A wave of new cybersecurity products has been launched to address the significant security and governance challenges posed by the rapid adoption of generative AI in the enterprise. With employees frequently using AI tools without corporate oversight—a phenomenon known as "shadow AI"—vendors like Barracuda Networks and PDI Technologies have introduced platforms designed to provide visibility, control, and protection. These solutions aim to discover which of the thousands of available AI services are in use, prevent sensitive corporate data from being sent to external Large Language Models (LLMs), and help enforce responsible AI usage policies, addressing a critical gap in many organizations' security postures.
The core issue these new products address is the lack of visibility and control over how employees use generative AI. A recent Barracuda study found that nearly half of IT leaders feel their teams lack the skills to govern AI securely. An IBM report cited by PDI found that 43% of security incidents now involve shadow AI. Employees may inadvertently paste proprietary source code, customer PII, or strategic documents into public LLMs like ChatGPT or Google Gemini, creating a massive risk of data leakage and intellectual property loss. Furthermore, these tools can be targeted by AI-specific attacks like prompt injection.
Launched on September 22, 2026, this platform is designed for resource-constrained organizations and MSPs. Its key features include:
Also announced on September 22, this is a managed service focused on providing a single source of truth for AI activity. Its capabilities include:
These launches, along with similar announcements from other vendors like Cycode and Proofpoint, signal a clear industry trend: the emergence of a new category of security tools dedicated to AI governance and protection.
The proliferation of shadow AI creates significant business risks, including:
The new platforms from Barracuda, PDI, and others aim to mitigate these risks by providing the necessary guardrails for organizations to adopt AI safely.
Organizations looking to govern AI use should take the following steps:
Establish an AI Usage Policy: Create a clear and concise acceptable use policy that defines which AI tools are approved, what types of data are permissible to use with them, and employee responsibilities. This is a form of Policy Development.
Discover and Inventory: Deploy tools to discover all AI services being used within the organization. You cannot govern what you cannot see. This aligns with Asset Discovery.
Implement Technical Controls: Use solutions like those from Barracuda or PDI to enforce the policy. This should include:
Promote Secure Alternatives: Instead of only blocking tools, guide employees toward secure, company-sanctioned AI solutions, such as private instances of LLMs or tools with strong data privacy guarantees.
Block access to unapproved AI tools and websites at the network level.
Mapped D3FEND Techniques:
Educate employees on the risks of using unapproved AI tools and the corporate policy for AI usage.
To gain initial control over shadow AI, organizations should use DNS denylisting (also known as DNS filtering) to block access to known, unapproved public AI services. Security teams can compile a list of domains for thousands of consumer-grade AI tools and configure their corporate DNS resolver or web proxy to block requests to these sites. This serves as a blunt but effective first step to channel users away from high-risk services. This should be combined with a clear policy that directs employees to a set of approved, enterprise-grade AI tools that have been vetted by security and legal teams. This approach reduces the attack surface by limiting exposure to services with weak data privacy controls.
For approved AI tools, the primary risk is data leakage. Organizations should deploy a solution capable of User Data Transfer Analysis, such as a Cloud Access Security Broker (CASB) or a dedicated AI security platform like Barracuda's. These tools act as a proxy for traffic to sanctioned AI services (e.g., ChatGPT, Gemini) and inspect the content of prompts in real-time. Configure DLP policies within these tools to detect and block the submission of sensitive data based on keywords (e.g., 'internal only', 'confidential'), regular expressions (e.g., for credit card numbers, social security numbers), and source code patterns. This allows employees to leverage the power of AI while providing a critical safety net to prevent inadvertent leakage of proprietary or regulated data.
Barracuda Networks launches Barracuda AI Data Security platform.
PDI Technologies announces its PDI Managed AI Prompt Protection service.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.