The Shadow App Problem: How Companies Are Losing Control of AI-Built Software
A new generation of business users is building applications with AI tools, but most of these apps sit completely outside the view of security teams. According to Orca Security's State of AI Security Report 2026, based on data from over 1,200 production cloud environments, 52% of organizations now create custom applications using artificial intelligence. The problem: these applications often bypass formal security reviews entirely, creating what security experts call "shadow AI" risks that can cost organizations significantly more when breached.
To address this growing challenge, Orca Security announced two new tools designed to secure software regardless of where or how it's built. The products, Orca AI AppGen Security and Orca AI Code Security Auditor, represent a fundamental shift in how companies need to think about application security in an AI-driven world.
Why Are Companies Building Apps Outside the Development Pipeline?
The rise of AI-powered app builders like Lovable, Claude, and Supabase has democratized software creation. Marketing teams, financial analysts, and business managers can now describe what they want an application to do, and AI tools generate working software in minutes. This speed and accessibility are powerful advantages, but they've created a security nightmare for IT teams.
The core issue is visibility. When a developer writes code in a traditional pipeline, security teams can review it, scan it for vulnerabilities, and track who built it. When a business analyst uses Lovable to spin up an application that connects to company data and APIs, that app often exists entirely outside security's radar. IBM estimates that breaches involving shadow AI cost organizations an average of $670,000 more than other incidents, underscoring the financial stakes.
"My developers and my business teams are both shipping software faster than my team can review it, and the apps built outside our pipeline were a complete blind spot. Seeing exploitable code and the AI apps our employees stand up in one platform lets us say yes to builders instead of slowing them down, and still know exactly what we're governing," said Sangram Dash, Chief Information Security Officer at Sisense.
Sangram Dash, Chief Information Security Officer at Sisense
What Do These New Security Tools Actually Do?
Orca's two new capabilities address different parts of the problem. AI AppGen Security is designed specifically for applications built outside traditional development workflows. It discovers AI-generated applications, identifies who built them, maps the risks tied to APIs and data access, and ranks exposures by business impact.
The second tool, Code Security Auditor, focuses on software developed within standard development pipelines. It uses AI-driven static analysis, a technique that examines code without running it, to detect vulnerabilities that traditional testing tools often miss. The tool scans entire code repositories and helps teams prioritize risks based on what attackers can actually exploit in practice.
How Can Organizations Secure Both Traditional and AI-Built Applications?
- Discover Shadow Applications: Use AI AppGen Security to identify every application built with AI tools across the organization and determine who created each one, closing the visibility gap that currently exists for most security teams.
- Map Data and API Risks: Understand what sensitive data and internal systems each AI-built application can access, then prioritize the highest-risk applications based on business impact rather than treating all exposures equally.
- Analyze Code for Exploitable Vulnerabilities: Deploy AI-driven code scanning that goes beyond pattern matching to trace data flows across multiple files and reconstruct actual attack chains, identifying only the vulnerabilities that attackers can realistically exploit.
- Unify Security Oversight: Bring visibility of both developer-created and AI-generated applications into a single platform so security teams can govern all builders and all applications consistently, regardless of where they were created.
The broader context here is significant. Orca's CEO Gil Geron framed the challenge in stark terms: "Everyone is a builder now. Developers are creating software in the pipeline, employees are building AI applications outside it, and the next generation of frontier AI models will increasingly generate and modify software on their own". This shift means security teams must adapt their approach fundamentally, moving from a model where they review code written by a known group of developers to one where they govern applications created by potentially anyone in the organization.
The announcement also reflects a broader industry recognition that traditional security tools were built for a different era. Static Application Security Testing (SAST) tools, which examine code for vulnerabilities, were designed to catch common coding mistakes. They struggle with the kinds of vulnerabilities that AI-generated code can introduce, particularly around data flow and API misuse.
Orca is positioning these tools as part of a unified approach to AI governance. The company recently added support for Anthropic's Claude through its Compliance API, part of a strategy to bring cloud, AI, and application security into one platform. The goal is to give security teams the context they need to make decisions quickly, so they can say yes to builders and innovation rather than becoming a bottleneck.
For many organizations, the practical challenge is that software built quickly by business teams can enter production use before formal security checks take place. This is especially risky when applications rely on external integrations or connect to internal data sources that could expose sensitive information if compromised.
Orca counts major enterprises including SAP, Autodesk, Gannett, Lemonade, and Digital Turbine among its customers as it expands its role in cloud, AI, and application security. The company will be showcasing these new capabilities at Black Hat USA 2026, the major cybersecurity conference, running August 1-6 in Las Vegas.