How to Prevent Shadow AI in Your Business

One of the risks that comes with AI in business is employees using AI tools for work without the business knowing how they are being used or what data is running through them. Business’s need to understand how AI is being used in the workplace, set guidance for acceptable use, and provide staff secure and useful tools.

What is Shadow AI?

Shadow AI is the use of AI applications or tools that are not approved or managed by the business. This could be an employee signing up for their own AI tool, using a personal AI account for work, or enabling an AI feature within existing software without knowing how company data will be handled.

The problem is not so much about the employee using unapproved tools, but importantly that the employee and the business may not know how the tool handles the information.

Why does Shadow AI matter?

Shadow AI can develop across a business very quickly and it is not always about staff trying to bypass IT or security processes. In most cases, the employee is simply trying to work more efficiently. AI tools are becoming increasingly easier to access and are being built into applications employees already use every day. Once company information is being shared with unapproved AI tools, it becomes difficult to know where that information goes and how it is handled. This creates security and privacy issues with sensitive business information.

Examples of risky Shadow AI.

These AI activities are legitimate business use-cases; however, a significant risk exists if staff are carrying these out on AI tools that do not meet your business’s security requirements.

  • Creating an AI agent that queries CRM data and sends customer emails.
  • Connecting AI tools to SharePoint, Teams, Outlook or other internal systems.
  • Using AI meeting assistants to record and transcribe confidential meetings.
  • Building AI workflows that read customer enquiries or company documents and take actions automatically.
  • Giving an external AI application access to Microsoft 365 data through integrations or permissions.
  • Uploading customer, financial or commercially sensitive information into an unapproved AI platform.

What are the main risks?

The level of risk depends on the tool, how it is configured and what information is being shared.

Some of the main risks are:

  • Data leakage.
  • Loss of control of data.
  • Unauthorised access.
  • Privacy and compliance.
  • Inaccurate information.

How to reduce Shadow AI use

  • Establish an AI policy.

Set rules around which AI tools employees can use, what information can be entered into them and when approval is required. The policy should be easy to understand and practical to apply.

  • Provide approved AI tools.

Employees are more likely to use unapproved tools if there is no suitable alternative available. Providing approved and useful AI tools gives staff a safer way to use AI while allowing the business to apply controls and maintain appropriate oversight.

  • Monitor and control AI use.

Businesses can also put technical controls in place to reduce access to unapproved AI platforms or identify where they are being used. The right approach is not to block all, just tools that have not been reviewed yet, do not meet security requirements or pose a high security risk. Depending on the environment, controls can include:

  1. DNS filtering to block access to selected AI websites or categories of AI tools.
  2. Web filtering and endpoint controls to restrict access to unapproved applications from managed devices.
  3. Cloud application monitoring to identify which online services employees are accessing and flag or block unapproved apps.
  4. Application and OAuth controls to prevent unapproved AI tools from connecting to Microsoft 365 or other systems.
  5. Data protection controls to help prevent sensitive information from being copied or uploaded into inappropriate services.
  • Educate employees

Staff should understand why some AI tools are approved and others are not. Training should make it clear that information entered into an AI tool is still company information and should be handled accordingly to AI policies and appropriate use guides.

  • Review and Invite

Regularly review AI use in the business, and give staff a simple way to request a new AI tool or use-case so they are not pushed towards using it without approval.

Managing Shadow AI.

Podcom can help businesses review their current AI use, put the right policies and controls in place, and introduce approved AI tools that reduce the risks associated with Shadow AI.

Our Latest Insights.

  • Sensitivity Labels and DLP: A Practical Guide to SharePoint Information Governance

    Sensitivity Labels and DLP: A Practical Guide to SharePoint Information Governance

    A practical guide to managing sensitivity labels and DLP policies in Microsoft SharePoint.

    Read more

  • When Data Centres Make Strategic Sense for Your Infrastructure.

    When Data Centres Make Strategic Sense for Your Infrastructure.

    From server room to data centre – scaling your infrastructure for greater resilience. For many…

    Read more

  • Podcom Is Growing – Expanding Our Team to Deliver Even Better IT Support

    Podcom Is Growing – Expanding Our Team to Deliver Even Better IT Support

    Podcom is growing with new Service Desk and Technical roles, strengthening our IT support delivery…

    Read more