← All articles

Shadow AI on .si domains: when “AI” became “SI”.

A US rename and a .si registration rush give unvetted AI tools a new name that word-based proxy, DLP and policy controls may not catch.

Incident period: 22–29 September 2026 rename and .si registration surgeSources checked: 2 Oct 2026
THE POSTURE QUESTION

Do your acceptable-use policy, proxy categories and DLP rules still apply when an AI tool calls itself “SI” and lives on a week-old .si domain?

Background: the week “AI” became “SI”

In one week the US government renamed AI, and a small European country code became the hottest namespace on the internet. That combination is a gift to anyone running shadow AI phishing or data-harvesting operations.

Date (2026) What happened
22 Sep At the UN General Assembly, President Trump says the US will call artificial intelligence “super intelligence” (SI), because “artificial” sounds fake. The State Department’s International Organization Affairs (IO) bureau tells staff the same day to change all references. (siornot)
22–23 Sep 3,826 new .si domains in 24 hours; 621 domains containing “super intelligence” registered on the day of the speech, against 1–33 a day in the prior three weeks. (Cybernews)
23 Sep .si registrations reportedly overtake .ai within about a day. (Domgate)
29 Sep Executive order “Inaugurating the Era of Super Intelligence”: agencies must use “SI” in communications, websites and reports. Laws, contracts and the statutory definition (15 U.S.C. 9401(3)) are unchanged; legislative proposals are due in 60 days. (IAPP)
29 Sep Tech firms sign a separate, voluntary “White House Accord on Super Intelligence” on internal controls and audits. (Fox Business, TechRepublic)

The technology did not change. The vocabulary did — and attackers live in vocabulary. Every email, ad and browser tab that says “SI” now sounds official, and .si (Slovenia’s country code) looks like the natural home for it.

How employees meet SI-branded tools

Most staff will not go looking for .si domains; the new label will come to them. Expect it through four everyday channels:

  • Search and ads — “free SI assistant”, “SI meeting summarizer”, “SI PDF translator”.
  • Browser extensions that promise to add “SI” to email, docs or chat.
  • Vendor emails announcing that an existing product now has “SI features” or a new login page.
  • Colleagues sharing links in Teams or Slack to a tool that “just works”.

Each one ends with a person pasting company data into a service nobody in IT, security or legal has reviewed. That is shadow AI — now under a name your filters and policies were never written for.

Why the rename widens the shadow AI gap

Editorial assessment: the rename breaks controls that match on words. Many enterprise guardrails were built around the string “AI”:

  • Web proxy and SSE categories such as “Generative AI” depend on vendor classification. Brand-new SI-labelled sites start uncategorized.
  • DLP and CASB policies often key on known app names and the .ai TLD, not on .si.
  • Acceptable-use policies and training say “AI tools”. Staff may honestly not see an “SI tool” as covered.
  • Procurement and third-party risk questionnaires ask about “AI” processing; vendors may now answer under a different label.

The result is a window of weeks where new tools are trusted because the name sounds official, and unseen because the name is new.

Key risks for companies

Risk What it looks like Teams that should care
Data leakage Source code, contracts or patient/trial data pasted into an unvetted SI tool DLP, Legal, Privacy
Credential theft Fake “SI login” or “SI upgrade” pages for known brands Email security, Identity (Entra)
Malicious extensions “SI helper” add-ons reading page content and session data EDR, Endpoint engineering
Lookalike vendors New domains impersonating real AI vendors under the SI label Threat intel, Brand protection
Compliance drift Personal data sent to services with no DPA or unknown data location (GDPR, APPI, HIPAA) GRC, Procurement
Weak attribution Fresh domains with no history, so reputation feeds score them “unknown” SOC, SIEM content

None of these risks are new. What is new is the volume of fresh, plausible-looking names arriving at once.

Threat model: where SI-themed abuse maps to MITRE ATT&CK

Defenders can treat the SI trend as a new theme on familiar techniques, not a new class of attack.

Stage ATT&CK technique SI-themed example
Resource development T1583.001 Acquire Infrastructure: Domains Fresh SI-branded registrations during the rush
Initial access T1566 Phishing “Your company now requires the SI version” notices
Initial access T1189 Drive-by Compromise Search ads for free SI tools
Credential access T1056.003 Web Portal Capture Fake SI sign-in pages for known vendors
Persistence T1176 Browser Extensions “SI helper” add-ons
Exfiltration T1567 Exfiltration Over Web Service Users themselves uploading data to an unvetted tool

The last row matters most. In shadow AI, the “exfiltration” is usually a well-meaning employee, so detection must focus on data flows, not only on malware.

Defender’s playbook

Update word-based controls first, then hunt for what already slipped through.

  1. Update policy language. Define AI tools as “AI, SI, super intelligence or any model-based service” in acceptable-use, training and procurement forms.
  2. Treat newly registered domains as risky. Block or isolate domains under 30 days old at the proxy/SSE, and add .si plus SI keywords to your watch list.
  3. Extend DLP and CASB. Apply generative-AI upload rules to uncategorized and newly seen domains, not just to named apps.
  4. Lock down extensions. Allow-list browser extensions through Intune or GPO; review any with “SI” or “super intelligence” in the name.
  5. Watch identity. Alert on Entra sign-ins and OAuth consent grants to unfamiliar apps naming SI.
  6. Give people a safe path. Publish the approved AI/SI tools list and a fast request process. Shadow AI shrinks when the sanctioned route is easy.

Starter hunts

Illustrative; not executed in a live tenant. No attributable IOCs are published for this theme, so these hunts look at namespace and data volume, not known-bad domains. Replace the time window and thresholds with values that fit your environment.

Microsoft Sentinel — .si and SI-keyword destinations with large uploads. Requires proxy or SSE logs in CommonSecurityLog with DestinationHostName, SourceUserName and SentBytes populated; adapt the table and field names to your connector. FirstSeen is the first sighting inside the 14-day window, not the domain’s registration age.

// Sentinel CommonSecurityLog (CEF proxy/SSE); adapt fields to your connector.
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DestinationHostName endswith ".si"
    or DestinationHostName contains "superintelligence"
    or DestinationHostName contains "super-intelligence"
| summarize FirstSeen = min(TimeGenerated), Users = dcount(SourceUserName),
            BytesOut = sum(SentBytes) by DestinationHostName
| where BytesOut > 1000000
| order by BytesOut desc
| take 200

CrowdStrike Falcon (Event Search / Next-Gen SIEM) — DNS lookups for SI-themed names by host. Set the time picker to the same 14 days. DnsRequest carries the sensor aid; the host name is joined from the aid_master_main.csv lookup.

#event_simpleName=DnsRequest
| DomainName=/(\.si$|superintelligence|super-intelligence)/i
| groupBy([aid, DomainName], function=count(as=Lookups))
| aid=~match(file="aid_master_main.csv", column=[aid], include=[ComputerName], strict=false)
| sort(Lookups, order=desc, limit=200)

Triage tip: many hits will be legitimate Slovenian business sites. Separate them by domain age and by whether data is being uploaded, not just visited. No result is not proof of safety: direct-to-IP traffic, DNS over HTTPS, unmanaged devices and proxy bypass all fall outside these searches. CommonSecurityLog schema; LogScale match().

Containment and eradication

  • Block the domain at proxy and DNS; revoke any OAuth grants to the app.
  • Reset credentials and sessions for users who entered passwords.
  • Remove the extension fleet-wide; confirm removal in EDR.
  • Ask GRC and Legal to assess what data left, and whether notification rules (GDPR, APPI) apply.
  • Root cause: was there no approved tool for that job? Fix that gap too.

Conclusion

A rename is not a risk by itself; a rename that outruns your controls is. This week, check three things: does your policy say “SI”, do your proxy and DLP rules catch new domains, and do your people know the approved route? If any answer is no, shadow AI already has a new name in your network.

Sources

All sources were re-read on 2 October 2026. Registration figures are as reported by those outlets and were not independently counted.

All articles →日本語で読む ↗