What are the risks of "Shadow AI" and how can we govern unsanctioned LLM use?
Our employees are increasingly using tools like ChatGPT and Claude to help with coding and summarizing internal reports. My concern is that they might be pasting sensitive company data or intellectual property into these public models. How do we create a policy for "Shadow AI" that allows innovation while preventing a massive data leak?
2024-09-14 in Cyber Security by Jessica Taylor
| 15700 Views
All answers to this question.
Have you run a discovery scan recently to see exactly which generative AI tools are currently trending among your different departments?
Answered 2024-09-02 by Anthony Walker
-
Anthony, a discovery scan is a great reality check! I did one last month and found our dev team using three different AI coding assistants we hadn't approved. Once you know the "what," you can address the "why." If the tools make them 20% faster, the business case is there. The solution is to bring those tools under corporate management with an Enterprise License Agreement (ELA) that guarantees data privacy and "zero retention" of your company’s specific prompts.
Commented 2024-09-23 by Steven Hall
Education is faster than software. Run a quick workshop showing employees how their "private" prompts can technically be seen by the AI provider's staff.
Answered 2024-09-15 by Dorothy Scott
-
Spot on, Dorothy. Most people think AI is a magic box, not a server owned by another company. Once they understand the plumbing, they become much more careful.
Commented 2024-09-16 by Margaret King
"Shadow AI" is the new "Shadow IT," and you can't just block it because people will find a way around it. The best approach is to provide a "Sanctioned AI" alternative—like an enterprise version of ChatGPT or an API-based internal tool where the data isn't used to train the public model. Your policy should clearly define what data is "Public" vs. "Confidential." Use a Cloud Access Security Broker (CASB) to monitor which AI sites are being used and to block the transmission of sensitive strings (like credit card numbers or API keys) to those external domains.
Answered 2024-09-17 by Margaret King
Write a Comment
Your email address will not be published. Required fields are marked (*)

