Employees are building software now. Not just the engineering team, but the finance analyst, the HR coordinator, the marketing assistant. Tools like Claude Code and OpenAI's Codex let anyone describe a task in plain English and get a working script back in minutes. That is genuinely useful. It is also creating a mess that most companies have not noticed yet.
Here is the pattern. Someone is stuck doing a repetitive task, like matching invoices or pulling reports. They ask an AI tool to automate it. It works, so they share it with a few coworkers. A month later, that little script is quietly touching real financial or customer data, with passwords typed directly into the code, no record of who built it, and no one checking whether it still works correctly. Industry writers have started calling this wild code: AI generated tools built entirely outside the view of the IT department.
The numbers back up how fast this is spreading. IBM's most recent breach research found that security incidents tied to this kind of unsupervised AI use have more than doubled in a year, and these incidents cost more on average to clean up than a typical breach. On the code itself, independent testing from Veracode has repeatedly found that close to half of AI generated code contains a real security flaw, and a separate audit of thousands of publicly available AI built apps found over two thousand serious vulnerabilities and hundreds of exposed passwords and access keys sitting out in the open.
This is not a story about careless employees. It is a story about a mismatch. Executives largely believe their staff already have the tools they need to do their jobs, but when employees are asked the same question directly, far fewer agree. That gap is exactly why people go around IT rather than through it: the official tools feel slower than just asking an AI to build something better.
Banning these tools does not close that gap, it just hides it. Companies that try to shut this down outright tend to find the same behavior continuing anyway, just without anyone telling IT about it. That is worse than the original problem, because now the risk is invisible instead of merely unmanaged.
The more workable path, and the one now showing up across the security industry from Tines to Microsoft to Zscaler, is giving employees a supervised space to build in from day one: connections that are pre-approved, passwords that stay hidden from whoever is building the tool, and one place where every automation running across the company is actually visible. None of this requires employees to stop building things for themselves, which was never realistic anyway.
For a business leader reading this, the takeaway is not to panic about a specific tool. It is to ask a much simpler question at the next leadership meeting: does anyone in this company actually know how many small AI tools employees have already built, and what those tools can touch. For most companies right now, the honest answer is no. That gap, not any single piece of software, is the real risk sitting inside most organizations today.