Video summary
Why Shadow AI Creates Insider Risk in Microsoft 365 ft. Gabriel Friedlander
Main summary
Key takeaways
Summary
The episode argues that AI increases insider risk in Microsoft 365 not only through malicious behavior, but through new “unintended” and “system-level” ways people will use AI—often outside formal policy.
Core idea: security is needed to enable faster AI adoption
Security is framed as “brakes”: not meant to stop business, but to help organizations move quickly without crashing. The key message is that many organizations are adopting AI faster than they can:
- train people
- implement guardrails
That gap creates real insider risk.
1) “Shadow AI” creates insider exposure
Gabby (Gabriel Friedlander) describes two common shadow-AI patterns:
-
AI-restricted companies (“we don’t allow AI”)
- Employees bring personal AI tools from home because they still need AI productivity.
- This can lead to company data being sent to unmanaged third-party accounts and a loss of visibility.
-
AI-adopting-by-FOMO companies (“everyone else uses AI”)
- Management pushes AI adoption without understanding the need for policies and guardrails.
- If employees aren’t trained or told which tools are approved, adoption becomes a “wild wild west,” reducing visibility and increasing risk.
2) “AI workers/agents” elevate insider threat into a new category
Beyond individuals using tools, the episode highlights a third category:
- Technology companies building AI agents that can perform tasks and access data.
- These agents may have no meaningful identity/audit trail at the human level (as described in the episode), making attribution and tracking harder.
- If an agent is compromised or taken over, it can effectively become a real insider threat—not because it has malicious intent, but because it will pursue its mission and try to access “what it needs” (e.g., “crown jewels”), potentially exploiting guardrail weaknesses.
- The discussion references lessons from AI “hacking” incidents where models can find ways around constraints, and notes that vulnerabilities like SSRF-style issues can be involved.
3) Training and risk assessment are presented as the minimum baseline
The episode argues that most organizations are clueless about their actual AI risk posture even while they rush to benefit from AI.
Recommended first steps include:
-
AI risk assessment questionnaire to determine:
- whether employees know approved AI tools
- whether they know whom to contact
- whether employees are using personal accounts/tools anyway
-
Mandatory AI security awareness training
- Emphasizes that AI usage isn’t “common sense.”
- People may understand basic privacy norms (e.g., salary sharing), but not that AI interactions can unintentionally expose sensitive data (e.g., sharing proprietary formulas to an external model).
-
Guidelines/guardrails before advanced controls
- Approve tools
- Define what data can be used
- Reinforce safe handling behaviors
4) Observability and auditability are harder with agents (Microsoft angle)
The conversation notes that while traditional account takeover can be investigated using logs, agent takeover may not produce clear login moments, making IP tracing harder and shifting the problem toward:
- API/observability
- auditing
It ties this to Microsoft’s direction with agent-related identity/audit concepts (mentioned as “Agent 365” in the episode), aiming to provide:
- intra-agent IDs
- audit logs of what the agent accessed and did
However, the episode frames this as “early days,” and says companies still need to understand the long-term control model.
5) Wiser’s approach: turning policy into engaged behavior
Gabby describes how his company (Wiser) primarily addresses insider risk through behavioral change and measurable engagement:
- Converts long security policies into short, emotional, story-driven training videos (typically ~1.5 minutes)
- Adds quizzes and tracking to confirm comprehension
- Uses simulation-style education (including “fishing simulations” mentioned) and continuous reinforcement (e.g., “monthly video” format)
- Includes a free AI risk assessment tool
- Emphasizes KPIs like whether employees share videos with friends/family, treating employees as ambassadors and using share rates as an engagement signal
Wiser adoption is described as: about 20,000 organizations using the platform.
6) Outlook: human-in-the-loop, not fully autonomous replacement
For the next 6–12 months, the episode predicts:
- Organizations will increasingly need human-in-the-loop governance rather than fully autonomous decision-making.
- AI won’t necessarily replace whole workforce segments, but it will accelerate productivity, meaning companies must manage more output and more oversight.
- More AI agents/tasks create new management needs (e.g., segmentation of context/memory, overlap control, monitoring), increasing operational complexity—and therefore risk if not managed.
Presenters or contributors
- Nathan Taylor (host)
- Gabriel Friedlander / “Gabby” (guest; described as founder of Observe It and associated with Wiser)
- Source Pass Center of Excellence for Microsoft (podcast/production sponsor/producer mentioned)