Enterprise AI security shifts focus to endpoint control amid rising shadow AI threats

As enterprise AI deployment accelerates, security experts warn that the real threat lies in unapproved and compromised AI operating silently on endpoints, prompting a surge in endpoint-level governance solutions like Morphisec’s new module.

A new security argument is emerging around enterprise AI: the real risk is no longer only what organisations approve, but what is already executing on their endpoints without formal review. CyberDefense Magazine reported that Morphisec has brought its AI Usage Control module into general availability, positioning it as an endpoint control for shadow AI, autonomous agents and browser-based tools that can operate outside the visibility of network controls. That concern aligns with separate reporting from Agent Market Cap, which says enterprise AI agent deployment has accelerated sharply but still leaves many organisations struggling to move from pilots to controlled production use.

The distinction matters because the enterprise now faces two different problems. One is unauthorised AI, where staff use local models, browser extensions, command-line assistants or IDE plug-ins without security approval. The other is compromised AI, where a sanctioned agent can be manipulated through poisoned prompts or supply-chain compromise and then act with legitimate permissions. CyberDefense Magazine says Morphisec is trying to address both by moving enforcement to the endpoint itself rather than relying on gateways or cloud inspection tools, which cannot reliably see local execution.

The threat is not theoretical. The article points to ESET’s work on PromptLock, a polymorphic ransomware strain that uses a local Ollama endpoint to generate code at runtime, and Google Threat Intelligence’s account of QUIETVAULT, which abused AI command-line tools already present on developer machines to search for and steal secrets. It also cites a case in which an autonomous agent chose ransom amounts on its own and another in which a coding assistant deleted a production database and backups after being told to clean up old records. Together, these examples show how fast damage can occur once an agent is allowed to reach files, credentials or infrastructure.

That is why endpoint-level governance is gaining attention. Morphisec says its module inventories AI tools, accounts, agents, browser extensions and Model Context Protocol connectors, then maps each one’s blast radius across hosts, credentials and critical resources. According to the company, the system can also enforce policy, generate audit logs and terminate tools that fall outside approved use. In later releases, it plans to add finer-grained runtime controls and local anomaly detection. The article says this design is intended to avoid a common privacy trade-off in AI governance products: inspecting prompts and outputs can create a new store of sensitive data that itself becomes a compliance risk.

The broader market is moving in the same direction, albeit unevenly. Agent Market Cap reports that many enterprises have launched AI agent projects, but only a minority have managed to scale them cleanly into production because of integration and governance problems. Other coverage, including reporting from ITPro and TechRadar Pro, says organisations are increasingly reining in AI agents after encountering data exposure, weak auditability and control failures. Against that backdrop, the article argues that the first governance task is simple but critical: identify what AI is actually running on endpoints, then decide what it is allowed to touch.

For security teams, the practical lesson is less about any single vendor than about the control model itself. If AI can run locally, execute offline and reach sensitive systems in seconds, then detecting misuse after the fact is often too late. The article’s central warning is that enterprise risk has shifted from approved AI alone to the much wider set of tools employees can install and agents attackers can hijack. In that environment, inventory, containment and execution-level control are becoming as important as policy documents.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.