Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Cloud Exchange 2026: Wiz’s Chris Saunders on controlling shadow AI

Дата публикации: 18-06-2026 14:23:21

As agencies move more apps to the cloud and access to AI tools becomes easier, it expands the data threat surface, Wiz solutions engineering director says.

Основное содержимое страницы с новостью.

The proliferation of artificial intelligence tools is opening up another front in the battle against “shadow IT.”

As cloud service providers incorporate AI capabilities into their offerings, agency chief information officers find they face new challenges from these “self-hosted models,” said Chris Saunders, the worldwide director of public sector solutions engineering at Wiz.

These shadow IT cloud presences become more problematic when employees use AI tools that aren’t approved by their agency.

“The biggest value that the industry can add is these new agentless technologies. They don’t require you to go out and install things or know where things are. We leverage application programming interfaces because APIs are friendly, and we leverage the ones that the cloud service providers like Google, Amazon and Azure are using,” Saunders said   during Federal News Network’s Cloud Exchange 2026.

“We can understand all the things that are deployed in those cloud environments. This really helps us give visibility, so you have to make it easy for these agencies to understand what is on their networks.”

Observe, identify and secure

The first step, of course, is understanding what is on the network or cloud service provider so the agency can assess its risk. The second step, Saunders said, is to secure the AI tools.

“The number one thing that we can do is prioritize where we see risk. If you have an AI model that is leveraging agency data that could be controlled unclassified information (CUI) or personally identifiable information (PII) or other information, and that workload is exposed to the internet, you might want to know about that,” he said. “You might want to fix that because maybe it’s not supposed to be exposed to the internet. Maybe the large language model is actually not supposed to be trained on sensitive information but knowing that is a top of the list priority for your teams.”

Without understanding these potential risks, an organization’s attack surface continues to grow. Saunders said technology leaders end up with a lot “cyber noise” that they have to sort through to decide which threats are serious and which ones are not.

As agencies continue to operationalize AI, Saunders said another way to ensure security is to take advantage of the guardrails cloud service providers set up within their environments.

Look to the frameworks

He said one best practice is for organizations to check themselves against assessment frameworks like those from the Center for Internet Security or the Open Worldwide Application Security Project.

“You should be checking yourself against those scores and see how well you’re scoring. If you’re improving week to week on your score, then you are ensuring you’re following the best practices for AI security,” Saunders said.

“The one big thing that we need to do better on is we have these service level agreements around patching. We have to have faster patching cycles because these attacks are going to keep coming. The other thing we have to do is make sure that these new applications that we’re building are at a much faster cadence of updates than the traditional software you’ve deployed before. That should not be a problem because these are all modern technologies so let’s make sure we’re rapidly fixing the known vulnerabilities that are in that software.”

Saunders said the goal for any organization is to patch software in seconds or minutes rather than hours or days.

Work toward self-healing environments

AI tools and automation will help agencies reduce the time it takes to patch systems and applications. But Saunders said by having more and more applications in the cloud, agencies can move toward creating a self-healing infrastructure.

“We have to get to a point where we have agentic AI helpers or agents: We have a red agent that continuously pen tests your environment for real exploits. If it finds one, it’s going to hand that off to the green agent, which is then going to be able to tell the customer or actually automate the fix: ‘Here’s the code fix that closes that vulnerability,’ ” he said. “If we are actually in a real-time attack, we have a blue agent that helps us understand what that attack is and what the remediation is. Create a world that’s self-healing and all these things are automatically happening.”

Saunders added in some cases, a human will not have to be in the loop for low-level cyberthreats.

“We’re still going to need folks to understand what the AI is meant to achieve. We’re still going to have to have a human in a loop to understand, ‘OK, is this a mission critical system or not? Are these crown jewels actually crown jewels? Are they real?’ ” he said.

“There’s going to be certain scenarios we’re still going to want to have that human loop. We’re just going to cut down a lot of the cycles spent on chasing false positives and noise.”

Discover more articles and videos now on the Cloud Exchange event page.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Cloud Exchange 2026: Ping Identity’s Kelvin Brewer on identity as foundation of secure AI adoption in government0518-06-2026
2Cloud Exchange 2026: Splunk’s Jonathan Gines on tackling post-migration challenges0518-06-2026
3Cloud Exchange 2026: Red Hat’s Michael Epley on building resilient AI architectures0518-06-2026
4Cloud Exchange 2026: Google Public Sector’s Cameron Groves on how AI agents are reshaping government workflows0518-06-2026
5Cloud Exchange 2026: Forrester’s Lauren Nelson on trends in cloud maturity0522-06-2026
6Cloud Exchange 2026: Salesforce’s Robert Lindsley on delivering connected digital experiences across government0518-06-2026
7Cloud Exchange 2026: Coast Guard’s Brian Campo on service’s new Digital Transformation Strategy0522-06-2026
8Why embodied AI security extends beyond the robot08.2624-07-2026
9Shadow AI is becoming enterprise security’s biggest blind spot010.2123-07-2026
10The ‘year of AI’: 2026 sees influx of ransomware attacks-2626-06-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 5. Источник: federalnewsnetwork.com.