Half of employees admit to using unapproved generative AI at work – the other half are lying. Jokes aside, there’s no question that the rise in generative AI has been noticed by overworked employees, lazy slackers and entrepreneurial types alike. Welcome to the world of shadow AI.
According to a survey from Software AG, half of those asked use shadow AI, which refers to non-company issued AI applications or tools rather than those specifically banned. A third of respondents said they were using shadow AI because their IT team doesn’t offer the tools they need to do their jobs more efficiently.
And that means some workers are making use of generative AI systems in their day-to-day work without letting their boss – or the IT team – know about it first. (If your boss hasn’t noticed, you may be wise to carry on: getting paid for managing a machine’s prompts will probably all be in our futures, and now you’ll have a head start.)
Some companies have banned the use of generative AI, or specific systems, from the office. Last year, companies including Apple, Amazon, Samsung and JP Morgan Chase banned or severely restricted staff from using ChatGPT over concerns they would unthinkingly share confidential or proprietary data with OpenAI.
What is shadow AI?
To be clear, shadow AI isn’t using Microsoft Copilot to make birthday party invitations for your offspring or memes to share with your WhatsApp group.
Instead, it’s about installing or using unapproved AI-powered services on a corporate network for business purposes. And the risks that could be introduced as a result; not only for IT departments but also across the wider organisation.
The term comes via shadow IT, which is the use of unapproved devices or software on a corporate network. There may be good reasons for this – you prefer Microsoft Excel to Google Sheets, say – but it can cause havoc. You could leak company data, offer fresh attack vectors to hackers and open up compliance issues.
The same follows for shadow AI, but the risks are different. There’s the chance of reputational damage and inaccurate results, given the so-called “hallucinations” that large-language models are prone to. Not to mention the worrying prospect of staff copying and pasting key business data into chatbots.
Why does it scare IT admins and business managers?
A BCS article raises four key concerns introduced via shadow AI: data privacy, regulatory compliance, security vulnerabilities and intellectual property. Let’s go through these one by one.
Data privacy. If you’re dropping customer data or business plans into ChatGPT, you may put your business at risk.
Regulatory compliance. If the AI tool you’re using doesn’t meet regulatory rules for sensitive industries, such as finance and healthcare, it could spark legal troubles.
Security vulnerabilities. Any untested software can be exploitable by hackers.
Intellectual property. You can spark IP problems by using content or producing products that you don’t actually own.
Beyond that, business leaders should be wary of employees using AI to sift through data and generate insights without the proper checks in place.
What to do about shadow AI?
Proper guidelines that are well communicated can go a long way to ensuring staff are at least aware they’re breaking company policy. However, another solution is to ditch the outright ban, or at least offer better alternatives.
Writing last year, two Google Cloud leaders noted in a blog post that outright bans of generative AI are “security theatre” because they take no technical measures to prevent misuse and risk pushing usage “deeper underground”.
The pair suggest that allowing enterprise-grade AI tools can actually mitigate the risk, as they can be controlled to prevent accidentally sharing key data into a chatbox prompt. While it’s no surprise to hear that suggestion from an AI-developing company, it’s also true that providing the tools that staff clearly want to use makes some sense.
If you decide to ban AI tools, follow up with technical controls such as monitoring for applications or blocking websites. Just be aware that if staff are working from home or bringing in their own devices, this becomes more of a challenge to achieve.
All of that said, there may be good reasons why your company needs to keep staff off the AI bandwagon for now. Make sure your staff know why – be it security or compliance or another reason – and offer the right tools, even if not AI, to make their work life easier.
And if you need staff to sift through data or manage some other dull job manually, give them enough time to complete the task or find a non-AI way to automate it. Otherwise, don’t be surprised when they turn to ChatGPT to do the work.
Read more on a similar theme: