Why Shadow AI Is a Governance Problem for Malaysian EnterprisesWhy Shadow AI Is a Governance Problem for Malaysian EnterprisesWhy Shadow AI Is a Governance Problem for Malaysian EnterprisesWhy Shadow AI Is a Governance Problem for Malaysian Enterprises
  • SERVICES
    • MANAGED SERVICES
      • Managed Detection and Response
      • Mobile Threat Defense
      • Security Intelligence
      • Incident Response
      • Digital Risk Protection
    • PROFESSIONAL SERVICES
      • Emergency Incident Response
      • Vulnerability Assessment
      • Penetration Testing
      • Compromise Assessment
      • Red Teaming
    • SOLUTIONS
      • Email Security
      • Endpoint Management
      • Breach and Attack Simulation
      • Third-Party Risk Management
      • Attack Surface Management
  • RESOURCES
    • Blog & News
  • COMPANY
    • About Us
    • Careers
    • Contact
  • Call us +603 5870 2252
GET IN TOUCH
✕
Shadow AI
5 October 2026

Why Shadow AI Is a Governance Problem for Malaysian Enterprises

Shadow AI

Your Mobile Device Management (MDM) policy covers the device. It says nothing about what an app on that device is quietly sending to an AI model hosted somewhere else.

That gap has a name now, Shadow AI, and Zimperium’s 2026 Global Mobile Threat Report puts real numbers behind how large it already is. In this article, we break down what Shadow AI actually looks like on mobile, why it deserves a closer look against Malaysia’s Cyber Security Act 2024, and why closing this particular gap starts with policy rather than software.

 

Executive Summary

  • 45% of employees are now regular users of AI on their corporate devices, authorised or not, up from 15% the year before.
  • Of those users, 67% are doing it through non corporate accounts, meaning the organisation has no visibility into the session, the account, or where the data goes.
  • The most common data type submitted to unauthorised AI tools is source code, followed by images and other structured data. In 3.2% of violations, employees uploaded research and technical documentation, a direct intellectual property exposure.
  • Mobile makes this worse than the laptop version of the problem, no browser extension or corporate login is needed to reach the same clipboard, storage and camera that an approved work app uses.
  • Malaysia’s Cyber Security Act 2024 places new emphasis on risk visibility and reporting for organisations designated as operating National Critical Information Infrastructure (NCII), and the accountability principles it reflects are relevant well beyond that group.
  • No mobile security tool, including purpose built mobile threat defense platforms, currently monitors what an employee types or pastes into an AI app. Closing this gap starts with policy, not a product.

What Shadow AI Actually Is, in Plain Terms

Shadow AI is what happens when employees use AI tools on company devices without those tools being approved, reviewed, or even known to the security team. It’s rarely intentional harm. Someone wants to move faster, so they paste a chunk of code into a chatbot to debug it, or drop a document into an AI tool to summarise it. The productivity gain is real. So is the fact that nobody in the organisation knows where that data went afterwards.

Zimperium’s data shows this is now mainstream behaviour, not an edge case. 45% of employees are regular AI users on corporate devices, and two thirds of that usage happens through personal, non corporate accounts. That means even organisations with an official, sanctioned AI tool still have a much larger amount of unsanctioned use happening in parallel, invisibly.

 

Why Mobile Makes This Harder to Catch

On a laptop, Shadow AI usually shows up as a browser tab or an extension, something a reasonably mature DLP setup has a chance of flagging. On mobile, there’s no equivalent tell. A GenAI app installed on a phone reaches the same clipboard, storage and camera that any approved work app uses, without needing a corporate login or leaving the same kind of trail.

The type of data at risk is exactly what you’d expect from a workplace: source code is the single most common thing submitted to unauthorised AI tools, followed by images and other structured data. Research and technical documentation showed up in 3.2% of violations Zimperium tracked, which is a direct intellectual property exposure, not just a policy breach.

There’s a second version of this problem too. Many business apps that were approved months or years ago have since had AI features added to them, quietly, in an update nobody reviewed. Zimperium’s zLabs data shows AI adoption in business apps growing 136%, and AI embedded apps overall up 14x on Android and 7x on iOS. An app your security team signed off on last year may not be the same app it is today.

Shadow AI adoption growth Chart

 

Why This Isn’t a Problem a Security Tool Solves on Its Own

Mobile Device Management covers the device, not what an app on it sends to a model hosted elsewhere. Data Loss Prevention controls, even well configured ones, only work within apps the enterprise manages, and as one line in the report puts it, “the data doesn’t need to be copied to leave. It just needs to be seen.” An employee can photograph a screen, upload a file from local storage, or type sensitive information directly into a chat window, none of which any current mobile security tool, including purpose built mobile threat defense platforms, is built to see or stop.

That doesn’t mean technology has no role. Where a mobile threat defense platform genuinely helps is at the app level, spotting that a GenAI app has been installed at all, or flagging when a business app your team approved has quietly shipped an update that adds an embedded AI feature. That’s real, useful visibility. It’s just a different thing from monitoring the content an employee sends to that app once it’s open, and that distinction matters if you’re deciding where to put your time and budget. This is a visibility and governance gap, not a tooling gap, every app carrying an AI model needs to be vetted under one consistent policy, rather than expecting a single product to close the hole.

 

Where the Cyber Security Act 2024 Comes In

The Cyber Security Act 2024, officially gazetted by the Attorney General’s Chambers and enforced by the National Cyber Security Agency (NACSA), was built around a fairly simple idea, organisations that hold or manage critical or sensitive systems need to actually know what their risk exposure looks like, and be able to demonstrate that to regulators when asked. Shadow AI sits directly against that principle.

For organisations designated as operating National Critical Information Infrastructure, the Act introduces obligations around risk assessment, audits, and incident reporting. Shadow AI complicates all three. You cannot meaningfully assess a risk you cannot see. You cannot audit a data flow that never touched an approved system. And if sensitive data left the organisation through an unsanctioned AI tool, it may not even register as an “incident” under existing detection processes, because nothing was technically breached, the data simply walked out through a channel nobody was watching.

This isn’t legal advice, and every organisation’s specific obligations under the Act depend on its designation and sector. What we’d encourage is a conversation with your compliance function about whether your current risk assessment process accounts for AI usage on mobile devices at all. For many organisations, right now, the honest answer is no.

 

A Parallel Consideration Under PDPA

Separately from the Cyber Security Act, Malaysia’s Personal Data Protection Act remains relevant here too. If an employee pastes customer information, contact details, or other personal data into an AI tool the organisation never approved, that data has left the organisation’s control in a way the PDPA’s principles around data processing were never designed to accommodate. It’s a second reason this gap deserves board level attention, not just an IT policy update.

 

Four Questions for Your Next Security Review

  • Does our AI usage policy extend to personal and BYOD devices, or only company issued ones?
  • Do we have a process for re-reviewing approved apps when they add new AI capabilities?
  • If asked to demonstrate our risk visibility into AI usage today, could we actually produce an answer?
  • Who in our organisation actually owns this policy, and does it reach past IT into compliance, legal and HR?

Closing the Gap Starts With Policy, Not a Product

Given everything we’ve just mentioned, the starting point isn’t software. It’s a policy that reaches every device employees use for work, including personal ones, paired with a clear answer to who owns it. That’s a governance exercise. Defining what’s allowed, extending existing AI and data policies to mobile and BYOD, and building the process to re-review apps when they change.

Vigilant Asia is a certified partner delivering Zimperium’s Mobile Threat Defense platform, which can help with the app level visibility described above. The policy itself is a decision for your own compliance and legal teams, and our role is giving them the visibility to make it with.

 

What Shadow AI Means for Mobile Compliance in Malaysia

Shadow AI didn’t arrive with a warning. It arrived quietly, through ordinary employees trying to get their work done faster, on devices that were never built for this level of scrutiny. Against a regulatory backdrop like the Cyber Security Act 2024, the question isn’t whether this gap exists, Zimperium’s data confirms it does, it’s whether your organisation has a policy that actually covers it, since no tool on the market closes this one alone.

If you’d like to understand what visibility into AI usage on your organisation’s mobile devices currently looks like, contact us for a conversation.

FAQ

1What is Shadow AI?
Shadow AI refers to employees using AI tools on corporate devices without those tools being approved, reviewed, or visible to the organisation’s security team, often through personal accounts.
2Is Shadow AI a bigger risk on mobile than on laptops?
Mobile makes it harder to detect. Standard browser based DLP tools that catch Shadow AI usage on a laptop generally have no equivalent visibility into what a mobile app is sending to an AI model.
3What kind of data is most at risk?
Zimperium’s data shows source code is the most common data type submitted to unauthorised AI tools, followed by images and structured data, with a meaningful share of violations involving research and technical documentation.
4Does this only affect large or regulated organisations?
No. While the Cyber Security Act’s specific obligations apply most directly to designated NCII operators, any organisation handling sensitive data or personal information carries exposure under PDPA principles as well.
5What’s a practical first step?
Establish whether your current AI usage policy, if one exists, actually extends to personal and BYOD devices, and whether you have any way to verify compliance with it.
6Can Zimperium’s Mobile Threat Defense, or any mobile security tool, detect or stop Shadow AI?
Not fully, and it’s worth being clear about that. Current mobile security tools can show you which AI apps are installed on a device and flag when an approved app has added a new AI feature. What they cannot do is see the content an employee types, pastes or photographs into an AI app once it’s open. Closing that part of the gap depends on policy that extends to every device employees use for work, not on a single product.
Share

Related posts

Mobile phone with an address in the background

Why Mobile Security Is the Weakest Link for Southeast Asian Enterprises


Read more
Crest AI Charter Signatory logo

Vigilant Asia Becomes a Founding Signatory of the CREST AI Charter


Read more

Top Cybersecurity Trends for 2026 in SE Asia and Beyond


Read more

TAGS

  • News
  • Tips

MOST RECENT

  • Shadow AI
    Why Shadow AI Is a Governance Problem for Malaysian Enterprises
  • Mobile phone with an address in the background
    Why Mobile Security Is the Weakest Link for Southeast Asian Enterprises
  • Crest AI Charter Signatory logo
    Vigilant Asia Becomes a Founding Signatory of the CREST AI Charter

FEATURED

  • Shadow AI
    Why Shadow AI Is a Governance Problem for Malaysian Enterprises

Get a free consultation

On our trustworthy cybersecurity services.

CONTACT US

Vigilant Asia is an award-winning Managed Security Service Provider with CREST-accredited expertise across Security Operations Centre (SOC), Penetration Testing and Cyber Incident Response, offering tailored cybersecurity solutions and services. We make it our responsibility to keep your company secure and protected within the hyperconnected world. Vigilant Asia is part of Efficient E-Solutions Bhd, listed on the mainboard of BURSA.

WHAT WE DO

  • Managed Services
  • Professional Services
  • Solutions

COMPANY

  • About
  • Careers
  • Contact

CONTACT

Malaysia

Vigilant Asia (M) Sdn Bhd (1255978-D)

No 3, Jalan Astaka U8/82, Bukit Jelutong 40150 Shah Alam, Selangor, Malaysia.

Singapore

Vigilant Asia Cybersecurity Pte Ltd

1 Coleman Street, #10-09B, The Adelphi, Singapore 179803.

+60 (3) 58702252
info@vigilantasia.com.my

© Vigilant Asia. A member of the Efficient Group Malaysia. All Rights Reserved.
    GET IN TOUCH