The risk: Plex had no reliable way to know where sensitive or regulated data was flowing, which AI vendors were processing it, or which AI agents could act on its behalf. A tool that never appeared in SSO could still have access to company data, while an unreviewed API token could give an AI agent access to critical systems without anyone realizing it.
That created more than a visibility problem. A single AI tool processing regulated data without the right controls, or an agent operating with excessive permissions, could expose Plex to security incidents, compliance scrutiny, and difficult questions from customers and regulators.
And with usage-based AI billing, there was no easy way to tell whether an agent was operating within its intended scope, or quietly consuming far more resources than expected.
The bigger risk: Plex knew about 30 approved AI tools. The real AI footprint could be significantly larger, creating a growing gap between the AI Plex had authorized and the AI actually operating inside the company.