CuraDevOps

Plan active

Shadow AI in CI/CD: threat-modeling from dev laptop to Kubernetes

2026-08-07 11:39 UTC · CNCF Blog · read the source ↗ #supply-chain#ai-security#ci-cd
  • Platform/SRE — Learn: Useful framing for understanding how unsanctioned AI tools introduce new attack surfaces into the platform layer, but no specific infrastructure action or deadline is present.
  • CI/CD — Learn: Directly relevant to pipeline security thinking — AI extensions and agents in the build path are an emerging supply-chain risk worth evaluating, but no concrete deprecation, compromise, or deadline anchors an Act or Plan verdict.
  • Leader — Plan: Shadow AI in delivery pipelines is a policy and governance gap that warrants adding AI tool usage to supply-chain standards and acceptable-use policy; schedule a review of which AI integrations teams are using in pipelines before the next security audit cycle.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.