A finance analyst at a mid-sized insurance company, frustrated with a clunky reconciliation process, spends a weekend with Claude Code building a lightweight automation that pulls vendor invoices, flags discrepancies, and posts summaries to a spreadsheet. It solves the problem in minutes, so she shares it with three colleagues. Within a month, it’s quietly running critical processes within their systems with API keys hardcoded, no error logging, and nobody in IT aware it exists.
No one did anything malicious. But now there’s an unowned, unaudited script sitting inside financial operations. And if it breaks, leaks credentials, or gets flagged in an audit, someone will have to explain why nobody knew it was there.
This is wild code: AI-generated scripts, agents, and apps built outside IT’s visibility. It’s spreading through finance, HR, legal, and marketing teams — not just engineering — and it’s expanding organizations’ attack surface faster than security teams can respond.
As seven-time CIO Mark Settle puts it: “We potentially have a viral adoption phenomenon that’s not being gated by IT or even by the operations teams within individual business departments.”
Here’s a closer look at what’s fueling the problem, why the usual responses fall short, and what a better approach looks like.
The cost of wild code
The security bill comes due
IBM’s 2026 Cost of a Data Breach Report found that security incidents involving shadow AI have more than doubled in the past year, jumping to 43% from 20% in 2025. Those incidents cost an average of $5.39M, up from the overall average cost of a breach at $4.99M. On top of that, one in five breaches come with a regulatory fine attached.
The code itself is often the entry point. Veracode’s 2025 GenAI Code Security Report found that 45% of AI-generated code contains security flaws. Escape’s State of Security of Vibe-Coded Apps went further, auditing over 5,600 publicly available apps and finding more than 2,000 high-impact vulnerabilities and 400+ exposed secrets, including API keys, access tokens, even bank account data.
Untracked spend and duplicated tools are draining budgets
Beyond breach costs, wild code drains budgets in less visible ways: untracked AI and API spend with no clear owner, unused licenses for tools employees bypass, and IT hours spent tracking down and remediating scripts nobody documented. Gartner predicts over 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs and unclear value.
Settle puts it bluntly: “Where things get a little crazy is when individuals decide to start building agents that duplicate the functionality of SaaS modules because they simply don’t like the way the workflow has been implemented in the SaaS tool they are already paying for.”
Why the usual fixes don’t work
Blocking innovation isn’t free either
Tools like Claude Code and Codex let subject matter experts fix their own problems instead of waiting in an IT backlog. WalkMe’s Global Study found 88% of executives believe employees have the tools they need, but only 21% of employees agree. If organizations block wild code entirely, the gap doesn’t close. It just goes underground.
IT is already stretched thin
A study on AI-assisted development found that AI shifts effort downstream. Someone still has to review, understand, and maintain what gets built. That’s expensive, according to Tines’ Voice of Security 2026: 76% of security professionals experienced burnout in the past year, while Auvik’s research puts IT burnout at 60%. Meanwhile, IBM’s C-suite study found 11% of tech leaders feel prepared for the scale of AI agent deployment coming in the next 12 months, and 77% say AI adoption is already outpacing governance.
What actually works: governance that keeps pace
Settle argues the fix isn’t restriction: “IT and security teams have a unique opportunity to avoid contentious downstream debates by introducing construction guidelines now.” The goal is to give every team, technical or not, a safe and governed place to build in from the start. That’s the thinking behind Tines 3B, an AI-native environment designed to bring wild code out of the shadows without slowing the people building it.
Want to find out where wild code is already lurking in your org?
Get the guide: Taming Wild Code: The IT Leader’s Guide to AI Code Sprawl — complete with a checklist to help you audit, govern, and get ahead of AI code sprawl before it costs you.
Social media post
In our latest piece for CIO Dive featuring insights from 7x CIO Mark Settle, we break down the threat of wild code: AI-generated scripts, agents, and apps built by employees outside IT’s visibility. It goes far beyond engineering into all teams throughout your org into finance, HR, legal, marketing — anywhere AI is embedded.
Get the basics on the wild code threat:
- Why shadow AI incidents jumped from 20% to 43% in a year, and why they cost $5.39M on average
- How 45% of AI-generated code contains security flaws, with real-world audits uncovering thousands of exposed secrets and high-impact vulnerabilities
- Why blocking wild code outright doesn’t solve the problem
- What governance that keeps pace with innovation actually looks like, according to seven-time CIO Mark Settle
And to get a head start on managing your risk, check out our guide, Taming Wild Code: The IT Leader’s Guide to AI Code Sprawl — complete with a checklist to help you audit, govern, and get ahead of AI code sprawl before it costs you.






