What is shadow AI?
Shadow AI is the latest addition to the overall shadow IT stable, which poses risk to organizations by introducing new back doors, footholds, and data storage sites that security leaders are unaware of, and therefore unable to factor into their overall security posture. This means these applications are used without the appropriate security tools and authentication levels on devices. Purchased without being formally reported to the organization, shadow technologies often occur because users are unaware of their responsibility, feel it isn’t important, or are sometimes purchased under personal expense claims.
What threats does shadow AI create?
While unbudgeted costs can be a challenge of any shadow IT, some of the biggest risks occur when employees and departments are leveraging less official, unpaid technologies. The current AI landscape offers users free programs that generally carry a higher level of security risk and are currently (largely) unregulated.
In addition to unauthorised access risk, shadow AI poses wider data protection risks. For example, how does the business know what potential proprietary, confidential, or private information is being provided to the AI solution in order for it to formulate decisions? Is the AI solution provided by a ‘trusted’ and reputable provider from a trusted nation state, or a corporation with a good history of data protection?
Shadow AI also presents a reputational risk to organizations. Decisions and actions recommended by any shadow AI solution may not be presented to the business, leadership, managers, or supervisors as being AI derived. Instead, users may represent these as ‘original’ thoughts. Not only does that create an ethical challenge for the employee, but it also risks bypassing the checks and balances that an organization might usually apply to AI-based insights.
How can organizations get a handle on AI use?
As ever, you can’t manage what you can’t see. Having the levels of visibility to identify and target the use of AI platforms through inspection of network telemetry is crucial. While humans have a whole host of reasons to fail to report AI use, network data is the source of truth. Solutions that provide deep observability of network traffic, wherever it flows – private/public cloud and on-prem, encrypted or unencrypted, north/south and east-west, are an essential tool in the armoury of any modern organization wishing to identify and eliminate the risks of shadow AI.
The author
Mark Jow is EMEA Technical Evangelist at Gigamon.






