- Shadow AI can pose risks to intellectual property and cybersecurity.
- Responsible use of AI and governance come with ongoing costs.
- Convincing use cases should be weighed against the known negatives.
Systems administrators and IT security staff know the importance of security and compliance. But shadow AI is causing issues in ways that are difficult to police, and may be endangering organisations’ intellectual property in addition to the cybersecurity concerns that already dominate personnel’s daily tasks.
In the mid- to late-00’s, shadow IT became an issue for many enterprises as, thanks especially to the popularity of the smartphone, staff were essentially coming into work equipped with powerful (or at least, powerful-enough) computers in their back pockets. Where previously the ‘company desktop’ was carefully built and managed centrally with an eye on potential cybersecurity issues, businesses had to cope with unregulated apps in daily use.
The policing of the perimeter and locking-down client devices became insufficient to protect the enterprise’s systems. Policies and tools had to adapt to consider a new way of day-to-day working that users liked, and made them more productive. To some extent, some of the dangers were assuaged by more cloud-based applications and web-based user interfaces which placed some of the onus for user safety on the SaaS providers. There were fewer client-based binaries to run, and so security systems were and remain able to continue to protect users.
Shadow AI the new kid on the block
But in the last couple of years, there has been a profusion of AI apps, with studies identifying any number of applications (some estimates put the figure in the millions) available a single click away, with dozens of new examples appearing daily. The threat from personnel using these apps comes not from infected or rogue binaries – although that remains a concern – but because often sensitive data is input into AI applications without oversight.
Many models openly or tacitly use copy-and-pasted data from end-users as further training material, meaning an intermingling of public and private data that could compromise an organisation’s intellectual property. In the worst case scenario, an AI model could then spit out IP to other users unconnected with the company. At best, an organisation’s information is now stored in an unauthorised location, one that might be non-compliant with the data polices so carefully created and enforced by the end-user’s business.
Traditional data governance and security frameworks are not equipped to deal with spontaneous AI application use, and given that the AI market is expanding and changing quickly, it’s unlikely that any measures taken today will be effective even a year hence.
In the light of the risks, organisations might consider the establishment of ‘responsible AI’ practices, accompanied by staff training to educate users on what is and isn’t safe practice. Like all such security and governance-focused policies, such a body of rules and guidelines has to be an evolving entity. Additionally, it’s probably wise to consider which are the approved providers of AI tools, and if no provision is in place to use them, make sure they’re either provisioned and/or paid-for.
Just like users insisting on using their shiny, new iPhone 3’s twenty years ago, staff will want to access the tools that make their lives easier and work more efficiently. And in the same way that BYOD policies accepted the new reality, BYOAI needs to take the same approach.
Creating responsible AI use guidelines and policies
The claim that AI can help in every possible role inside the enterprise suggests that the creation of responsible AI guidelines needs to be a collaborative affair that includes every business function. The resources needed to create and maintain policies and the accompanying staff training have to be weighed against the efficiency gains that are won by end-users running AIs to help them with their work.
If the measurable benefits of AI use are properly quantified, decision-makers may surmise that, in fact, the net gains from AI’s use are negligible or simply not worth the extra effort required to implement it safely. Or it may be the case that the marketing hyperbole around AI’s use is at least partially true, and using large language and media generation models contributes positively to the business.
Just because AI exists doesn’t necessarily mean it has to be used. If it’s of provable, quantifiable value, and its safe and legal implementation doesn’t cost so much as to outweigh the benefits, then decision-makers can take the appropriate steps. As a relatively new technology, it’s difficult to ascertain what future AI might be capable of. Any assessment of the technology’s potential right now has to be open to the possibility that companies give AI a hard pass.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.