Vanta warns of AI security chaos as employee builder roles surge 300%
- Builder roles at Vanta customers surged more than 300% YoY as AI democratizes software development
- Vanta identifies 'shadow AI' as a key risk where unvetted tools access corporate data
- Daily users of Vanta's AI agent grew more than 250% this year
- Usage of Vanta's MCP server expanded 50-fold, indicating high demand for automated workflows

*this image is generated using AI for illustrative purposes only.
Artificial intelligence is expanding employee capabilities beyond technical teams, creating significant security challenges for companies struggling to track access by humans and AI agents.
Jeremy Epling, chief product officer at Vanta Bioscience , described the shift in an interview, noting that AI allows employees to build software and automate tasks with minimal technical expertise. This democratization of building capabilities is fundamentally altering how organizations approach cybersecurity and compliance.
Rising Builder Roles
Vanta has observed a sharp increase in non-traditional technical roles among its more than 16,000 customers. Epling stated that builder roles, including go-to-market engineers and governance, risk and compliance (GRC) engineers, have increased by more than 300% year over year. This growth reflects businesses using AI to accelerate development and automate workflows.
However, this expansion creates new security gaps. Epling noted that security through obscurity is no longer viable because AI agents can find ways to access data or perform unexpected actions. Security teams now face the challenge of monitoring not just employees, but potentially thousands of autonomous systems operating on their behalf.
Shadow AI Concerns
The company identified "shadow AI" as an emerging risk, where employees sign up for AI services without established security vetting. In some cases, employees may feed company information into unvetted tools. This raises the prospect of organizations needing to monitor an expanding network of AI systems that can make decisions and act with increasing autonomy.
Epling warned that organizations could eventually have dramatically more agents than employees, creating a severe visibility problem for security teams. He predicted that the amount of automation will "fundamentally change everything" and create chaos that may overwhelm users.
Vanta’s AI Adoption
Vanta is also deploying AI to automate its own security and compliance work. Its Vanta agent can analyze security programs, assess vendors, answer questionnaires, and identify risks. The company has introduced integrations, APIs, an MCP server, and custom agents for customer workflows.
| Metric | Growth | Period |
|---|---|---|
| Daily users of Vanta agent | More than 250% | Year over year |
| Usage of MCP server | 50-fold | Year over year |
Daily users of Vanta’s agent have increased by more than 250% this year, while usage of its MCP server has grown 50-fold, according to Epling. This internal adoption mirrors the broader trend of companies granting AI systems greater authority to act on their behalf.
What the Numbers Show
The divergence between the 300% rise in customer builder roles and the 250% growth in Vanta’s own agent usage highlights a dual dynamic: customers are rapidly deploying AI for development while simultaneously relying on automated tools for governance. This suggests that as AI lowers the barrier to entry for building software, the demand for automated compliance monitoring scales proportionally to manage the resulting complexity.
Historical Stock Returns for Vanta Bioscience
| 1 Day | 5 Days | 1 Month | 6 Months | 1 Year | 5 Years |
|---|---|---|---|---|---|
| -0.20% | 0.0% | 0.0% | -4.85% | 0.0% | 0.0% |
How will regulatory bodies adapt compliance frameworks to account for autonomous AI agents acting on behalf of employees?
What new security architectures will emerge to monitor thousands of autonomous systems without stifling the productivity gains of democratized software building?
Will 'shadow AI' usage lead to a significant increase in data breaches, and how might this impact corporate liability and insurance premiums?
































