Top 6 Claude Security Risks to Watch as AI Becomes Your Employees’ Operating System

Source: Cloud Security Alliance

Author: unknown

URL: https://www.akto.io/blog/claude-security-risks

ONE SENTENCE SUMMARY:

Claude’s expanding privileges create shadow AI, connector, skills, and code risks requiring comprehensive discovery, governance, IAM, SDLC controls, and monitoring.

MAIN POINTS:

  1. Unapproved Claude usage exposes proprietary, financial, and legal data without organizational visibility or guardrails.
  2. Missing SSO and acceptable-use policies prevents understanding data flows and regulatory compliance status.
  3. Claude Projects act as unmanaged repositories for sensitive documents, access sharing, and connectors.
  4. Organizations often cannot identify uploaded files, project access holders, or active connector activity.
  5. MCP connectors expand attack surface by enabling direct access to Slack, GitHub, Drive, Jira, Notion.
  6. OAuth scopes and authentication boundaries are frequently over-permissioned by users for convenience.
  7. Cowork introduces autonomous AI actions, complicating accountability, policy enforcement, and auditing requirements.
  8. Claude Code skills create supply-chain risks; plain-English prompts can drive data exfiltration.
  9. Studies found high vulnerability rates in Claude-generated code, increasing production security defects.
  10. Platform flaws in Claude Code enable malicious repositories to trigger command execution and key compromise.

TAKEAWAYS:

  1. Perform enterprise-wide asset discovery to inventory Claude usage across web, desktop, Code, and Cowork.
  2. Treat Projects as persistent data stores and enforce DLP with classification and real-time monitoring.
  3. Govern MCP/connector enablement with security review, least privilege, and token-usage visibility.
  4. Apply secure SDLC gates to AI-generated code, skills, extensions, and autonomous workflows.
  5. Build continuous audit trails for AI activity, access patterns, and sensitive-data exposure across all surfaces.