Your Employees Already Gave ChatGPT (and Half a Dozen Other Tools) Access to Everything. Did You Notice?

generative AI risk attribute

Schedule a Portnox Cloud demo today.

Contents

Somewhere in your organization right now, an employee is pasting a customer contract into an AI assistant to get a faster summary. Somewhere else, a developer just installed a coding copilot that reads their entire local repo. No request form, no ticket to IT, no sense that they’ve done anything wrong — because they haven’t, not really. They just got their afternoon back.

That’s the quiet problem with shadow AI: it doesn’t arrive like other risky software. The permissions warning is right there — it’s just that the risk of connecting it to Outlook feels small next to finally clearing out 4,000 unread emails. It just shows up. No review, no oversight — just an app with the same access to your files and systems as the employee who installed it.

Security teams have handled unmanaged software before. Shadow IT isn’t new. Shadow AI is just its fastest-moving version yet: a rogue browser extension might sit quietly for weeks, but a local model runner or an agentic coding tool can start reaching files, credentials, and remote resources the moment it’s opened — with no separate authentication step, no admin approval, and often no obvious signature to flag.

The tools themselves aren’t the enemy. ChatGPT, Claude, Perplexity, DeepSeek, and the growing list of local and self-hosted options are legitimately useful, and banning them outright just pushes people toward workarounds. The actual gap isn’t the tools — it’s how they got there. An approved AI assistant, provisioned through a company account with the right data-handling safeguards in place, is a different risk profile than the same tool an employee grabbed on their own. Most IT and security teams can’t currently tell the two apart.

Introducing Portnox’s New Generative AI Risk Attribute

Here’s the short version: the Generative AI risk attribute lets you assign risk to a device based on which generative AI client apps are installed on it. Set an allow list — anything not on it raises the device’s risk score — or a block list, where only what you’ve explicitly named raises it. Either way, once a device’s risk score is elevated, you decide what happens next: a warning, an alert, restricted access to specific apps or resources, or removal from the network entirely — whether that means blocking the device from joining in the first place, or disconnecting it the moment a disallowed app turns up on one that’s already connected.

And because finding the problem isn’t the same as fixing it, Portnox can go a step further with automated remediation — terminating the AI agent’s processes and uninstalling the disallowed application outright, on both macOS and Windows. No ticket, no manual cleanup — the loop closes itself.

None of this is really a new category of risk — unmanaged software on endpoints has always been a security exposure. What’s changed is speed. Shadow AI can start acting on data the instant it’s installed, with none of the friction that used to buy security teams a little time to notice. The Generative AI risk attribute doesn’t ask you to reinvent your approach to endpoint risk. It just extends the policy-based control you’re already applying everywhere else to the category that’s moving fastest right now.

Curious what it actually looks like in practice? Take a look below.

Take a Tour of the Generative AI Risk Attribute

Share

About the Author

Picture of Kate Asaff

Kate Asaff

Kate Asaff is a Technical Product Marketing Manager at Portnox with more than two decades of experience spanning networking, enterprise IT, and cybersecurity. Before moving into product marketing, she spent over 15 years at SolarWinds in technical support and program management, helping bridge the gap between engineering and the people who rely on technology every day. Today, she writes about network access control, zero trust, AI, identity security, and passwordless authentication for the practitioners who implement them.

About the Author

Picture of Kate Asaff

Kate Asaff

Kate Asaff is a Technical Product Marketing Manager at Portnox with more than two decades of experience spanning networking, enterprise IT, and cybersecurity. Before moving into product marketing, she spent over 15 years at SolarWinds in technical support and program management, helping bridge the gap between engineering and the people who rely on technology every day. Today, she writes about network access control, zero trust, AI, identity security, and passwordless authentication for the practitioners who implement them.

Related Reading

Network SecuritySecurity Trends

The Three Parties Now Asking Manufacturers to Prove What’s on Their Network

September 22, 2026
Network Access ControlSecurity Trends

Once It’s In: Where Can an Unauthorized Device Go?

September 22, 2026
Network Access ControlNetwork Security

What the Jaguar Land Rover Breach Really Exposed

September 18, 2026