Somebody is selling your staff cheap access to Claude. It works. The key they hand over returns real answers from a real frontier model, at a price well under what the vendor charges for the same thing. In security circles the product has picked up a name, Poison Claude, and the name is the whole point. The operator sits in the middle of the connection and reads every prompt that passes through it on the way to the model.

I am not telling you that a named company has been caught doing a named thing. I am telling you three things I am confident of: that discounted frontier model access is being resold by intermediaries, that at least one such product is circulating with exactly that reputation attached, and that the mechanism it would use requires nothing clever at all.

Shadow AI has spent two years being treated as a policy problem. Staff pasting confidential material into ChatGPT, a training module, a line in the acceptable use policy, done. That was never a good enough answer, but it was at least the right shape of problem. It is not the problem any more.

How simple this actually is

Your staff member does not install anything unusual. They change one line of configuration, the address their tool sends prompts to, and point it at the reseller instead of the vendor. Everything downstream looks the same. Same tool, same interface, same quality of answer, smaller bill.

What has changed is where the encrypted connection ends. It now terminates at the reseller's server rather than the vendor's. The reseller decrypts the request, reads it, passes it on to the real model, takes the answer back, and hands it to your staff member. Nothing is broken and nothing has failed. That is simply what happens when you put a server in the middle of a connection and tell your software to trust it.

The encryption did its job. It protected the prompt from everybody except the party your people pointed it at.

On the wire it looks like ordinary API usage, because it is ordinary API usage. There is no malware to detect, no exploit to patch, no anomalous behaviour to alert on. A network monitoring tool sees encrypted traffic to a commercial endpoint, which is what it sees all day. The only thing that gives it away is the address, and nobody is looking at the address.

Now think about what your people actually put into a prompt. Not what your policy imagines they put in. Draft contracts before they go to the other side. Board papers. The pricing on a tender you are still bidding. Client files, patient notes, an employee grievance somebody wanted help wording. Code, with the credentials still in it. A prompt is not a search query. It is the working document, pasted whole, plus the question they did not want to ask a colleague.

This is not the shadow IT you have handled before

For twenty years shadow IT has meant an unsanctioned tool holding data it should not hold. You know the shape of that problem. The data sits somewhere you did not choose, under terms nobody read, in a jurisdiction nobody checked, and if that vendor is breached you inherit the breach.

This is a different problem and it is worse in one specific way. With a rogue SaaS tool the exposure is conditional. Somebody still has to break in, or go looking, or make a mistake. Here, the reading is not the risk. The reading is the product. The discount exists because the prompts are worth something to the operator, and the prompts are only worth something if the operator reads them.

You are not exposed to a possible future breach. You are inside a completed one, continuously, and paying for the privilege out of an expense claim.

There is a second difference that matters more than it sounds. A rogue SaaS tool holds whatever was loaded into it. An intermediary in the model path sees the questions as well. It sees what your people are worried about, what they are negotiating, what they are drafting, and what they were unsure enough about to ask a machine instead of a person. That is not a data set. That is a running commentary on your organisation's judgement, delivered daily, in your own words.

The cheap option is the compromised option

Here is the part that makes this spread rather than stay contained.

Frontier model access is not cheap, and it is not getting cheaper fast enough for the people who need it. The labs publish their prices openly, in dollars per million tokens, and anyone can check them in a minute. Anthropic lists its Opus tier at five dollars per million input tokens and twenty-five per million out; the Sonnet tier sits at three and fifteen. Openness is normally a good thing. It also gives an intermediary a published number to undercut by an amount that looks like a bargain and still reads as plausible, because everybody knows there is margin in enterprise software and everybody has seen it discounted before.

So put yourself in your team's position for a minute. They have a budget that was set before anyone had an AI line item. They have been told to do more with the same headcount, and AI is how they were told to do it. Their approved tool costs real money per seat and the approval took a month. Then they find something that costs a fraction of that, does the same job, and requires no business case, no procurement, no conversation with you at all. What, precisely, is going to stop them?

Nothing is. That is the answer. Cost pressure and the compromised option point in the same direction, and they will keep pointing that way as long as buying properly is the slow and expensive path. That is not bad luck. It is the business model, and it is aimed squarely at the part of your organisation that is under the most pressure.

The cheapest option is the one somebody else is paying to read. That is not a coincidence. That is the product working as designed.

The other reason this slips through is that legitimate resale is now completely normal, and boring. You can buy the same frontier models through Amazon Bedrock, Google Vertex AI and Microsoft Foundry, under agreements a lot of Australian organisations already hold. Those are real channels with real contracts and real accountability. So when an invoice arrives from a company that is not Anthropic or OpenAI, nothing in it looks wrong to a finance officer approving a three hundred dollar charge. Buying AI from somebody who is not the lab is ordinary. That is exactly what makes the version that is not ordinary so easy to miss.

Why none of your controls saw this

The reasonable objection at this point is that you already have controls, so surely one of them would have caught it. Take them one at a time, because the answer is instructive.

You blocked the consumer chat sites. This is not one of those. It is an interface called by software: a code editor plugin, a browser extension, a spreadsheet macro, a script somebody wrote on a Wednesday. Your web filter is looking at which sites your people visit. Nobody visits this.

You have single sign-on and conditional access, and they are good controls. They govern identities logging in to applications. Your staff member did not log in to anything. They pasted a key into a settings field, and a key is not an identity.

You have data loss prevention. It inspects email and file transfer for patterns that look like leaving data. This does not look like leaving data. It looks like an encrypted request to a commercial endpoint, which is what every other piece of software on that laptop is also doing.

You have procurement thresholds. The charge is a few hundred dollars a month on somebody's personal card, reimbursed as a software subscription, well under the number that triggers a review. Nobody signed a contract, so nobody read one.

And you have an AI policy. It names ChatGPT, Copilot and Gemini, because those were the names when it was written. The thing it would need to name is a company nobody in the room has heard of, which did not exist when the policy was approved and may not exist next quarter.

Every one of those controls worked exactly as designed. Not one of them was designed for this.

They were all built to answer a question about which sites your people visit and which applications they sign in to. The question that matters now is a different one: which address does the software on that laptop send your work to. Almost nobody is asking it, which is why almost nobody knows the answer.

What has already left the building

Your first question will be how bad it is. That question has a specific shape and it is answerable in an afternoon.

Start with who. Not job titles, people. The staff who adopted AI first are almost never the ones you would have picked. They are your fastest and most capable, the ones carrying the most work and the least patience for a six-week approval. They are also the ones handling your most sensitive material, because that is what capable people get given.

Then what. For the period the tool was in use, what were those people working on? You do not need to reconstruct individual prompts and you will not be able to. You need the categories: client matters, personal information, contract terms, source code, unreleased financials, anything under a confidentiality undertaking. That is enough to size it.

Then obligations, and this is where it stops being an IT issue. If personal information about identifiable people passed through an intermediary that read it, you are in Privacy Act territory and you have a decision to make about the Notifiable Data Breaches scheme, on a clock. If client confidentiality or legal professional privilege was involved, you have an obligation that runs well ahead of anything a regulator will ask you. And if your contracts commit you to controls over data flows and subcontractors, which most material contracts now do, you have promised something you did not deliver.

None of that is comfortable. All of it is considerably easier to deal with when you are the one who found it. I have written before that you cannot govern the AI you cannot see. This is the version of that problem where the thing you cannot see is on your own card statement.

Card data finds the spending. It does not find the AI.

Go through those twelve months and you will find real things. You will also hit the limits of the method inside a day. Card data only finds what somebody put on a card, so it misses the free tier, the trial, the personal card that was never claimed, and the key a colleague passed along. It gives you a merchant and an amount, not what the tool can reach once it is running, what it is actually doing, or who else is using it. And it is true as at the day you ran it. The next thing your people find will be cheaper than the last, and they are looking this week.

You cannot govern model access you cannot see. Counting it once is not seeing it.

The answer to all three is a register you do not maintain by hand. We find what AI is already running across your organisation, what it can access, what it is doing and who is using it, and your AI asset register is built and kept current by software. Not a survey, and not a spreadsheet that is stale the day it is signed off. It covers the sanctioned tools, the shadow subscriptions and the AI sitting inside products you already bought, which is the part no policy-approved list has ever kept up with. It is the same capability I set out when OpenAI could not keep its own models in the box, pointed at the question this article is about: which providers your people are actually reaching, and which of those is somebody standing in front of the model.

The inventory is the precondition for every control you would want after it. You cannot block an endpoint you have not found, you cannot put a provider through procurement while nobody knows it is in use, and you cannot tell a regulator or a client what went through an intermediary if you cannot say which intermediaries you had. Most boards I speak to are working from an inventory that misses the majority of their real surface, and they do not find that out until something makes them check. So check. Start with the register, then the money.

Find out who you are paying. Then make direct the easy option.

If you are the person who actually owns this, the operations lead, the IT manager, the risk or compliance officer who will be asked what happened, here is the work. You can start it today without calling anybody, and you will know where you stand by the end of the week.

  1. Build the AI asset register from what is actually running, rather than what was approved. Go looking in three places, not one: the tools you sanctioned, the subscriptions your people bought themselves, and the agents already running inside software you never think of as AI, which is the place most inventories never look. For each one, record what data it can reach, what it is being used for, and by whom. Name an owner and set a refresh cycle, because a register nobody rebuilds becomes a description of last quarter, and you will still be governing from it.
  2. Pull every AI charge out of your card and expense data for the last twelve months and hold it against that register. Search the corporate card feed and the expense system for the model vendors and the known resellers, by name and by merchant descriptor. Read it both ways: charges with nothing running behind them, and AI running that nobody is paying for. The two will not match, and the gap is the finding.
  3. For each provider on that list, work out whether you are buying from the vendor or from somebody standing in front of it. Check the billing entity on the invoice, the domain the receipt came from, and the address the tool is actually pointed at. If you cannot answer that in five minutes, treat it as an intermediary until somebody proves otherwise.
  4. Buy direct, on a corporate agreement, and make that the path of least resistance. Direct accounts and the major cloud channels are available to you on terms you can hold somebody to. The cheap option only wins while it is the only thing your people can reach without asking permission.
  5. Make your egress visible and look at where the prompts are actually going. Pull the outbound destinations your network and your managed devices talk to, and filter for AI endpoints. If traffic is leaving to a host that is not the vendor's, you have found the intermediary without needing anyone to confess.
  6. Assume anything routed through an intermediary has been read, and establish what went through it. Take the date range, the people and the work they were doing in that window, and treat it as a disclosure question rather than a disciplinary one. Working it out yourself is the difference between managing this and being told about it.
  7. Give your people an approved fast path, and make it genuinely fast. They went around you because you were slow, and no amount of policy fixes that. If getting a model approved takes six weeks and a form, they will keep going around you, and the next thing they find will be cheaper than the last.

Do those seven and you will know something most organisations do not: what your people are actually paying for, and who is actually on the other end of it. In my experience the list of AI providers a business is really funding is two to three times longer than the one its policy describes, and the discovery is uncomfortable for exactly that reason. It is also the only honest starting point.

That is work we do, and it starts with seeing the estate rather than surveying it. Under AI Governance as a Service you subscribe to discovery that keeps running: what AI is live across your organisation, what it can access, what it is doing and who is using it, maintained by software instead of being true only on the day somebody signed it off. It finds what never touched a card, and it is still finding things next month, when your people have found something cheaper again. Alongside it we take twelve months of card and expense transactions, name every AI provider your people are genuinely paying for, and separate the vendors from the intermediaries, and from there it becomes data governance work: what went through each one, whose information it was, and whether any of it triggers an obligation you now have to meet under the Privacy Act or your own contracts. Where you need someone senior holding that permanently rather than for a fortnight, we do that too, as your fractional CISO one to three days a week, until you have a security function that can carry it without us.

Your staff were not trying to leak anything. They were trying to do the work you gave them, faster and cheaper than you were letting them.

Somebody has built a business on that.