build within our product using any model. Got thousands of options, integrate any of your tools or applications all within one. But if you've already got an existing vendor you're building on, great. Let us just help apply the controls, the guardrails, the visibility, and give you that overarching management across all the AI in your organization.
Jordan Wilson [00:06:21]:
Yeah. And, and Kevin, I, I love that analogy. I'm going to just maybe steal it because it's so good. Right? Just it's like AI spaghetti. Right? Like, everyone's throwing AI at the wall, except they might not actually go back and see what sticks. Right? Maybe they just throw it at the wall and walk away and hope that revenue goes up, productivity goes up. Right. But, I'm curious when you're talking enterprise leaders right now, what does AI sprawl actually look like on the ground?
Kevin Kiley [00:06:51]:
I think the the most immediate thing that resonates is the security risk of it. And I I talked about maybe, you know, that that these are overly premise agents that an employee may stand up. Nobody really knows what it's doing apart from that one individual. And if they leave the company, who knows? If you if you speak to a lot of these CIOs and even the CISOs will soften acknowledge there isn't a central inventory of what's happening out there. That's the the immediate concern, and that's only gonna become more pronounced as we see more and more of these attacks happen. This past ninety days, we've seen a number of these in the press where whether it was prompt injections or, indirect prompt injection attacks. There's a couple of big ones that were announced just in the last two weeks. And I think you'll see a lot more of these scary stories starting to show up where companies are finding that they're very vulnerable because AI has been thrown out.
Kevin Kiley [00:07:44]:
So, sort of rushed without a lot of control or or visibility. So that's the the most immediate concern from there. It is often about how do we help, rationalize some of the use, find a way to to enable our employees to embrace it, whether you're a, you know, citizen developer who's never done any AI engineering, you're not a data scientist, etcetera. But you're really good at your one function within the business. You may be the best at finance or marketing or whatever it might be. Let's give you capabilities, to build your own AI using your knowledge, and we'll take care of the the plumbing bits around it that help make it more productive. All the way up to the the most advanced users who really already know AI, but maybe don't wanna be bogged down with doing some of that integration work. We can help with all those components.
Kevin Kiley [00:08:33]:
And so that's usually how we'll sort of progress our dialogue with the client is starting with discovery, providing some security, and then enabling them to do more with AI and to control it.
Jordan Wilson [00:08:44]:
Yeah. It it seems like yeah. We you know, we're kind of referencing the, know, original chat GBT moment. It seemed like, you know, back then, the model was maybe the most important thing. But fast forward to today, it's probably not. It's it's the scaffolding. It's it's the plumbing, you you know, like you talked about. That's extremely important.
Jordan Wilson [00:09:02]:
And another thing that's extremely important is to just call a spade a spade here because I talk to people all the time. I'm sure you hear it. You you know, leaders worried and rightfully so about employees using unauthorized AI tools. Right? Regardless of what report you look at, you know, the stats are all all over the place, sometimes up into the 90% of people using unauthorized AI tools at work. And the worst part is sometimes they're using the free version, which doesn't protect data, and employees aren't always sure of that. So, you know, what are you seeing in terms of shadow AI behavior that maybe worries you the most?
Kevin Kiley [00:09:45]:
It it is often then well intended employee that I mentioned you who, you know, they they they're really trying to move up. They've got a a a mandate to go build their piece of the business and and drive some new product launch or whatever it might be. And, they are not trying to do anything that would undermine security, but they're, of course, giving the agent permissions or maybe it's uploading sensitive data that in their context doesn't look that dangerous. But if a bad actor were to get to it or your competition were to get to it or someone else that could take advantage, that's where the risks really start to get introduced. And, of course, and at the same time, we've got this Cambrian explosion of models. You mentioned already. You know, there's so much innovation happening out there, and so much of it is very positive. But if you look back over this past year, things like deep sea coming out, you don't have to to look far to see all the risk that comes with it.
Kevin Kiley [00:10:35]:
They're they're pretty upfront with their terms and conditions. If you read through the legal agreement, it says you have no guarantee to confidentiality. They're gonna send your data to China and and look. Again, the employee who's trying to just get stuff done maybe isn't taking the time to read through all that. They just know that it this helps them write a better presentation or improve their analysis. These are the sort of things that you've gotta give them tools. It's not enough to just say no. And I think it's almost more dangerous if you try to have some sort of prohibition in place.
Kevin Kiley [00:11:04]:
A lot of companies have started with that. Your your employees are trying to to move quickly. They're trying to make it work. They're gonna find ways around it. So you have to serve something up better that you give them a model set that you can trust or at least a canvas that they can work on where you know you've got some protections in place. That's a
Jordan Wilson [00:11:23]:
good point. And I think also, you know, yes, employees are gonna go out and find a solution if one isn't provided. But sometimes they might find more problems than solution, and maybe they aren't even aware of it. But, you know, one kind of common trend that I saw, especially in 2024, what I referred to as as duct tape AI. Right? When you have different organizations using different models and well, if you don't have a platform that brings it all together, that just might create more work in the long run than it's even worth. You you know, if you're doing a certain task, you know, 30% faster, but you have to rewrite your business processes, it's not gonna lead to a positive ROI. So can you talk a little about, a little bit about because one thing that I love, about Aria is just the platform that allows even people, you know, no code, low code, so kind of regardless of experience level to use any model. Right? So whether you're using an in Prop eight, Google, OpenAI, right, and and keep it in a secure environment.
Jordan Wilson [00:12:21]:
So can you kind of talk about that kind of, like, any model, any skill level approach that you all take?
Kevin Kiley [00:12:27]:
Sure. Absolutely. So, again, back to to all the innovation out there now, 2,000,000 plus models on hunting pace, which is crazy to think about. Crazy. How fast that has exploded and the breadth of options that are out there. And again, a lot of that's really positive. There's innovation. You're gonna find models that are really good at at certain things that you can use and and and bring direct benefits to the business.
Kevin Kiley [00:12:50]:
But all of that means more operational complexity. They're all going through a lot of upgrades. You may get onto a model that gets deprecated sometimes in a matter of months or even weeks after it's released. Of course, there's security vulnerabilities which are continually being discovered and and, you know, having a way to to see those or at least update, manage those is a really important part of all of this as well. So, back to your question again, being able to provide almost like a a a model garden for your employees is an important part of this, where we could serve up a list of models that we consider to be trusted, or perhaps we've already done the procurement work behind the scenes. So you don't have to worry about putting your card in and getting all the different spend that's kinda gone out of control. Let's have a central view into where we're consuming, set budgets, reading thresholds for notifications. These are all capabilities that we can provide within the platform that help bring some insight into, again, how are we using AI? Are we getting good return on it? But also being able to manage this from a a project level, departmental level, which to date has been really difficult to do.
Kevin Kiley [00:13:57]:
And I don't know. I don't wanna accuse the model, providers of deliberately trying to make it kind of opaque, but it certainly is. Each of them have their own consumption models around their tokens, and and you have to set up each one individually. It just creates a lot of operational overhead for, especially a larger company.
Jordan Wilson [00:14:16]:
Yeah. That's and that's a great point because I think it's something, you know, in the chase for, you know, business leaders to always wanna use the latest and greatest model. Right? I see a lot of times sometimes people just boxing themselves in. Right, because you might not think that there's a huge difference between, I don't know, Entropic SONNET four five and, you know, Google Gemini three. Right? But there actually is and there can be. You you know, can you talk a little bit about the modular, kind of setup and why it's important to have a platform that maybe allows you to avoid vendor lock lock in. Right? Because, yeah, like you said, what if a model gets shut down or if all of a sudden a new update causes it to be overly sycophantic or something?
Kevin Kiley [00:15:03]:
Right. Right. Well, the first thing I would I would point to is, again, that there's this arms race of innovation happening right now where month to month, sometimes week to week, you're seeing a new leader take that top benchmark for performance, accuracy. We we've just all continued to be blown away by how quickly the space is evolving. And, it's performance. It's the fact that they may be shedding that old model that you got hooked on, or it may be the cost implications. You know? If you started on Chad g p t four o last year and somehow tried to stay on that, very powerful. And and really, again, it was so exciting when it first came out, but it's also quite expensive.
Kevin Kiley [00:15:45]:
And we've seen that every subsequent release, the cost has fallen significantly. Even going from four to four dot one, I think, was something like a 800, percent difference. Well, massive, amount of change there between, how your token costs were were being incurred. So that continues to happen. And in this space, it's sort of Moore's law in in on steroids where, the cycle times are getting faster and faster. The models are getting more and more powerful, and often the costs are coming down on a token basis. Now there's another level of detail behind, again, how the tokens are consumed, but it's it's you can't deny that the models are getting better. And by and large, they're getting cheaper, for what you need them to do.
Kevin Kiley [00:16:31]:
So being able to stay agile becomes really, really important. I would argue a key part of your organization's AI strategy is making sure that you maintain some some free agency, if you will, to be able to swap as these different large companies battle between each other to deliver a better technology. Keep yourself open so that you can harness the latest and greatest, at the the the most efficient rates. And then the bigger issue of vendor lock in comes into play where they are gonna, of course, be trying to hold you into their ecosystem and and gain more and more leverage, and for every organization. As you build into greater dependency on AI, you have to look at this as a risk, not just from a financial perspective, but also from business continuity. There've been a lot of outages over the last year. I I won't name names, but you can Google most of this. You'll see that most of the major providers had significant outages, sometimes six, ten, twelve hours long.
Kevin Kiley [00:17:29]:
And if you built an application that is business critical or or worse yet, maybe patient critical, and that goes down and now your team is really relying on that for the way that they're working, you've got a really significant problem. The ability to route between models providers, I think, will become, sort of a a standard of care. You have to have that if you really got a credible program.
Jordan Wilson [00:17:59]:
Are you still running in circles trying to figure out how to actually grow your business with AI? Maybe your company has been tinkering with large language models for a year or more, but can't really get traction to find ROI on GenAI. Hey. This is Jordan Wilson, host of this very podcast. Companies like Adobe, Microsoft, and NVIDIA have partnered with us because they trust our expertise in educating the masses around generative AI to get ahead. And some of the most innovative companies in the country hire us to help with their AI strategy and to train hundreds of their employees on how to use Gen AI. So whether you're looking for chat g p t training for thousands or just need help building your front end AI strategy, you can partner with us too, just like some of the biggest companies in the world do. Go to your everydayai.com/partner to get in contact with our team, or you can just click on the partner section of our website. We'll help you stop running in those AI circles and help get your team ahead and build a straight path to ROI on GenAI.
Jordan Wilson [00:19:03]:
Yeah. And that ability, right, it requires a secure sandbox for people to go out test. Right? Because what a lot of people don't realize is you might look at a model like a GPT five one and assume it's the same until you see a GPT five two or a GPT five five, but that's not the case. There's always kind of updates going on under the hood. So can you talk a little bit about the importance of having that secure environment where you can not only constantly test or prepare, you know, in the case that you just brought up, prepare if, hey, a model does go down for six hours, ten hours, twelve hours, have you securely tested the next model up, so to speak? Can you talk a little bit about the importance of that and how you all provide that option?
Kevin Kiley [00:19:50]:
Absolutely. So I think we start by looking at and as you're building a model, have you tested the different models to see which is gonna be most performative for your use case? And we measure that on a number of levels. It could be latency. It could be cost as we talked about. So running the same task or prompt across four or five models to see how they're all gonna compare to each other and then continue to monitor on that basis. The initial exercise will allow you to benchmark them for what you're trying to do and define what your primary model is and then maybe a secondary or a failover or even a third failover, so that in the event that something goes wrong, not only can we detect that, let's say, latency spiking on, Mistral's model or or quad or whatever it is we've used for this, and that is real performance concern. But we know to now route to the next model, which could be from, again, their competition. And so not only is it important to have, I think, the capability to to swap between them that way without having any disruption in service, but the fact that we're not beholden to any one of those companies, I think, becomes a really important value for us, that we partner with all of them and a long list of other open source models that our clients can choose from so that you can trust us to move between them.
Kevin Kiley [00:21:11]:
And if you were just all in on Microsoft or Anthropic or any one of them, Could you really ask them or expect them to route you over to their competition when something goes wrong? I think that's why you need an independent third party company to sit as this sort of front end that they manage.
Jordan Wilson [00:21:29]:
Yeah. I I I liked what you said earlier, kind of the, the the free agent provider. Right? Like, that's important. You know, but so I'm I'm curious because you also mentioned, you know, 2,000,000 models on Hugging Face, and I know even, you know, smaller domain specific models are getting more and more, common and popular in the enterprise. So, you know, I assume this 2,000,000, model, if we talk next year, it's gonna be way more. But that also creates more sprawl. It creates more potential security if you're if you're trying to just do them all individually on your own without using a a a provider. But maybe if we look at it from a a CFO's perspective or a COO's perspective, You know, where does AI sprawl kind of quietly start destroying value before anyone notices? Because, I I I think from people I've heard of, once you notice, it's either not too late, but you've already lost a lot of ground.
Jordan Wilson [00:22:27]:
So where does it start to pop up before anyone really knows?
Kevin Kiley [00:22:31]:
Well, the big problem that has been well documented in a lot of different studies and most recently, there was the MIT, Gen AI divide, I think about the state of AI and business, report. That was really kind of an earthquake across the industry. And I suspect a lot of a lot of your audiences has had a chance to see this or at least read parts of it, where they saw that 95% of these pilots never get to production. And that's staggering when you think about all the money that's being spent and the good intention, behind all the tools that are being purchased and implemented and consultants. You know, it's a lot of waste, unfortunately, that thus far has just not been able to deliver real value to the business. And and I think the number that they put in study was, they ranged in from 30 to $40,000,000,000 worth of investment across the enterprise right now. So, I mean, it it really is just wild to think about how much how much money is is being burned on some of this right now. And that's gotta be front of mind for the CFO is is understanding all this hype, how How much of it is really translating into to value? Are we making good use of the investment?
Jordan Wilson [00:23:43]:
And, you know, we've kind of touched on security a little bit, but I wanna dive a little bit deeper. Right? I'm I'm one that's always, you know, testing out the latest models and and seeing how they work. And if if if I'm being honest, over the last, I don't know, two quarters, seeing what just models are capable of, it's it's it's almost getting to the point where it's like, wow. A single model can do a lot more than an entire system could do, you you know, two years ago or or even eighteen months ago. You know, talk about how quickly security changes on the AI side and, you you know, what business leaders need to know, about, you know, kind of the intersection of agentic AI and security.
Kevin Kiley [00:24:33]:
Well, I think, again, there's so many moving pieces here for security to keep up with, and it really is a new world. The existing stack of security tools and even methodologies that most organizations have in place today just they weren't built for this. They they never contemplated what an agent might be able to do. And so if you think about that, an agent is deliberately given some sort of goal and some autonomy to go accomplish it. It's also gonna be given permission and access, to go touch multiple systems and tools. So it's very, very capable, as we've talked about, you know, already today, sometimes too capable for what it was initially set out to do. If it was given permissions of an individual that may have very broad set of capabilities, that's that's a little scarier, because then security doesn't know who really touched what information, what systems, you've got it running around. There's gonna be a lot of ambiguity about how we lock that down if if the employee leads the organization.
Kevin Kiley [00:25:44]:
Do we know to turn that off when we wanna turn it off? So the whole agentic, paradigm shift here that's happened is a real issue for security. Beyond that, though, AI itself being so powerful, but only when it's prompted correctly is another risk. You know, as we move from APIs, which were very deterministic, and I could call this system and get this bits for these fields to something that is driven by natural language, which is subject to interpretation and can be manipulated. That's a real challenge. You want the AI to be able to understand a command that may be presented in a number of different ways, but that could be deliberately weaponized to try to take advantage of the ambiguity of natural language. And then lastly, if I had to give a third sort of concern around this and and this is at eye level, just that AI enables a scale and a sophistication that wasn't humanly possible before, or wasn't even capable within the boundaries of computing. Now you can have swarms of agents that are going to attack your defenses and instantaneously communicate deficiencies, gaps, vulnerabilities that they're finding with each other to further manipulate those and surge attacks on certain parts of the business or your defenses that never would have been able to be coordinated at that sort of scale or velocity previously. It's very, very scary to think what AI will be capable of doing in the wrong hands.
Kevin Kiley [00:27:24]:
And we're already, again, starting to see some of this As much potential as there is for good and productive outcomes, there's at least as much potential for bad with, those that wanna manipulate it and and come in with malicious intentions.
Jordan Wilson [00:27:38]:
Yeah. And, great you're right. Great example of that. Yeah. There is the recent report, the, Chinese backed, you know, using cloud code. Yeah. This is scary stuff, but just using off the shelf models. Right? It's it's it's not like you have to have the world's most sophisticated, cyberattacks anymore when you can use natural language in off the shelf models.
Jordan Wilson [00:28:01]:
So, you you know, we've covered a ton in today's show, Kevin. I I I, again, I'm stealing the AI spaghetti thing. That's great. But, I'm wondering as we wrap, today's show, if if an enterprise leader right now and they're like, wait. Something you said, this this hits. Clearly, you know, my organization, we're dealing with AI sprawl or, you know, we need to get shadow AI under control. What are the things that you would tell them to do immediately, you know, in the next, you know, couple of weeks, once they realize that sprawl has become a problem within their organization?
Kevin Kiley [00:28:39]:
Well, like, Andy, I think awareness is where it starts. So, the fact that they recognize some of it is great, but truly, investing in the discovery is gonna be critical. So, whether it's technology like ours or using some other methodology to go really identify where AI is being employed across the organization. And those could be vendors that you know about. You may just not know that they've turned on the AI and inside their tool. That's a very common one. Second, there may be other decisions that have been made. Again, in this huge rush to employ AI that a lot of people started pulling out company cards or even expensing work that they were using on other tools.
Kevin Kiley [00:29:20]:
And this is where you start to get into some of the shadow AI. So identifying where the AI is and then applying some protections around it. Again, you may find a lot of this is probably good work that's being done and you want to continue to support that. And if anything, maybe fortify it, make it more durable. But I can guarantee 90% of of the situations
Jordan Wilson [00:29:44]:
you're gonna find AI that you weren't aware of, or you certainly didn't intend for, and that there is real risk behind. Such such great insights, especially timely, right, as as we're looking at, end of year and making everyone's plans into 2026. Kevin, I think you just gave us a a great road map on where we should start to reign AI's for all in. So thank you so much for taking time out of your day to join the Everyday AI Show. We really appreciate it.
Kevin Kiley [00:30:13]:
Jordan, my pleasure. Really, glad to be here today, and and, thank you for the opportunity to to join.
Jordan Wilson [00:30:20]:
Alright. We covered a ton of great, content there. Y'all, if you miss anything, don't worry. We're gonna be recapping everything that Kevin just went over in our newsletter. So if you haven't already, please go to your everydayai.com. Sign up for that free day newsletter. Thanks for tuning in. We'll see you back tomorrow and every day for more everyday AI.
