IT Brief US - Technology news for CIOs & IT decision-makers
United States
ThreatDown adds shadow AI & identity tracking tools

ThreatDown adds shadow AI & identity tracking tools

Thu, 23rd Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

ThreatDown has added tools to identify shadow AI use and track non-human identities within its security platform. The additions expand its monitoring of cyber risks linked to unsanctioned AI tools and machine-based accounts.

The update gives customers an inventory of AI applications running across their networks, including unauthorised tools used by employees. It also broadens ThreatDown's identity monitoring to cover service accounts, API tokens, OAuth credentials and other machine identities used to access company systems and data.

The new AI visibility function is built into ThreatDown's existing agent and console and is available to all customers at no extra charge. The company presents the move as a response to a growing security gap as organisations adopt generative AI tools faster than they establish rules for their use.

Outside research cited by ThreatDown reflects that gap. An ISACA poll found that 90% of professionals reported employees using AI at work, whether sanctioned or not, while only 38% of organisations had a formal AI policy in place.

At the same time, non-human identities have become a larger part of the attack surface. These include software-driven credentials and automated accounts used by applications, scripts and AI agents. Such identities often outnumber human users in an organisation, yet tend to receive less oversight, according to ThreatDown.

The company's updated identity threat detection and response tools are designed to show the ownership, age and privilege level of those accounts and credentials. In practice, security teams can see which machine identities exist, how long they have been active and what level of access they hold.

Growing blind spots

The issue has become more pressing as AI services spread through businesses via both official deployments and informal employee use. Shadow AI, the term for AI tools adopted without formal approval or visibility from IT and security teams, can create risks when data is uploaded to external services or access is granted through poorly governed credentials.

ThreatDown linked the release to findings from its own cybercrime research on AI-related threats. Its report identified more than 6,000 AI models on Hugging Face presented as guardrail-free and downloaded more than 22 million times in a 30-day period.

The financial impact of weak oversight can also be significant. ThreatDown cited IBM research showing that breaches involving shadow AI exposure cost organisations roughly USD $670,000 more on average than breaches without that factor.

Security vendors across the market have been rushing to add AI-related monitoring and governance features as businesses seek to understand where employees are using external models and agents. ThreatDown's approach combines that monitoring with machine identity oversight in a single console rather than separating the functions into different products.

According to the company, the AI visibility dashboard lists each tool's name, category, platform, vendor, version and endpoint count. It also shows which devices are accessing which services, giving administrators a way to baseline normal use and spot software that may have entered the environment without approval.

Single platform

ThreatDown said the new functions are part of its AI Detection and Response and Identity Threat Detection and Response offerings. It argues that linking endpoint activity, identities and AI use can help security teams investigate suspicious behaviour across different parts of an environment without moving between tools.

The wider platform also includes a managed detection and response service. ThreatDown reported a median time to detect of five minutes and a median time to respond of 19 minutes, combining automated analysis with human analysts.

The company is also adding an AI assistant to its console that translates security information into plain-language guidance and suggested actions for administrators. Those actions are subject to review and confirmation before execution, ThreatDown said.

The release is aimed not only at in-house security teams but also at managed service providers, which often oversee multiple customer environments and need broad visibility into endpoint, identity and application risk. By using the existing console and agent, customers can adopt the new functions without adding another standalone security product, according to ThreatDown.

Analysts and vendors have increasingly focused on machine identities as organisations rely more heavily on APIs, cloud services and automated workflows. Service accounts and tokens can persist for long periods, retain high privileges and be overlooked during standard identity reviews, making them attractive targets for attackers.

ThreatDown warned that the combination of unauthorised AI use and unmanaged machine credentials creates a compound risk. If employees adopt external AI tools without central approval, those tools may connect to internal systems or data sources through tokens, service accounts or other credentials that are not being monitored closely.

"Shadow AI is the next major blind spot for security teams, and most organizations haven't even started thinking about the identities behind AI activity," said Kendra Krause, General Manager of ThreatDown.

"ThreatDown brings both into view on the platform teams already use, without adding complexity, to provide visibility into the AI tools active in their environment," said Krause.