The Cloud Security Alliance has released its latest guidance paper, Confronting Shadow Access Risks: Considerations for Zero Trust and Artificial Intelligence Deployments.
Shadow access, a growing concern within cloud computing and identity and access management (IAM), refers to unintended, unauthorized access to systems and data, often intensified by the complexities of modern technological environments. The increasing availability of generative artificial intelligence (GenAI) introduces new shadow access risks, such as unauthorized access, sensitive data exposure, and governance issues.
This guidance, by the CSA Identity and Access Management Working Group, underscores the necessity of adapting traditional zero trust IAM approaches to the nuances of AI technology.
Key sections include:
- What Shadow Access is and why it exists
- What Zero Trust is
- The impacts of Shadow Access on Zero Trust
- What Zero Trust can do to mitigate Shadow Access
- The top concerns regarding Shadow Access, AI, and LLMs, including change management, data access visibility, identity verification, content authorization, and more.






