ProBackend
agent sprawl and shadow ai
1 hour ago4 min read

AI Code Sprawl: How Security Leaders are Taming 'Vibe Coding' Risks

As AI enables faster, more accessible code creation, security leaders face a new visibility crisis. We explore how CISOs at Datadog, Jamf, and ASOS are pivoting from gatekeepers to enablers to manage the ungoverned spread of 'vibe coding'.

Shadow AI and the New Reality of Code-Writing Employees

Employees are writing code, and they’re not all developers. It’s the era of "vibe coding," where AI tools—from chatbots to specialized autonomous agents—offer non-engineers the intoxicating ability to solve problems, build applications, and deploy assets with a handful of prompts. It sounds like a productivity miracle, but beneath the surface, there’s a quiet visibility crisis unfolding. Security teams are, in many cases, essentially flying blind.

"I spent the weekend burning through assets" is not something a CISO wants to hear, but it’s becoming the new reality when assets are spun up without any formal security review. Data from a recent RedAccess report (as highlighted in our source material) shows a staggering 380,000 publicly accessible assets—from databases to applications—built completely outside of traditional security oversight. Even worse, 5,000 of those contain sensitive corporate data. This isn't just about sloppy code; it’s about a massive expansion of the attack surface, driven by autonomous capabilities that are now in everyone's hands.

Addressing AI Cybersecurity Governance: What It Actually Means

So, what is AI governance in this context? It’s not just a collection of policies that employees rarely read and even more rarely follow. AI cybersecurity governance is the active, continuous framework an organization implements to ensure that the adoption of AI—whether by engineers or business users—is safe, compliant, and visible.

At its core, it’s about moving from a "gatekeeper" model, where security sits in the middle of everything and inevitably slows things down, to an "enablement" model. It’s about codifying security into the fabric of the organization so that the right way to do things is also the easiest way to do them. Without this, you're not just dealing with shadow IT; you're dealing with shadow intelligence—autonomous agents acting on behalf of employees without anyone knowing, or knowing whether that access is justified.

addressing ai cybersecurity governance

Addressing AI Cybersecurity Governance: What It Actually Means

Why Traditional Governance Fails in the Agentic Age

The fundamental issue is that traditional, paper-based governance simply wasn't designed for this velocity. When an employee can build and deploy an agent in five minutes, a two-week security review process—or even a one-day one—is fundamentally broken.

Employees will naturally move to channels that don’t bottleneck their productivity. If security represents a roadblock, it will be skipped entirely. This is human nature as much as it is a technology problem. When employees realize they can "vibe code" a solution that connects to a database, they might not worry about access controls, encryption, or auditing. The result is the current sprawl—systems running without authorization, without visibility, and without a plan for decommissioning when the project ends. This sprawl is inherently dangerous because, at some point, these agents will likely be compromised or misconfigured, and they will become the entry points for the next big breach.

traditional governance fails in the agentic age

Why Traditional Governance Fails in the Agentic Age

Strategies for CISO Teams: From Gatekeepers to Enablers

The CISOs at companies like Datadog, Jamf, and ASOS are realizing that they have to pivot. They’re abandoning the "no-button" approach in favor of being a hub that facilitates secure, productive use of AI.

This means providing the business with a marketplace of approved, vetted tools. If employees have a safe set of tools that help them build what they need, they’re far less likely to search for unauthorized alternatives that compromise the perimeter. Security teams need to curate these toolsets and provide clear, simple guidance on how to use them—essentially creating a "tutorial" for safe AI adoption.

Building Traceability for Autonomous Agents

Maybe the most critical part of this modernization is traceability. An agent shouldn't just be an anonymous process in the cloud; it must be treated like any other infrastructure asset.

A CISO should insist on a "use-case registry" that tracks these deployments. This is where AI governance gets practical. Each agent needs to be mapped to a human identity and a clear business purpose. Who built this? What data does it access? Why does it need that access? These simple questions are often the hardest to answer when you don't have this level of traceability. If an incident involving an autonomous agent occurs, you need to know exactly where to go and who to talk to, immediately.

Aligning Practices with Established Security Frameworks

We don't need to reinvent the wheel here. Organizations should, and must, align their agent and AI management practices with established security frameworks.

The NIST AI Risk Management Framework (nist.gov) provides a solid foundation for thinking about the risks inherent in autonomous systems. Similarly, referring to standard application vulnerability awareness resources (such as those from owasp.org) is essential when you're looking at code sprawl. These frameworks aren't just from compliance; they are the baseline for what constitutes acceptable risk.

The agentic age is here. It’s moving fast, and it’s tempting to try and lock everything down. But the only way forward is to embrace the speed while building the visibility, traceability, and governance that keep the organization secure. We’ve managed technology shifts before; we can manage this one too—if we stop acting as gatekeepers and start acting as architects of a secure, agentic future.

More blogs