The 45% problem: How wild code Is pushing IT toward a security event horizon

https://imgproxy.divecdn.com/JorFWeH0W4Q3zj3Fc1WpS93-cT9ulq7BeZVvjS0zs_4/g:ce/rs:fit:770:435/Z3M6Ly9kaXZlc2l0ZS1zdG9yYWdlL2RpdmVpbWFnZS9UaW5lX0hlYWRlci5wbmc=.webp

A finance analyst at a mid-sized insurance company, frustrated with a clunky reconciliation process, spends a weekend with Claude Code building a lightweight automation that pulls vendor invoices, flags discrepancies, and posts summaries to a spreadsheet. It solves the problem in minutes, so she shares it with three colleagues. Within a month, it’s quietly running critical processes within their systems with API keys hardcoded, no error logging, and nobody in IT aware it exists.

No one did anything malicious. But now there’s an unowned, unaudited script sitting inside financial operations. And if it breaks, leaks credentials, or gets flagged in an audit, someone will have to explain why nobody knew it was there.

This is wild code: AI-generated scripts, agents, and apps built outside IT’s visibility. It’s spreading through finance, HR, legal, and marketing teams — not just engineering — and it’s expanding organizations’ attack surface faster than security teams...

Copyright of this story solely belongs to www.ciodive.com. To see the full text click HERE