Shadow AI — AI tools in the software lifecycle without approval, ownership, or monitoring — has a new threat model from CNCF. It's a good one, and the framing shift matters.
The moment AI stops advising and starts acting, it stops being productivity software.
"Once an AI system is allowed to call tools and take actions, it stops being productivity software and becomes a new non-human identity with permissions, a blast radius, and a place in your threat model."
That's the sentence to share with your security team.
What the threat model covers








