
Know what's running.
3 SIGNALS · 1 LESSON · 1 ACTION · ABOUT 5 MINUTES
Welcome to the first Hackademic Briefing. Every week you'll get three signals that matter, one lesson worth more than the news, and one thing to do, in about five minutes. I'm Chris Simpson: 27 years of Navy cyber, a doctorate on the cyber workforce gap, and AI security consulting through Hackademic Solutions. We start where almost everyone is exposed right now: the AI nobody approved.
SIGNAL 01
OWASP ships AISVS v1.0, a testable AI security standard
What happened. On June 24, OWASP released version 1.0 of the AI Security Verification Standard (AISVS), an open catalogue of testable security requirements for AI-enabled systems. It spans the AI lifecycle from data collection and model training through deployment, monitoring, and retirement. Version 1.0 includes 12 chapters, including Orchestration & Agentic Security and Model Context Protocol (MCP) Security, organized across three verification levels. Most production systems should aim for at least Level 2.
Why it matters. AISVS gives security teams a verification layer for AI systems. The OWASP LLM Top 10 and Agentic AI Top 10 name the risks; AISVS turns those risks into concrete requirements that can be tested, audited, and used in procurement. That moves “we should secure our AI” from vibes and vendor hand-waving into something closer to evidence.
What to do. Pick your highest-risk AI application, map it against the AISVS chapters at Level 2, and reuse the same requirements as vendor-evaluation criteria.
SIGNAL 02
Industry and the DoD issued the same shadow-AI warning a month apart
What happened. In May, the Cloud Security Alliance called autonomous AI agents a new class of insider threat: they read files, run commands, call APIs, and inherit their owner's permissions, acting at machine speed without anyone approving the step. A month later, DCSA's counterintelligence arm reached the same conclusion for the federal world, naming shadow AI a primary path to unauthorized disclosure and data spillage.
Why it matters. The warning from both is really about visibility. The CSA, citing Akto, puts 47% of enterprise AI use on personal accounts outside SSO and audit logs, and finds 79% of organizations blind to their AI agents and MCP connections. The insider-risk figures DCSA cites, from DTEX and Ponemon, put the annual cost at $10.3M, up 17% year over year, with 44% of organizations reporting little to no visibility into AI-agent activity. When an industry body and DoD counterintelligence reach the same conclusion independently, it is worth taking seriously, and both name the same root cause: you can't see it.
What to do. Discover the agents and tools running across endpoints, SaaS, and personal accounts; map the effective permissions of your non-human identities; and move from quarterly access reviews to continuous monitoring.
Source: Cloud Security Alliance (DoD figures: DCSA BTAC bulletin, June 2026)
SIGNAL 03
Canary tokens beat AI attackers in a 951-run test
What happened. In a working paper published in late May, Tracebit reported results from 951 simulated attack runs in an isolated AWS cyber range, with ten frontier models — including Claude, GPT, Gemini, and Grok — acting as autonomous attackers. The agents reached admin privileges in 162 runs, taking about 14 minutes in the runs that succeeded. In compromising runs where canary tokens were present, the canaries fired before the attacker's first critical action 95.9% of the time, and simply telling models to expect deception cut full compromises from 20% to 3%.
Why it matters. A 14-minute path to admin ends any response plan built on human reading speed. The encouraging half is that one of the cheapest control classes in security — decoy credentials, tripwire tokens, fake buckets — still works when the intruder is a frontier model. Worth knowing: this is a vendor's own working paper, and a simulated range rather than production.
What to do. Seed a few canary tokens along the paths an attacker would take — a decoy credential, a fake admin bucket — and route the alerts somewhere a human actually watches. It's an afternoon of work at near-zero cost.
Source: Tracebit Research
THE LESSON
Shadow AI Is Not a Policy Problem
Most organizations meet shadow AI by writing another acceptable-use policy. That drives the behavior underground and changes nothing you can see. Shadow AI is a visibility problem first and a policy problem second: you cannot govern what you cannot see. The new hire pasting a customer list into a free chatbot isn't a policy failure; it's a visibility failure.
The standards already assume you've solved the seeing. AISVS, the standard from Signal 1, does mandate inventories: a model registry (requirement 3.1.1) and a signed AI bill of materials (requirements 6.2.1 to 6.2.3). But every one of those covers the models you deliberately deployed and already control. AISVS has no requirement to discover the AI you never sanctioned. Its inventory starts where shadow AI ends.
Watch where the largest vendor is spending. Microsoft is shipping a Shadow AI page in the Microsoft 365 admin center to detect unmanaged AI agents first, then govern them: detect, then govern, which is the whole lesson. Even then it only sees managed Windows devices enrolled in Intune. That's partial visibility from the company with the most reach into the enterprise, which shows how hard “just see it” actually is.
DO THIS WEEK
Run a 30-minute shadow-AI inventory
Pull your SSO and OAuth app grants, or your egress and proxy logs, and list every AI tool your people have already connected. You'll find more than you expect. That list, not a new policy, is your starting point.
Start with SSO and OAuth grants, then proxy or egress logs.
One caveat: this catches SSO-connected tools. The personal-account usage, the 47% from Signal 2, is the harder next layer.
If that inventory turns up more than you expected, that's where a Hackademic Solutions AI Posture Review starts: a scored view of what's running in your Microsoft environment, in days rather than quarters.
— Chris Simpson
Hackademic Solutions
The Hackademic Briefing · Know what's running.