AI's role in cybersecurity spans attacks, defense, and a third area few teams watch: AI now runs inside vendor tools and configs across the supply chain, invisible to most security programs. Vendor ratings don't measure this. Proximity to your systems does.
The role of AI in cybersecurity today spans three areas: helping attackers, helping defenders, and increasingly operating inside third-party software and digital supply chains. While most discussions focus on the first two, organizations are also inheriting AI-related risk through vendors, SaaS platforms, and external dependencies.
That third part is the one most 2026 coverage skips. Verizon's 2026 Data Breach Investigations Report found that shadow AI detections in enterprise DLP data increased fourfold year over year. IBM's 2025 Cost of a Data Breach Report found that one in five organizations experienced a breach related to shadow AI, and organizations with high levels of shadow AI incurred an average of about $670,000 more in breach costs.
What is AI in cybersecurity?
AI in cybersecurity refers to the use of artificial intelligence to detect threats, automate analysis, support security operations, identify vulnerabilities, and increasingly manage cyber risk introduced by third-party software and digital supply chains. Learn why external dependencies increase supply chain risk.
AI is already an attacker's tool
Attackers use generative models to write phishing emails in a target's own language and tone, and to generate malware variants faster than signature-based tools can keep pace with.
HiddenLayer's 2026 AI Threat Landscape Report documents deepfakes, AI-enabled fraud, and supply chain incidents tied to AI systems across hundreds of organizations, along with a jailbreak technique that got past safety guardrails on several frontier models. The report's framing is blunt: AI is shifting from a tool people operate to something that increasingly acts on its own, while most security programs are still built for static software rather than systems that plan and act unsupervised.
Prompt injection and model manipulation belong in this category too. An AI system wired into internal documentation or a customer-facing chatbot can, if poorly secured, be talked into revealing far more than it was meant to. Security teams are already responding to real incidents like this, logged in breach reports rather than left as a theoretical concern.
AI is also becoming a defender's tool
AI can read unstructured data at a scale no analyst team could match on its own, the kind of buried detail that hides a hardcoded credential or an exposed production endpoint inside a deployment script nobody reviews line by line.
ThingsRecon's own Smart Findings feature works this way, with AI agents reading the actual content of files discovered across a vendor's exposed infrastructure rather than matching known patterns against structured metadata. The broader industry's AI-powered ratings and threat intelligence tools do something adjacent: faster scoring, quicker CVE triage, more automated first-pass analysis.
That's useful, and it's still only half the picture. None of it tells you where AI itself is running inside the vendors you depend on, only what AI can help you find once you're already looking in the right place.
Where does shadow AI actually show up in a supply chain?
It shows up in signals most vendor questionnaires never ask about: a chatbot running on a subdomain nobody registered, or a configuration file leaking a variable that points straight at a model provider. Both are visible from the outside, the same way any other misconfigured asset is, if you know where to look.
Some of it is straightforward once you're looking for it. A chatbot embedded in a vendor's website is a strong signal that a model sits behind it, and that model is usually connected to other systems worth mapping. Configuration files leaked through a misconfigured server sometimes carry the plainest evidence of all: a variable name pointing directly at a model provider.
Earlier this year, a routine scan turned up a vendor that had left an entire directory of trained customer models sitting unprotected on a misconfigured subdomain, reachable by anyone who followed standard subdomain enumeration to the right path. No breach was reported. No questionnaire would have caught it, because the vendor likely didn't know the directory was exposed either.
The bigger shift is who can introduce this risk. Shadow IT used to be a developer's problem: someone spinning up an unsanctioned server or leaving credentials in a public repository. Shadow AI doesn't require a developer. Connecting an API key to a chatbot or a workflow tool takes nothing more than being able to describe what you want in plain language, and that stretches the population capable of creating exposure across nearly every function at a vendor, engineering included. It's the same shift covered in why external dependencies increase supply chain risk: more connections, more of them undocumented, and now more of them AI.
Why doesn't a vendor's security rating capture this?
A security rating scores a vendor in the abstract: patch cadence and certificate hygiene, averaged into a single letter or number. It says nothing about how that vendor is wired into your specific systems, or whether the AI tool it just adopted sits three integrations away from your customer data, or ten.
Your supplier got an A. So why were you breached already covers why a strong rating and a bad outcome can coexist. AI adds a fresh version of the same gap. A vendor can score well on paper and still run an unsanctioned AI tool that touches shared data, because TPRM questionnaires are usually filled in once and rarely revisited, while AI adoption inside a vendor's business can shift week to week.
What matters isn't a vendor's AI use as an isolated fact about that vendor. It's how close that use sits to the systems you depend on, which is the logic behind the proximity metric ThingsRecon built. A global score couldn't capture it, and it’s part of why supply chain intelligence keeps getting treated as something separate from TPRM, EASM, and GRC rather than a feature bolted onto one of them.
How should organizations manage AI cybersecurity risk?
A few things help more than a longer questionnaire.
- Ask vendors what AI they run, then verify externally. A questionnaire answer reflects what a vendor believes today, not what someone in its marketing team connected to a chatbot last week.
- Prioritize by proximity, not by how many vendors mention AI in their materials. A vendor with unmanaged AI three hops from your customer database matters more than one with the same issue sitting far outside your core systems.
- Expect the surface to keep growing on its own. Gartner projects that by 2028, 90 percent of B2B buying will run through AI-agent intermediated transactions, which pushes procurement itself toward becoming another AI surface worth watching, not only the tools vendors already run in production.
The role of AI in cybersecurity is no longer limited to helping attackers or defenders. AI has become part of the digital supply chain itself. Organizations that only evaluate vendor security posture may miss where AI is actually connected to their critical systems. Understanding those relationships, not just vendor ratings, is becoming essential to managing cyber risk.
Key takeaways
- AI in cybersecurity now affects attacks, defense, and supply chains.
- Shadow AI often appears inside third-party vendors.
- Vendor ratings don't measure AI exposure.
- Digital proximity helps prioritize AI-related supply chain risk.
- Organizations should continuously verify external AI exposure instead of relying only on questionnaires.


