Kaspersky Warns Asian Firms on Shadow AI Data Risks
Kaspersky identifies "shadow AI" as a growing cybersecurity threat for Asian firms. Unauthorised employee use of generative artificial intelligence (AI) tools exposes sensitive corporate data, expanding attack surfaces for cybercriminals.

Shadow AI Threat Grows
Cybersecurity firm Kaspersky highlights "shadow AI" as a rapidly expanding corporate risk. Employees increasingly use unauthorised generative artificial intelligence (AI) tools, bypassing internal IT oversight. This practice exposes sensitive company data to public AI models, significantly expanding potential attack surfaces — points cybercriminals can exploit. Andrian Hia, Kaspersky's Asia-Pacific managing director, noted this creates parallel technology environments outside corporate governance. Employees routinely upload financial records, proprietary code, and confidential documents, increasing data leakage risks.
Escalating Cyberthreats
The scale of cyberthreats continues to grow. Kaspersky detected and blocked over 500,000 unique malicious files daily in 2025, a 7% increase from 2024. In 2026, the firm identified more than 15,000 malware samples disguised as agentic AI software. As AI agents increasingly rely on third-party frameworks and application programming interfaces (APIs), a single compromised component can spread widely. This significantly elevates risks of cyber sabotage and espionage across downstream systems. Cybercriminals now exploit AI to automate attacks and accelerate malware development.
Kaspersky's AI Protect Platform
To counter these threats, Kaspersky plans to launch its AI Protect platform. This platform scans AI agents and open-source AI components before deployment, detecting malware and vulnerabilities. It also provides visibility into unauthorised AI usage, preventing sensitive corporate information from leaking into public AI platforms. Kaspersky's enterprise business grew 60% in its latest financial year. Following investments in Vietnam and Indonesia, Thailand is now Kaspersky's next strategic growth market in Southeast Asia.
Organisations must treat AI as a core defensive capability, not solely a risk source. The shift to machine-centric operations means cybercriminals execute faster, more sophisticated, and automated attacks. Critical infrastructure, internet-connected devices, and software supply chains are prime targets. Securing operational technology (OT) environments is crucial; attacks can disrupt electricity, water, telecoms, and transport. Continuous monitoring and threat detection are essential for Asian businesses to mitigate these evolving, AI-driven risks and protect critical assets from compromise.
Get The Brief.
Asia’s economy in five minutes, every weekday morning. Free.


