The Temptation of Inadvertent Shadow AI
In the course of my AI self-indulgence (also known as professional skills development), I have delightedly discovered some useful ways to cut short my own annoying administrative needs, both personal and business, which otherwise would have cost me dozens of hours copiously typing notes in front of my laptop. And, while I’m quite well-known to spend hours clicking away at a time, I must confess that these shortcuts are a welcome relief.
A generated business template that I can tweak for my new consultancy has saved me pulling countless comparisons and identifying commonalities to pull into my own fledgling document. Plugging in an effective prompt to pull research materials for my latest blog or journal article saves a lot of combing the internet for primary sources. And even my child’s evolving dietary requirements that require specialty cookbooks and keeping up with the latest guidance can benefit from not only a suggested meal plan but also a weekly shopping list that takes into account the stores closest to me and the brands she prefers the most.
While I was merrily learning my Anthropic, Claude, Gemini, and other AI ABCs, I began to realize how one person could quickly morph into a wannabe AI engineer, billowing out almost brazen confidence in their coding skills thanks to the suggestions of one or more toolset. With just one of my projects, a handful of software tools, subscriptions, and APIs (and code) were recommended to me, but I found myself hesitating to go on a downloading spree.
I am not an engineer. Did I feel confident that I wouldn’t accidentally give too much access or divulge too much personal information into a program that I was building? So, I paused. Instead of running full steam ahead as my training and my brainstorming bubbled and whirled around in my head with ideas, I stopped to take account of what I still needed to learn about these tools.
How many people don’t stop and with a smile across their face download, upload, reload and everything in between to create the app or program or shortcut that they need for their day job? We as an industry long have felt the pain from shadow IT, but now we have shadow AI.
The unintentional insider threat steps quietly into the room when an eager employee desires to use AI to better their work. Acceptable Use policies and banning of genAI tools from the corporate system might stem the tide at first, but it doesn’t stifle the curiosity and the genuine need for AI tools to increase efficiency. And as any parent knows, stubborn curiosity leads to creative workarounds for kids and for employees.
Even for processes that are under the oversight of IT and security teams, mistakes can still happen as we have noted recently in the agentic AI world. If I can take my own intrepid adventures into AI as a baseline, here are some thoughts on how security teams can consider tackling the looming Shadow AI issue:
1. Consider dedicated employee portals for testing and using AI. A safe place where they can experiment and not worry about breaking anything is peace of mind for both of you. And, letting creativity loose can potentially generate some golden nuggets your company can work with.
2. Work with your Data Loss Prevention (DLP) team for AI tools and programs in production and in development. Even the best-laid plans can experience turbulence, so better be safe than sorry and integrate your DLP from the start.
3. Actively scan for shadow AI assuming that something might still get created within the perimeter. This includes AI agents behaving outside of their intent.
4. Don’t just write a policy; embed controls in your browsers to prevent and warn wandering staff. While I hesitated before going further, others might need that blocker to prevent them from making the wrong choice.
5. Create your own Bill of Materials for your AI tools as many tools and platforms require several components. As I learned from just one project, there are several third parties involved in making one program, so be sure you know what you are using and monitoring for issues that might arise with these sites and software.
As companies embrace AI, safeguarding your staff, your intellectual property, your customers, and your brand must be top priority. Hiding from AI won’t help your company, but ensuring a safe exploration that is partnered with your IT and security teams can lead to internal innovation that creates a more efficient workspace for your team.
