Barracuda, PDI Launch Platforms to Govern Enterprise 'Shadow AI' Use

Vendors Launch New Tools to Secure Enterprise AI Adoption

INFORMATIONAL
September 23, 2026
4m read
Security OperationsPolicy and ComplianceCloud Security

Related Entities

Organizations

Products & Tech

Barracuda AI Data SecurityPDI Managed AI Prompt ProtectionChatGPTMicrosoft CopilotGoogle Gemini

Full Report

Executive Summary

A wave of new cybersecurity products has been launched to address the significant security and governance challenges posed by the rapid adoption of generative AI in the enterprise. With employees frequently using AI tools without corporate oversight—a phenomenon known as "shadow AI"—vendors like Barracuda Networks and PDI Technologies have introduced platforms designed to provide visibility, control, and protection. These solutions aim to discover which of the thousands of available AI services are in use, prevent sensitive corporate data from being sent to external Large Language Models (LLMs), and help enforce responsible AI usage policies, addressing a critical gap in many organizations' security postures.

The 'Shadow AI' Problem

The core issue these new products address is the lack of visibility and control over how employees use generative AI. A recent Barracuda study found that nearly half of IT leaders feel their teams lack the skills to govern AI securely. An IBM report cited by PDI found that 43% of security incidents now involve shadow AI. Employees may inadvertently paste proprietary source code, customer PII, or strategic documents into public LLMs like ChatGPT or Google Gemini, creating a massive risk of data leakage and intellectual property loss. Furthermore, these tools can be targeted by AI-specific attacks like prompt injection.

New Security Offerings

Barracuda AI Data Security

Launched on September 22, 2026, this platform is designed for resource-constrained organizations and MSPs. Its key features include:

  • Visibility: Discovers and provides control over 1,300+ generative AI tools.
  • Data Loss Prevention (DLP): Inspects prompts and uploads in real-time to block sensitive data (passwords, PII, source code) from being sent to external AI models.
  • Threat Detection: Detects AI-specific threats like prompt injection and aligns with the OWASP Top 10 for LLM Applications.

PDI Managed AI Prompt Protection

Also announced on September 22, this is a managed service focused on providing a single source of truth for AI activity. Its capabilities include:

  • Discovery: Provides visibility into over 15,000 AI services being used across the workforce.
  • Governance: Helps organizations establish and enforce policies for secure and responsible AI adoption.
  • Protection: Aims to protect against data exposure and other AI-related security risks.

These launches, along with similar announcements from other vendors like Cycode and Proofpoint, signal a clear industry trend: the emergence of a new category of security tools dedicated to AI governance and protection.

Impact Assessment

The proliferation of shadow AI creates significant business risks, including:

  • Data Breaches and IP Theft: Sensitive data used in prompts can be incorporated into the LLM's training data, making it potentially accessible to others.
  • Compliance Violations: Uncontrolled use of AI can lead to violations of regulations like GDPR or HIPAA if customer or patient data is mishandled.
  • Inaccurate Information: Employees may rely on factually incorrect or biased information generated by LLMs for decision-making.
  • New Attack Vectors: Attackers can use prompt injection to manipulate AI tools or craft highly convincing phishing emails.

The new platforms from Barracuda, PDI, and others aim to mitigate these risks by providing the necessary guardrails for organizations to adopt AI safely.

Compliance Guidance

Organizations looking to govern AI use should take the following steps:

  1. Establish an AI Usage Policy: Create a clear and concise acceptable use policy that defines which AI tools are approved, what types of data are permissible to use with them, and employee responsibilities. This is a form of Policy Development.

  2. Discover and Inventory: Deploy tools to discover all AI services being used within the organization. You cannot govern what you cannot see. This aligns with Asset Discovery.

  3. Implement Technical Controls: Use solutions like those from Barracuda or PDI to enforce the policy. This should include:

    • Blocking unapproved AI tools at the network level.
    • Implementing DLP to inspect and block sensitive data in prompts to approved tools.
    • Educating employees on the policy and the risks of shadow AI.
  4. Promote Secure Alternatives: Instead of only blocking tools, guide employees toward secure, company-sanctioned AI solutions, such as private instances of LLMs or tools with strong data privacy guarantees.

Timeline of Events

1
September 22, 2026
Barracuda Networks launches Barracuda AI Data Security platform.
2
September 22, 2026
PDI Technologies announces its PDI Managed AI Prompt Protection service.
3
September 23, 2026
This article was published

MITRE ATT&CK Mitigations

Block access to unapproved AI tools and websites at the network level.

Mapped D3FEND Techniques:

Educate employees on the risks of using unapproved AI tools and the corporate policy for AI usage.

D3FEND Defensive Countermeasures

To gain initial control over shadow AI, organizations should use DNS denylisting (also known as DNS filtering) to block access to known, unapproved public AI services. Security teams can compile a list of domains for thousands of consumer-grade AI tools and configure their corporate DNS resolver or web proxy to block requests to these sites. This serves as a blunt but effective first step to channel users away from high-risk services. This should be combined with a clear policy that directs employees to a set of approved, enterprise-grade AI tools that have been vetted by security and legal teams. This approach reduces the attack surface by limiting exposure to services with weak data privacy controls.

For approved AI tools, the primary risk is data leakage. Organizations should deploy a solution capable of User Data Transfer Analysis, such as a Cloud Access Security Broker (CASB) or a dedicated AI security platform like Barracuda's. These tools act as a proxy for traffic to sanctioned AI services (e.g., ChatGPT, Gemini) and inspect the content of prompts in real-time. Configure DLP policies within these tools to detect and block the submission of sensitive data based on keywords (e.g., 'internal only', 'confidential'), regular expressions (e.g., for credit card numbers, social security numbers), and source code patterns. This allows employees to leverage the power of AI while providing a critical safety net to prevent inadvertent leakage of proprietary or regulated data.

Timeline of Events

1
September 22, 2026

Barracuda Networks launches Barracuda AI Data Security platform.

2
September 22, 2026

PDI Technologies announces its PDI Managed AI Prompt Protection service.

Sources & References

Barracuda launches AI Data Security for safe AI adoption
Barracuda (barracuda.com) September 22, 2026
PDI Expands Security Services to Combat Shadow AI with AI Prompt Protection
GlobeNewswire (globenewswire.com) September 22, 2026
Barracuda brings AI security and governance within reach of smaller organizations
Help Net Security (helpnetsecurity.com) September 23, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

AI SecurityShadow AIGenerative AIDLPData GovernanceBarracudaPDI

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.