News
The most damaging AI-related security incident your organization faces this year probably won't originate from external attackers using sophisticated new models. It's far more likely to begin with an employee pasting a client contract, a financial forecast, or a set of HR records into an AI tool because it makes their job easier and nobody has told them why it matters.
Shadow AI is a growing problem, and our research found that nearly half of employees at larger enterprises regularly feed corporate data into AI tools that nobody in IT has approved or governs.
More striking still, 85% of employees continue doing so even when company-sanctioned tools are available, pointing to a governance failure that runs all the way to the executive suite. With shadow AI, sensitive data can move silently outward through channels most security stacks were never designed to intercept.
Adding to the security risk of this unmonitored data flow, the advent of the EU AI Act also means organizations now face specific legal demands on managing AI use. The ability to have full governance over how AI is deployed, governed and monitored, is becoming a regulatory, as well as a security, imperative.
Why the EU AI Act makes this a board-level problemShadow AI represents a serious security issue, with IBM's 2026 Cost of a Data Breach report estimating that unauthorized tools contributed to 43% of breaches over the last year Now, the EU AI Act is adding significant regulatory requirements on top of these risks.
The Act's obligations have rolled out in phases; most recently, organizations classified as general deployers of AI have new inventory, data governance, audit logging and transparency obligations as of 2nd August 2026.
Other deadlines have shifted further ahead, with controls over high-risk AI usage, covering areas like recruitment, credit scoring and biometric categorization, set to come into force from 2nd December 2027. AI embedded in regulated products will be covered from 2nd August 2028.
Any organization whose employees use AI systems now has compliance obligations as a deployer, regardless of whether those systems were formally sanctioned.
All organizations using AI should be aware that the AI literacy obligation under Article 4 has been enforceable since February 2025, meaning organizations are on the hook for ensuring their employees are aware of safe and sanctioned AI use.
Rules around high-risk AI usage will also apply to more operations than it may seem at first, including an employee using an unapproved consumer tool for tasks like screening CVs, assessing creditworthiness, and evaluating performance.
These are common tasks that could trigger the full weight of the Act's oversight against a system that the IT department didn’t even know had been deployed.
With penalties reaching up to €15 million or 3% of global annual turnover for high-risk breaches, many organizations are carrying more exposure than they realize.
Why your existing security stack can't see itThe challenge with shadow AI is that it exploits the blind spots between conventional security layers, slipping through gaps that most tools were never designed to close.
CASBs and secure web gateways cannot decrypt conversational data flowing to legitimate LLM domains over HTTPS, for example. From the network's perspective, a prompt containing a full customer database is indistinguishable from any other encrypted web session. Browser extensions are limited to managed endpoints, blind to personal devices and AI embedded within approved SaaS.
Likewise, API gateways are usually built around authorized enterprise deployments, which means they capture the AI activity organizations have already approved while missing the consumer-grade AI tools driving most risk.
These blind spots compound with each other, so an organization running all three layers may still have no visibility into AI activity across a significant portion of its estate, and no means of generating the interaction logs or policy enforcement evidence the Act requires.
What good AI detection looks likeControlling AI data flows is usually managed by workers performing their duties without malicious intent. However, it’s remarkably similar to defending against an external threat actor covertly accessing your data.
The detection logic needs to match that reality. Endpoint-native detection intercepts sensitive data at the point of movement before it reaches an external AI system, enforcing policy at the prompt level across managed and unmanaged browsers, personal devices, and AI functionality embedded within SaaS tools. It operates where the activity occurs, rather than attempting to catch it downstream.
Given the scale of the potential fines, the ability to prove compliance matters almost as much as preventing security breaches.
Continuous discovery across the estate, including any unsanctioned tools gives organizations the AI system inventory the Act requires.
Granular interaction logs - who used what, when, and what data was involved - satisfy the documentation requirements under Articles 12 and 13, without teams needing to scramble to reconstruct activity after the fact. The same data pinpoints exactly where AI literacy gaps exist, making Article 4 compliance something demonstrable rather than simply asserted.
Practical steps for complianceSecurity and compliance teams aiming to comply with the EU AI Act have a clear path to follow.
The starting point is mapping the full AI estate. Discovery needs to extend beyond IT-approved tools to unmanaged endpoints, personal devices on corporate networks, and AI embedded within SaaS.
Data governance must move to the endpoint. Policies prohibiting sensitive data sharing with unapproved tools are not technical controls and, by the time enforcement happens at the network edge, the data has already left.
It’s important to remember that information shared with an external AI system may be retained in prompt logs, incorporated into model training data, or held on servers in jurisdictions the organization has no visibility into. The moment data crosses that boundary, the organization loses control of it entirely, and no policy document will retrieve it.
And since Article 12 requires interaction records that can be handed to regulators on demand, organizations will need to have continuous, automatic auditing of both activity and security measures.
Finally, AI literacy programs aimed at improving user awareness should be driven by behavioral data rather than generic training programs. Activity logs showing where governance failures are occurring - at senior leadership level as much as anywhere else - provide both the diagnosis of the issue and the evidence regulators will want to see.
We've featured the best antivirus software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Casualty fans, buckle up: two special episodes for its landmark 40th anniversary are heading to BBC and BBC iPlayer from September 5th.
If dealing with lots of ill people on a daily basis is bad enough, this new double-bill steps the drama up to levels we haven't seen in decades. Think The Pitt, if HBO Max decided to set it in South West England.
What Stars WatchEveryone gets stuck on what to watch next — so let’s make that choice easier with the help of your favorite actors. What Stars Watch pairs the latest TV shows and movies with cinematic classics or underrated gems, based on A-List tastes. Read the full series here.
As you can tell from the below trailer our episodes are centered on a massive explosion strikes near the Clifton Suspension Bridge, plunging the city of Wyvern, and the hospital, into immediate chaos.
In the back of an ambulance, Stevie Nash (Elinor Lawless) and clinical lead Flynn Byron (Olly Rix) are caught in a race against time. Meanwhile, Dylan Keogh (William Beck) must lead the emergency department through its darkest hour... including facing his own personal tragedy.
Understandably, the 40th anniversary of Casualty is going to be a pretty intense watch. In fact, it could be so intense that you'll likely want to decompress by streaming something that's the polar opposite completely answer.
Luckily enough, I asked the Casualty cast for their ideas — and how they got through the on-set stress themselves — and the suggestions are genius.
'I've just finished Love Island'"I've just finished Love Island... though I'm not sure if I want everyone knowing," Melanie Hill tells me. I hope she forgives me for including this, but it's such an unexpectedly fantastic choice that it actually makes complete sense.
Reality TV is often dubbed 'trash viewing,' treated as second-rate viewing because it's considered to be low-brow. The truth is the opposite — not only are most of the smartest women I know absolutely obsessed with it, but many shows offer fascinating insight into human social behavior and psychology. It's us at our best and worst, under glossy lights.
Frankly, Love Island is exactly the sort of show I'd choose to watch after watching people on death's door, even if it's only fictional. But if this isn't your thing, the suggestions don't stop there.
"I watched Shabaz Asks: Are Billionaires Bad? not too long ago," Neet Mohan adds. "It was a one-episode documentary by ShabazSays on TikTok. Was really funny. I also watched Pitch Perfect with my daughter... so there's that."
William Beck jokes, "I think if you want the complete opposite, go for snooker. But that's not very exciting, is it? Maybe even [children's show] Hey Duggee."
The good news is that three out of four of these TV show suggestions are readily available on BBC iPlayer, with Love Island currently on ITVX (or on Hulu in the US).
No matter what your jam is, you've got something ready to stream for free on the same platform... but come on, it's gotta be Love Island, right?
For years, enterprise Software as a Service (Saas) has enjoyed a comfortable position at the center of organizational processes. Users who wanted to raise a ticket, process an invoice or manage a workflow would log into their employer’s cloud application. The user interface was the gateway to the work, and the provider’s business model followed naturally: charge for seats, expand adoption, and grow revenue as more users spend more time inside the platform.
Agentic AI is beginning to change that. As users increasingly deploy AI agents, either to carry out tasks within SaaS platforms or to deliver functionality outside them, organizations require fewer seats – hitting providers’ subscription revenues.
At the same time, AI is making bespoke software faster and cheaper to build, giving organizations a credible alternative to buying another SaaS platform. Why accept subscription costs and vendor lock-in, when cheaper alternatives may achieve the same outcome?
None of this means SaaS is about to disappear, but its position at the center of enterprise software is under threat. SaaS vendors are facing three structural challenges that will reshape the economics of enterprise software.
Agents become the userThe first threat is simple: users may have AI agents carry out tasks within the SaaS platform, reducing the need for human users, or build agentic capabilities outside those platforms altogether.
That is a serious problem for any SaaS vendor whose business depends on people living in the interface. If an agent can resolve a support query, update a record or complete a routine transaction, the user never has to touch the application.
We’re already seeing this in practice. In some IT service management projects, agents now resolve such a high proportion of tickets that organizations need far fewer users interacting with the SaaS platform. As buyers begin questioning whether they still need premium software for the shrinking proportion of manual work, the economics start to shift.
Bespoke is backThe second threat is the one SaaS vendors dislike most: buyers may once again be willing to build new capabilities from scratch.
For the last decade or so, ‘build versus buy’ was often a non-debate. Custom software was too slow, too expensive and too risky, so SaaS usually won.
AI is starting to shift those calculations. As software development becomes faster, cheaper and more adaptive, some solutions that previously defaulted to SaaS start to look buildable – especially when the organization needs a narrow set of capabilities wrapped around its own processes and data. The more customization a SaaS platform requires, the weaker its cost-efficiency and automated-upgrade advantages become.
This does not mean large enterprises will abandon mature SaaS platforms overnight. Their resilience, integrations and compliance capabilities remain valuable. But once customers believe they have a credible alternative, vendors lose pricing power and the assumption that renewal is the obvious decision
Business model redundancyThe third threat is that even when the product survives, the commercial model may not.
Traditional SaaS pricing was built for a world in which value correlated reasonably well with the number of people sitting in the application. That logic gets shaky when agents perform work that would once have required more licensed users, and more operational dependency on the interface.
Vendors can see this. Many are shifting towards consumption-based pricing, exposing services directly to agents or redesigning products for an agentic world. The common thread is clear: once software starts working for people rather than being operated by them, seat-based economics begin to look outdated.
From the customer’s perspective, that could be a good thing. Paying for usage is often cheaper than buying licenses. The challenge for vendors will be proving they’re genuinely adapting to an agentic future, rather than simply repackaging existing products to protect margins.
SaaS is not deadTo be clear, this is not a “SaaS is over” argument. Many enterprise platforms will remain valuable, providing governance, resilience, compliance, and years of accumulated functionality that are difficult and expensive to recreate.
What will change is where value sits. In an agentic world, SaaS will be less the primary interface through which work gets done; more a component in a broader ecosystem of agents, orchestration and systems of record. Some platforms will adapt and become stronger; others will discover that the value they once captured has shifted elsewhere.
As for the corporate users of SaaS, the best advice we can give is not to wait for perfect conditions before acting. No business ever reaches a point where its data, processes or architecture are “finished”, and SaaS providers will continue to adapt their offers.
Meanwhile, experiment, learn and adapt in your delivery of administrative and corporate functions: in some functions you may find that agents drive down SaaS costs; in others, greenfield development may now be viable. In still other cases, adding new functionality using agents that leverage SaaS solutions but sit outside those ecosystems keep future options open.
So do something that works for you now – but keep the option of moving again in a year or two.
We've featured the best AI tool.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- Lake Ontario is now Lake America in the US via an executive order
- Google Maps has updated its maps to reflect the change
- Viewing the map from outside the US still shows the original name
Some 18 months on from the controversial renaming of the Gulf of Mexico, another edit has been made to Google Maps at the behest of US President Donald Trump: Lake Ontario, spread across the US-Canadian border, is now Lake America.
Or rather, it is if you're viewing Google Maps from inside the US (via Gizmodo) — the rest of the world will still see the Great Lake labeled as it has been since at least the 17th century. The name Ontario most likely comes from the Iroquoian word Kaniatarí:io or Oniatarí:io meaning "lake of shining waters" or "beautiful lake", as per Wikipedia.
The name change is the result of an executive order from the White House, as President Trump bickers with Canada over trade tariffs. In response, Canadian authorities have installed a large new sign at the lake (via the BBC), reading 'Lake Ontario. Now and Always'.
Reactions on Reddit are calling the switch "beyond ridiculous" and "braindead", though some commenters are pointing out that Google is obliged to follow the lead of the US Board on Geographic Names (part of the United States Geological Survey).
Google respondsNew York won’t be calling it that. https://t.co/FJQonEk8tIAugust 27, 2026
For its part, Google has also chimed in to say that it has to follow "official government sources" when it comes to place names, saying that "these updates follow our long-standing policy for bodies of water with names that vary from country to country, and are starting to roll out now".
"People using Maps in the US will see 'Lake America', those in Canada will continue to see 'Lake Ontario', and those outside of the US and Canada will see both names," according to the official blog post from Google Maps on the matter.
However, not everyone is towing the line on this: New York State Governor Kathy Hochul took to social media to declare that "New York won't be calling it [Lake America]", so there are going to be some pockets of resistance regarding the change.
As yet the change hasn't rolled out on Apple Maps, but presumably it'll eventually have to comply with the official government, and start renaming Lake Ontario depending on where in the world you're viewing the map from.
For anyone working in IT and familiar with SaaS sprawl, the idea we’ll soon end up with agent sprawl may set off alarm bells. Agent sprawl refers to the rapid, uncoordinated deployment of AI agents across departments, each built on different models, governed by different rules, and often disconnected from core business workflows.
But while SaaS sprawl caught enterprises off guard, this time organizations have no excuse, and need to put measures in place now to avoid repeating the same mistakes. However, right now, most organizations are building agents in isolation and optimizing for local productivity rather than enterprise value.
Thankfully, with the right control layer funneling every agent through the same governance and security standards within an organization, the agent-powered future can be far safer, scalable and simple.
Agent sprawl is inevitableJust like SaaS before it, agent sprawl is already happening. Each department within organizations is experimenting with different agent technologies to address specific challenges or work more efficiently.
A sales team may deploy a CRM-based AI assistant to qualify leads, while developers build their own coding agents, and marketing adopts a separate content generation tool. Each delivers local value, but none are aligned or connected to the other, creating a familiar-looking sprawl.
This fragmentation introduces a range of challenges that will only increase over time. With no single owner responsible for how agents are deployed or monitored, there’s a lack of governance and oversight. Security risks increase as agents gain access to sensitive systems without consistent controls.
Teams may unknowingly duplicate efforts, solving the same problems in parallel with different tools. At the same time, many agents are deployed without clear links to business outcomes or understanding the wider context, making it difficult to measure return on investment and distinguish meaningful innovation from experimentation. Lots of AI tools may be exciting, but deliver far more style than substance.
Is sprawl inevitable? Yes, probably. So the question now becomes, how do we control it?
The role of orchestrationHaving an orchestration layer can bring order to this complexity by creating consistency in how agents are governed, secured and deployed across the business. For SaaS applications, orchestration provides visibility into what tools already exist and gives a clear view of enterprise workflows.
With agents, it outlines what agents are already available and how they operate, while also controlling how they access data, tools and existing technology. Orchestration is the critical element that turns agents from experiments into scalable business infrastructure, for example, assigning agents to business workflows and measuring their performance against real outcomes.
Too often, we see enterprises experimenting with different agents that have no connection to the core business processes and goals, meaning they fail to deliver any ROI. For example, some portions of a business simply do not require AI technology and will unlikely see benefits in the same way as another department. Orchestration can unearth and filter out agents that are unnecessary, saving businesses money.
Building trust in AI-driven enterpriseRather than trusting individual agents, organizations should focus on trusting the system that governs them.
This is where orchestration becomes a trust layer, ensuring every agent operates within clearly defined boundaries with consistent oversight and accountability. Instead of individual teams managing risk in siloes, organizations can centralize control while still enabling innovation across different departments and business functions.
In the same way orchestration brought order to SaaS sprawl, it can do the same for the next wave of enterprise AI. It brings the same ease, security and integration with existing SaaS tools, while ensuring only high-value agents make it into production, supporting innovation and keeping within the business goals and purpose.
As agents become embedded across every function, orchestration will shift from a technical layer to a core enterprise capability. The winners will be those who can control, connect and trust their agents at scale.
We've featured the best AI website builder.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit


