<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/assets/feed-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Shadow AI Watch</title>
    <description>Independent coverage of workplace AI governance, shadow AI risks, compliance, and enterprise AI policy.</description>
    <link>https://shadowaiwatch.com</link>
    <atom:link href="https://shadowaiwatch.com/feed.xml" rel="self" type="application/rss+xml"/>
    <language>en-AU</language>
    <lastBuildDate>2026-05-21T06:00:00+08:00</lastBuildDate>
    <item>
      <title>California Wants to Ban Employers From Using Worker Data to Train AI That Replaces Their Jobs. The Bill Just Cleared Committee.</title>
      <link>https://shadowaiwatch.com/compliance/california-ab-2027-worker-data-ai-training-ban-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/compliance/california-ab-2027-worker-data-ai-training-ban-2026/</guid>
      <pubDate>2026-05-21T06:00:00+08:00</pubDate>
      <description>AB 2027 would bar employers from using worker data to train AI that replaces their jobs. It cleared committee on 22 April and is now in Appropriations.</description>
      <category>Compliance</category>
    </item>
    <item>
      <title>A Federal Judge Fined Two Oregon Lawyers USD 110,000 for AI-Fabricated Citations. US Courts Imposed at Least USD 145,000 in AI Sanctions in Q1 2026 Alone.</title>
      <link>https://shadowaiwatch.com/compliance/oregon-ai-sanctions-fabricated-citations-legal-governance-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/compliance/oregon-ai-sanctions-fabricated-citations-legal-governance-2026/</guid>
      <pubDate>2026-05-20T06:00:00+08:00</pubDate>
      <description>US courts imposed at least USD 145,000 in AI sanctions in Q1 2026. Oregon's record penalty and per-citation fine formula make AI hallucination costs scalable.</description>
      <category>Compliance</category>
    </item>
    <item>
      <title>Researchers Scanned 380,000 Vibe-Coded Apps. 5,000 Were Leaking Medical Records, Bank Data, and Corporate Documents to the Open Web.</title>
      <link>https://shadowaiwatch.com/shadow-ai/vibe-coded-apps-data-exposure-shadow-ai-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/shadow-ai/vibe-coded-apps-data-exposure-shadow-ai-2026/</guid>
      <pubDate>2026-05-19T06:00:00+08:00</pubDate>
      <description>RedAccess found 5,000 AI-built apps with no authentication leaking patient records, bank data, and corporate documents. Axios and Wired verified the findings.</description>
      <category>Shadow AI</category>
    </item>
    <item>
      <title>Half of All AI Systems Pen Tested by CyberCX Had a Severe Vulnerability. Web Apps Were Half That Rate.</title>
      <link>https://shadowaiwatch.com/research/cybercx-hack-report-2026-ai-pen-test-severe-findings/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/research/cybercx-hack-report-2026-ai-pen-test-severe-findings/</guid>
      <pubDate>2026-05-18T06:00:00+08:00</pubDate>
      <description>CyberCX analysed 70,000+ findings from 7,500+ pen tests. AI systems had severe vulnerabilities at double the rate of web apps. Social engineering won 77%.</description>
      <category>Research</category>
    </item>
    <item>
      <title>AI Just Overtook Immigration and DEI as the Top Workplace Policy Concern for US Employers. 84% Expect Regulatory Impact This Year.</title>
      <link>https://shadowaiwatch.com/research/littler-employer-survey-2026-ai-regulation-governance-gap/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/research/littler-employer-survey-2026-ai-regulation-governance-gap/</guid>
      <pubDate>2026-05-15T06:00:00+08:00</pubDate>
      <description>Littler's 14th Annual Employer Survey: AI is the top policy concern for 84% of US employers, up from 42% in 2025. Only 55% review AI tools pre-deploy.</description>
      <category>Research</category>
    </item>
    <item>
      <title>47% of Workers Are Using AI to Finish Early and Spending the Rest of Their Paid Hours on Personal Activities. Their Employers Have Not Caught On.</title>
      <link>https://shadowaiwatch.com/shadow-ai/novoresume-ai-generated-work-undisclosed-governance-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/shadow-ai/novoresume-ai-generated-work-undisclosed-governance-2026/</guid>
      <pubDate>2026-05-14T06:00:00+08:00</pubDate>
      <description>Novorésumé surveyed 1,000 US workers. 47% use AI to finish early then spend freed time on personal activities. 53% hide their AI use from employers.</description>
      <category>Shadow AI</category>
    </item>
    <item>
      <title>Google Chrome Is Silently Installing a 4GB AI Model on Corporate Laptops. Most IT Teams Have No Idea.</title>
      <link>https://shadowaiwatch.com/shadow-ai/chrome-gemini-nano-silent-install-corporate-governance-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/shadow-ai/chrome-gemini-nano-silent-install-corporate-governance-2026/</guid>
      <pubDate>2026-05-13T06:00:00+08:00</pubDate>
      <description>Chrome downloads a 4GB Gemini Nano model to eligible devices without consent, re-downloads it if deleted, and powers AI features most users have never enabled.</description>
      <category>Shadow AI</category>
    </item>
    <item>
      <title>Bots Now Generate More Internet Traffic Than Humans. AI-Driven Attacks Jumped From 2 Million to 25 Million Per Day in a Year.</title>
      <link>https://shadowaiwatch.com/research/thales-bad-bot-report-2026-ai-agentic-traffic/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/research/thales-bad-bot-report-2026-ai-agentic-traffic/</guid>
      <pubDate>2026-05-12T06:00:00+08:00</pubDate>
      <description>Thales' 2026 Bad Bot Report: 53% of web traffic is automated, bad bots are 40%, AI-driven attacks grew 12.5x, and financial services bore 46% of account takeovers.</description>
      <category>Research</category>
    </item>
    <item>
      <title>Five Eyes Cyber Agencies Just Published the First Multinational Playbook for Securing Agentic AI</title>
      <link>https://shadowaiwatch.com/governance/five-eyes-agentic-ai-security-guidance-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/governance/five-eyes-agentic-ai-security-guidance-2026/</guid>
      <pubDate>2026-05-11T06:00:00+08:00</pubDate>
      <description>Six cyber agencies from the US, UK, Australia, Canada and NZ released joint agentic AI security guidance on 1 May 2026, covering five risk categories.</description>
      <category>Governance</category>
    </item>
    <item>
      <title>APRA Just Told Every Bank, Insurer and Super Fund in Australia That Their AI Controls Are Not Good Enough</title>
      <link>https://shadowaiwatch.com/governance/apra-ai-risk-industry-letter-step-change-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/governance/apra-ai-risk-industry-letter-step-change-2026/</guid>
      <pubDate>2026-05-08T06:00:00+08:00</pubDate>
      <description>APRA's 30 April 2026 industry letter warns AI governance is not keeping pace. The regulator named Mythos and called for a step-change from all regulated entities.</description>
      <category>Governance</category>
    </item>
    <item>
      <title>Senior Leaders at Santander, Lloyds and Revolut Say the UK Has No Shared AI Governance Standard for Financial Services</title>
      <link>https://shadowaiwatch.com/governance/uk-financial-services-ai-governance-gap-zango-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/governance/uk-financial-services-ai-governance-gap-zango-2026/</guid>
      <pubDate>2026-05-07T06:00:00+08:00</pubDate>
      <description>A Zango AI report draws on 27 C-suite interviews and four roundtables with 60 practitioners from major UK and European banks. The US and Singapore have published sector-specific AI governance frameworks. The UK and EU have not.</description>
      <category>Governance</category>
    </item>
    <item>
      <title>The Workers Using AI the Most Are the Ones With the Most Access to Sensitive Data. That Is a Governance Problem.</title>
      <link>https://shadowaiwatch.com/shadow-ai/ft-focaldata-ai-adoption-divide-high-earners-governance-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/shadow-ai/ft-focaldata-ai-adoption-divide-high-earners-governance-2026/</guid>
      <pubDate>2026-05-06T06:00:00+08:00</pubDate>
      <description>An FT-Focaldata poll of 4,000 US and UK workers found over 60% of top earners use AI daily versus 16% of lowest earners. The people with the most autonomy, the most seniority, and the broadest access are adopting AI fastest, with the least oversight.</description>
      <category>Shadow AI</category>
    </item>
    <item>
      <title>The DOJ Just Backed Elon Musk's xAI Against Colorado's AI Discrimination Law. Compliance Teams Should Keep Building Anyway.</title>
      <link>https://shadowaiwatch.com/compliance/doj-xai-colorado-ai-act-constitutional-challenge-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/compliance/doj-xai-colorado-ai-act-constitutional-challenge-2026/</guid>
      <pubDate>2026-05-05T06:00:00+08:00</pubDate>
      <description>The US Department of Justice intervened in xAI's constitutional challenge to Colorado SB24-205 on 24 April 2026, calling the state's algorithmic discrimination requirements unconstitutional. The law's 30 June 2026 compliance date has not changed.</description>
      <category>Compliance</category>
    </item>
    <item>
      <title>EU AI Act Delay Talks Collapsed. The 2 August 2026 High-Risk Deadline Is Back.</title>
      <link>https://shadowaiwatch.com/compliance/eu-ai-act-omnibus-collapse-august-2026-deadline-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/compliance/eu-ai-act-omnibus-collapse-august-2026-deadline-2026/</guid>
      <pubDate>2026-05-04T06:00:00+08:00</pubDate>
      <description>Twelve hours of EU trilogue negotiations broke down on 28 April 2026 without agreement on the Digital Omnibus reforms. The original 2 August 2026 deadline for high-risk AI systems and Article 50 transparency obligations is still in force. Compliance teams that were banking on an extension need to change course.</description>
      <category>Compliance</category>
    </item>
    <item>
      <title>The FTC Has Quietly Built an AI Enforcement Playbook. A Dozen Cases in 2025 Show What Comes Next.</title>
      <link>https://shadowaiwatch.com/compliance/ftc-ai-enforcement-playbook-section-5-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/compliance/ftc-ai-enforcement-playbook-section-5-2026/</guid>
      <pubDate>2026-05-01T06:00:00+08:00</pubDate>
      <description>The FTC brought at least 12 AI-related enforcement actions in 2025, targeting deceptive capability claims, undisclosed automated decisions, and AI-generated fake content. Section 5 of the FTC Act is doing the work that AI-specific legislation has not.</description>
      <category>Compliance</category>
    </item>
    <item>
      <title>The UK Just Made an AI Code of Practice a Legal Requirement. The ICO Has No Choice but to Write One.</title>
      <link>https://shadowaiwatch.com/compliance/uk-ico-ai-adm-code-of-practice-si-2026-425/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/compliance/uk-ico-ai-adm-code-of-practice-si-2026-425/</guid>
      <pubDate>2026-04-30T06:00:00+08:00</pubDate>
      <description>A new statutory instrument requires the UK Information Commissioner to produce a formal code of practice on AI and automated decision-making. SI 2026/425 comes into force on 12 May 2026 and includes mandatory guidance on children's data.</description>
      <category>Compliance</category>
    </item>
    <item>
      <title>A Vercel Employee Installed a Consumer AI Tool. It Cost the Company a Supply-Chain Breach Now on Sale for USD 2 Million.</title>
      <link>https://shadowaiwatch.com/shadow-ai/vercel-context-ai-breach-shadow-ai-supply-chain-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/shadow-ai/vercel-context-ai-breach-shadow-ai-supply-chain-2026/</guid>
      <pubDate>2026-04-29T06:00:00+08:00</pubDate>
      <description>Vercel was breached through Context.ai, a consumer AI productivity tool connected to a single employee's Google Workspace with 'Allow All' OAuth permissions. Stolen data is now listed on BreachForums for USD 2 million. The kill chain started with a Roblox cheat download.</description>
      <category>Shadow AI</category>
    </item>
    <item>
      <title>Canada Is Spending $890 Million to Build a Sovereign AI Supercomputer. The Governance Signal Is Bigger Than the Hardware.</title>
      <link>https://shadowaiwatch.com/governance/canada-sovereign-ai-compute-infrastructure-program-2026/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/governance/canada-sovereign-ai-compute-infrastructure-program-2026/</guid>
      <pubDate>2026-04-28T06:00:00+08:00</pubDate>
      <description>Canada's AI Sovereign Compute Infrastructure Program opened applications on 15 April 2026. The $890 million investment turns data residency and provider jurisdiction from abstract risks into funded infrastructure decisions.</description>
      <category>Governance</category>
    </item>
    <item>
      <title>The FBI's 2025 Internet Crime Report Puts AI-Enabled Fraud at USD 893 Million. That Number Is a Floor, Not a Ceiling.</title>
      <link>https://shadowaiwatch.com/research/fbi-ic3-2025-ai-enabled-fraud-893-million/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/research/fbi-ic3-2025-ai-enabled-fraud-893-million/</guid>
      <pubDate>2026-04-24T06:00:00+08:00</pubDate>
      <description>The FBI's IC3 logged 22,364 AI-related complaints with losses exceeding USD 893 million in 2025. It is the first time the annual report includes a dedicated AI section. Enterprise risk frameworks need to catch up.</description>
      <category>Research</category>
    </item>
    <item>
      <title>Stanford's 2026 AI Index: Incidents Up 55%, Transparency Index Falls 18 Points, and Adoption at 88%. The Governance Maths Are Getting Worse.</title>
      <link>https://shadowaiwatch.com/research/stanford-ai-index-2026-incidents-transparency-governance/</link>
      <guid isPermaLink="true">https://shadowaiwatch.com/research/stanford-ai-index-2026-incidents-transparency-governance/</guid>
      <pubDate>2026-04-23T06:00:00+08:00</pubDate>
      <description>Stanford HAI's 2026 AI Index shows AI incidents rose from 233 to 362, the Foundation Model Transparency Index dropped from 58 to 40, and organisational adoption hit 88%. The gap between capability and accountability is widening.</description>
      <category>Research</category>
    </item>
  </channel>
</rss>
