Shadow AI in production
CISO · public fintech
Six product teams shipped LLM features in a quarter — three never went through security review. Nobody had a list of every model, key, and downstream endpoint actually in use.
AIOStack discovered 41 distinct LLM-calling workloads from kernel traffic alone — including a customer-support summarizer routing transcripts to a personal OpenAI key, and an Anthropic call buried inside a vendor SDK.
- 41 AI workloads inventoried in 36 hours
- 3 unsanctioned providers retired the same week
- 0 code changes, 0 developer interrupts