The riskiest AI in your estate this quarter was not smuggled in by an employee. It arrived in a release note, on schedule, with the toggle already flipped.

Why Default-On Shadow AI Matters Now

The standard shadow AI story has an employee as the protagonist: a marketer pasting a customer list into a chatbot, or an engineer wiring an unapproved coding agent into a repo. That story is still true. But it is no longer where most of the new exposure comes from.

The faster-moving source is your vendors. Over the last two quarters, SaaS platforms you already approved have moved AI and agent capabilities from opt-in to opt-out, and in some cases to no opt at all. Nobody on your team made a decision. The change came in with the release calendar.

Metric Value Source
Organizations reporting a breach involving shadow AI ~1 in 5 IBM Cost of a Data Breach Report 2025
Added breach cost where shadow AI was a factor up to +$670K IBM Cost of a Data Breach Report 2025
Breached organizations with no AI governance policy, or one still in development 63% IBM Cost of a Data Breach Report 2025

Price those numbers against a default-on rollout and the math changes. The exposure doesn’t grow when someone breaks policy. It grows on the vendor’s timeline, across every tenant at once.

Two Sources of Shadow AI, Two Risk Profiles

We have split shadow agents into two types before: the ones employees install and the ones embedded in software you already run. The vendor-enabled kind belongs to the second type, and it behaves differently on every axis a risk desk cares about.

Dimension Employee-introduced shadow AI Vendor-enabled shadow AI
Trigger An individual decision A release note or rollout wave
Correlation Idiosyncratic, one user at a time Systematic, every tenant on the same date
Visibility Endpoint and network signals Arrives inside an already-approved app
Policy lever Acceptable-use policy, training Admin console, if a setting still exists
Procurement review Bypassed Already cleared, for a product that has since changed
Blast radius One user’s data The whole data set the SaaS platform holds

The correlation row is the important one. Employee shadow AI is a scattered tail. Vendor-enabled shadow AI is a single systematic factor that hits the whole book at once.

Anatomy of a Default-On Rollout

The public record from the last few months shows a repeatable pattern:

  1. Salesforce Agentforce. For Winter ‘27, Salesforce says it will auto-enable Agentforce in all orgs with Agentforce access. Existing orgs are being enabled on a rolling basis starting in September, and the Agentforce toggle on the Agents setup page is scheduled for removal. Admins can still turn off the Einstein setting, which shuts the platform off. That is a coarser switch than before, and it now takes an active decision. (Source: Salesforce Winter ‘27 release notes, as reported by Salesforce Ben.)
  2. Zendesk AI agent tickets. Zendesk switched AI agent tickets on by default for some Pods in February 2026 and let customers turn them off until May 4, 2026. After that date the feature is on for most customers and cannot be turned off. (Source: Zendesk help center announcement.)
  3. DocuSign. DocuSign’s recent eSignature release notes describe envelope-sharing APIs that are on by default for every account, and the only way to disable them is a Support ticket. The pattern is the same even though this feature isn’t an AI agent: capability ships on, and the off switch is outside your admin console.
  4. The sequence. A feature announced as opt-in becomes default-on with an opt-out window. The window closes, the setting leaves the UI, and the capability becomes part of the product you already bought.

Look at step 4 on its own terms. The procurement decision you made eighteen months ago is being marked to a product that no longer exists in that form.

The Vendor Drift Formula

Here’s how to put a number on it. Score each approved SaaS platform on four factors, each from 1 to 5:

Vendor Drift Exposure = (Default-On Velocity × Data Gravity) + (Control Erosion × Detection Lag)

Factor What it measures How to score it
Default-On Velocity How often the vendor ships AI capability enabled by default Count of default-on AI releases in the trailing 12 months
Data Gravity Sensitivity and volume of data the platform holds Customer PII, contracts and financials score high
Control Erosion Whether the off switch is getting coarser or disappearing Granular toggle = 1; platform-wide kill switch = 3; ticket-only or none = 5
Detection Lag Time between a change shipping and your team noticing Days from release note to a confirmed inventory update

Rank your top twenty SaaS vendors by this score. The top five are your real shadow AI program, whatever the acceptable-use policy says.

What Detection Actually Requires

Most answers to “how to detect shadow AI” are tuned for the employee version: CASB logs, browser DLP, proxy rules. Those tools are blind to a capability that ships inside a domain you already allow. The SaaS-embedded seam is where they stop working.

Control point Catches employee shadow AI Catches vendor-enabled shadow AI
CASB / proxy allowlists Partially No. Same domain, new behavior
Browser DLP on prompts Partially No. The agent runs server-side or in the native client
Vendor admin consoles No Only while the setting still exists
Release-note monitoring No Yes, if someone reads them weekly
Endpoint-level agent observability Yes Yes, for desktop clients and local agent processes touching your data

The honest answer is that no single layer covers both. A layered agent governance program runs vendor change tracking as a feed, not an annual review. It pairs that feed with endpoint telemetry that sees what actually executes, whichever vendor put it there.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Pull the last 12 months of release notes for your top 20 SaaS vendors Default-on AI change log 1 analyst-week
2 Score each vendor on the Vendor Drift formula Ranked exposure book 2 days
3 Add “AI default posture and off-switch granularity” to renewal and procurement terms Contract language for next renewals 1 legal review cycle
4 Stand up endpoint discovery for agents and AI clients Live inventory against which to reconcile vendor changes (what CISOs see in week one) 2 weeks

The Bottom Line

Shadow AI is no longer mainly an employee behavior problem. It is a vendor release-calendar problem. The exposure is correlated, it lands inside approved software, and the controls to reverse it get coarser with every rollout wave. The CISOs who handle this well will treat vendor AI defaults as a position to mark weekly, not a procurement checkbox.

If your team is sizing this for the Q4 planning cycle, request a working session. We will walk through your SaaS estate, build your first Vendor Drift exposure ranking, and scope an agent firewall deployment for the endpoints where these capabilities actually execute. Budget 90 minutes.