The riskiest AI in your estate this quarter was not smuggled in by an employee. It arrived in a release note, on schedule, with the toggle already flipped.
Why Default-On Shadow AI Matters Now
The standard shadow AI story has an employee as the protagonist: a marketer pasting a customer list into a chatbot, or an engineer wiring an unapproved coding agent into a repo. That story is still true. But it is no longer where most of the new exposure comes from.
The faster-moving source is your vendors. Over the last two quarters, SaaS platforms you already approved have moved AI and agent capabilities from opt-in to opt-out, and in some cases to no opt at all. Nobody on your team made a decision. The change came in with the release calendar.
| Metric | Value | Source |
|---|---|---|
| Organizations reporting a breach involving shadow AI | ~1 in 5 | IBM Cost of a Data Breach Report 2025 |
| Added breach cost where shadow AI was a factor | up to +$670K | IBM Cost of a Data Breach Report 2025 |
| Breached organizations with no AI governance policy, or one still in development | 63% | IBM Cost of a Data Breach Report 2025 |
Price those numbers against a default-on rollout and the math changes. The exposure doesn’t grow when someone breaks policy. It grows on the vendor’s timeline, across every tenant at once.
Two Sources of Shadow AI, Two Risk Profiles
We have split shadow agents into two types before: the ones employees install and the ones embedded in software you already run. The vendor-enabled kind belongs to the second type, and it behaves differently on every axis a risk desk cares about.
| Dimension | Employee-introduced shadow AI | Vendor-enabled shadow AI |
|---|---|---|
| Trigger | An individual decision | A release note or rollout wave |
| Correlation | Idiosyncratic, one user at a time | Systematic, every tenant on the same date |
| Visibility | Endpoint and network signals | Arrives inside an already-approved app |
| Policy lever | Acceptable-use policy, training | Admin console, if a setting still exists |
| Procurement review | Bypassed | Already cleared, for a product that has since changed |
| Blast radius | One user’s data | The whole data set the SaaS platform holds |
The correlation row is the important one. Employee shadow AI is a scattered tail. Vendor-enabled shadow AI is a single systematic factor that hits the whole book at once.
Anatomy of a Default-On Rollout
The public record from the last few months shows a repeatable pattern:
- Salesforce Agentforce. For Winter ‘27, Salesforce says it will auto-enable Agentforce in all orgs with Agentforce access. Existing orgs are being enabled on a rolling basis starting in September, and the Agentforce toggle on the Agents setup page is scheduled for removal. Admins can still turn off the Einstein setting, which shuts the platform off. That is a coarser switch than before, and it now takes an active decision. (Source: Salesforce Winter ‘27 release notes, as reported by Salesforce Ben.)
- Zendesk AI agent tickets. Zendesk switched AI agent tickets on by default for some Pods in February 2026 and let customers turn them off until May 4, 2026. After that date the feature is on for most customers and cannot be turned off. (Source: Zendesk help center announcement.)
- DocuSign. DocuSign’s recent eSignature release notes describe envelope-sharing APIs that are on by default for every account, and the only way to disable them is a Support ticket. The pattern is the same even though this feature isn’t an AI agent: capability ships on, and the off switch is outside your admin console.
- The sequence. A feature announced as opt-in becomes default-on with an opt-out window. The window closes, the setting leaves the UI, and the capability becomes part of the product you already bought.
Look at step 4 on its own terms. The procurement decision you made eighteen months ago is being marked to a product that no longer exists in that form.
The Vendor Drift Formula
Here’s how to put a number on it. Score each approved SaaS platform on four factors, each from 1 to 5:
Vendor Drift Exposure = (Default-On Velocity × Data Gravity) + (Control Erosion × Detection Lag)
| Factor | What it measures | How to score it |
|---|---|---|
| Default-On Velocity | How often the vendor ships AI capability enabled by default | Count of default-on AI releases in the trailing 12 months |
| Data Gravity | Sensitivity and volume of data the platform holds | Customer PII, contracts and financials score high |
| Control Erosion | Whether the off switch is getting coarser or disappearing | Granular toggle = 1; platform-wide kill switch = 3; ticket-only or none = 5 |
| Detection Lag | Time between a change shipping and your team noticing | Days from release note to a confirmed inventory update |
Rank your top twenty SaaS vendors by this score. The top five are your real shadow AI program, whatever the acceptable-use policy says.
What Detection Actually Requires
Most answers to “how to detect shadow AI” are tuned for the employee version: CASB logs, browser DLP, proxy rules. Those tools are blind to a capability that ships inside a domain you already allow. The SaaS-embedded seam is where they stop working.
| Control point | Catches employee shadow AI | Catches vendor-enabled shadow AI |
|---|---|---|
| CASB / proxy allowlists | Partially | No. Same domain, new behavior |
| Browser DLP on prompts | Partially | No. The agent runs server-side or in the native client |
| Vendor admin consoles | No | Only while the setting still exists |
| Release-note monitoring | No | Yes, if someone reads them weekly |
| Endpoint-level agent observability | Yes | Yes, for desktop clients and local agent processes touching your data |
The honest answer is that no single layer covers both. A layered agent governance program runs vendor change tracking as a feed, not an annual review. It pairs that feed with endpoint telemetry that sees what actually executes, whichever vendor put it there.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Pull the last 12 months of release notes for your top 20 SaaS vendors | Default-on AI change log | 1 analyst-week |
| 2 | Score each vendor on the Vendor Drift formula | Ranked exposure book | 2 days |
| 3 | Add “AI default posture and off-switch granularity” to renewal and procurement terms | Contract language for next renewals | 1 legal review cycle |
| 4 | Stand up endpoint discovery for agents and AI clients | Live inventory against which to reconcile vendor changes (what CISOs see in week one) | 2 weeks |
The Bottom Line
Shadow AI is no longer mainly an employee behavior problem. It is a vendor release-calendar problem. The exposure is correlated, it lands inside approved software, and the controls to reverse it get coarser with every rollout wave. The CISOs who handle this well will treat vendor AI defaults as a position to mark weekly, not a procurement checkbox.
If your team is sizing this for the Q4 planning cycle, request a working session. We will walk through your SaaS estate, build your first Vendor Drift exposure ranking, and scope an agent firewall deployment for the endpoints where these capabilities actually execute. Budget 90 minutes.