<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ShadowIT on My Thought Garden</title>
    <link>https://thought-garden.pages.dev/blog/shadowit/</link>
    <description>Recent content in ShadowIT on My Thought Garden</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    
    
    
    
    <lastBuildDate>Sun, 01 Feb 2026 00:00:00 +0000</lastBuildDate>
    
    
    <atom:link href="https://thought-garden.pages.dev/blog/shadowit/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Shadow Stack Reality</title>
      <link>https://thought-garden.pages.dev/draft/shadow-stack-reality/</link>
      <pubDate>Sun, 01 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://thought-garden.pages.dev/draft/shadow-stack-reality/</guid>
      <description>&lt;p&gt;You have an AI strategy. Your employees just haven&amp;rsquo;t told you what it is yet.&lt;/p&gt;&#xA;&lt;p&gt;I speak to CISOs who tell me, &amp;ldquo;We aren&amp;rsquo;t deploying GenAI yet. We blocked ChatGPT.&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;Here is the hard truth: &lt;strong&gt;Blocking ChatGPT doesn&amp;rsquo;t stop GenAI. It just drives it underground.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;While you draft policies in the boardroom, your engineers are pasting code into personal LLMs to meet deadlines. Your marketing team is using unvetted tools to generate copy. Your HR team is summarizing sensitive resumes in the cloud.&lt;/p&gt;&#xA;&lt;p&gt;This is the &lt;strong&gt;Shadow AI Stack&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;It is invisible, unmonitored, and completely bypasses your &amp;ldquo;block.&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;The goal of AI Security cannot be &amp;ldquo;prevention&amp;rdquo;—that ship has sailed. The goal must be &lt;strong&gt;Visibility&lt;/strong&gt; and &lt;strong&gt;Safe Enablement&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;Acknowledge the demand&lt;/strong&gt; (People want to work faster).&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Provide the paved road&lt;/strong&gt; (Give them a secure enterprise alternative).&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Monitor the edges&lt;/strong&gt; (Watch for data exfiltration, not just URL access).&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;You can&amp;rsquo;t secure what you refuse to see.&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>