Key Takeaways
- 82% of Enterprises Harbor Shadow AI Agents
- Pre-Alignment Alone Isn't Enough
- Start With a Full Inventory of AI Assets
- Re-Review Procedures When MCP or APIs Change
On September 7, 2026, Park Ha-eon, CTO of AIM Intelligence, cited Cloud Security Alliance (CSA) statistics showing that roughly 82% of enterprises harbor shadow AI agents they haven't fully identified internally. The remarks came during a session titled 'The Frontline of AI Control: From Models to Agents to Physical AI' at the 'AI Risk Conference Seoul 2026,' held at the Samsung Finance Campus.
What Was Reported
CTO Park stated, "Roughly 82% of enterprises harbor shadow AI agents they haven't identified on their own, and more than half reported that their AI agents have at some point acted beyond their authorized scope." Regarding control methods, he emphasized, "Traditional checklist-based verification or simple input/output-focused controls no longer work. Because even a single change to an MCP or model API can alter the entire risk structure, continuous vulnerability detection and real-time defense systems are essential."
What Changes With Physical AI
The presentation cited case examples of security risks that can arise in physical AI environments.
- In an autonomous driving experiment, inserting subtle text covering just 0.8% of total pixels was enough to induce a vehicle to strike a pedestrian.
- Confirmed scenarios included a drone tracking a tank being counter-attacked and crashing, and home IoT devices malfunctioning from audio-based attacks alone.
- In collaboration with NASA, a vulnerability was discovered in the AI aboard the solar probe 'Parker,' leading to a temporary suspension of the service.
CTO Park pointed out that even OpenAI's 'Astra,' regarded as AGI-level, cannot be fully controlled through 'alignment' alone—the safety mechanism designed to make AI refuse threatening actions. Given the clear limitations of pre-alignment alone, he explained that a security layer capable of monitoring and controlling the entire AI lifecycle in real time must be integrated.
AIM Intelligence is building an integrated security framework centered on its red-teaming solution 'Stinger' and its guardrail platform 'Starfort.' The company reported that Stinger has diagnosed more than 160 AI models, while Starfort has been applied to over 100,000 AI agents. It has also launched a 'Physical AI Security Consortium' with around 20 domestic and international institutions and is developing dedicated guardrails for LG Electronics' robot 'CLOi.'
Implications for Korean Enterprise AX
CTO Park emphasized, "The top priority for enterprises looking to strengthen AI security is to conduct a full inventory of their own AI assets. Securing clear visibility into internal data flows, permission scopes, and potential risks is the key to safe AI operations."
Applying this standard to your own organization, the review sequence could be structured as follows.
- Compile a single, consolidated list of all agents and automations actually running across departments. Anything missing from that list is, by definition, shadow AI.
- Check logs to confirm which account permissions each agent uses to access which data, and whether any actions have exceeded authorized scope.
- Establish rules in advance for what needs to be re-reviewed whenever a connected MCP or model API changes.
There's one thing worth checking this week: see whether you can produce a single-page list of the AI agents currently running within your organization, and if you can, whether you can answer what permissions each of them holds.
