Shadow APIs are endpoints created during development or testing that stay live in production. Organizations deploy API discovery tools to find unmanaged endpoints. Security testing integrates into DevSecOps pipelines. AI model inference APIs get targeted for training data extraction. The attack surface grows from forgotten test code.