The risk: Benchling had already vetted its SaaS portfolio, but that approval was based on how those applications operated when they were adopted, not on how they operated after adding GenAI.
A previously trusted vendor could introduce AI search, copilots, summaries, or model-training practices without triggering a new security review.
That created a blind spot with potentially serious consequences. Customer data could be exposed to new AI capabilities or used for model training under updated vendor terms, while security teams had no centralized way to know which applications had changed or whether those capabilities could be disabled. The risk wasn't limited to shadow AI, it was trusted applications quietly changing their data practices after approval.
For the CISO, this meant the company could have hundreds of applications that were technically “approved,” while some no longer met the assumptions under which they were originally vetted. And when the board asked which vendors were using GenAI or training on customer data, answering required manual investigation across hundreds of applications.
The bigger risk: Benchling could have a well-governed SaaS portfolio on paper while AI-related changes were quietly creating new data exposure and compliance gaps underneath it.