The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities, misconfigurations, and weak data protection.
Cybersecurity experts emphasize that a blanket ban on AI-aided development is often counterproductive, as employees may then conceal their development activities. Instead, a structured governance framework is recommended to provide necessary security and compliance guardrails. Tenable, a cybersecurity company, has adopted such a framework to manage the risks associated with its own citizen coders.
The risks from these unsanctioned applications are not entirely new, having gained prominence with the rise of low-code/no-code development platforms. However, generative AI tools have exacerbated the issue by enabling virtually anyone to create functional applications from natural language prompts. Unlike many low-code/no-code platforms that are often hosted as SaaS and monitored by IT, generative AI products are frequently consumer-grade tools accessible to individual employees.
Common security and compliance issues in AI-generated citizen-coder applications developed without IT and security oversight include a lack of testing, scanning, and quality assurance, leading to code with critical vulnerabilities, dangerous misconfigurations, and risky open-source components. These applications may also insecurely access critical company systems and store sensitive data, often without being included in update, patching, monitoring, logging, backup, or disaster recovery plans. Furthermore, they can possess excessive permissions and privileges, bypassing the organization's identity and access management (IAM) systems.
Even when citizen coders attempt to involve IT and security teams, the sheer volume of AI-built applications can overwhelm these departments, making it burdensome to review, approve, and securely onboard them. This can lead to significant costs, particularly if applications consume AI tokens, and can result in dangerous data sprawl as citizen coders create local data lakes.
Tenable's comprehensive five-tier AI governance framework aims to address these challenges. The first tier, "Strategy," involves executive staff setting strategic alignment, investment guidance, and prioritization for AI initiatives. The second tier, "Governance," features an AI Governance Board and AI Technical Council responsible for creating AI policies, guidance documentation, and lists of approved AI tools, while explicitly owning compliance, data privacy, and model risk.
The third tier, "Execution," tasks AI Functional Leads and R&D Champions with driving specific use cases, managing departmental adoption, and measuring productivity. The fourth tier, "Enablement," involves an Enablement Working Group led by IT, Learning & Development (L&D), and Corporate Communications, which handles hands-on training, resource distribution, and enterprise demonstrations. Finally, the fifth tier, "Community," provides dedicated channels for support, crowdsourcing solutions, and discussions on AI usage and engineering.
This multi-tiered model ensures that foundational protections and controls for AI-generated applications are established uniformly company-wide by IT and security experts, rather than being determined independently by individual business units. Mandatory security and compliance awareness training for citizen coders is also a key component of this approach, alongside peer leadership and oversight within departments.






