Despite cybersecurity professionals’ best efforts to protect an organization’s networks and data, employees have long been the weak link in the chain. They click on malicious links in emails, reuse weak passwords, share sensitive information, and make other mistakes that threat actors exploit.
Then came generative AI, which promised to improve productivity but introduced new security risks. Unauthorized use of AI tools by employees is increasing the speed and scale of machines, increasing the risk.
According to a recent Bitdefender survey of 1,200 global cybersecurity professionals, nearly half (47%) of cybersecurity professionals admit that they do not fully understand the AI tools used by their organization’s employees. The study also found a gap between what company leaders think they know about internal AI use and what front-line employees report. 58% of IT and security managers say they have complete visibility into AI, but only 46% of practitioners agree. This means businesses may be underestimating the security risks posed by unauthorized AI.
“This is not just a technology issue, but also a governance vacuum,” the Bitdefender report said. “Shadow AI may seem like the new shadow IT, but it is harder to detect and the potential for data breaches is orders of magnitude greater.”
Shadow AI strategy for CISOs
A blanket ban on AI could make a bad problem even worse, said Chase Cunningham, a zero trust security expert, strategic advisor to multiple cybersecurity providers, and chief strategy officer at software demonstration platform Demo-Force.
“A policy of simply saying ‘we won’t use generative AI’ is not a strategy,” he said. “Frequently, usage happens underground, making it even less visible to security teams.”
Rather than restricting the use of AI, Cunningham argues that security leaders should first focus on understanding how employees use the technology. If you can identify which shadow AI tools your employees are using and why, you can create governance policies that encourage employees to responsibly adopt AI, rather than hiding how they use it.
A policy of simply not using generative AI is not a strategy. In many cases, usage is further extended underground, with even less visibility for security teams.
chase cunninghamDemo-Force Chief Strategy Officer
“Organizations can’t manage what they can’t see,” Cunningham added.
Internal corporate messages often encourage users to adopt AI for business efficiency. But companies also need to communicate AI risks, from data breaches to model hallucinations, in a way that resonates with non-technical employees, said Eric Kron, CISO advisor at KnowBe4, which provides security awareness training.
“From creating reports to writing and rewriting code, employees are realizing how AI can help them be more efficient, which is important in a time of doing more with less,” said Kron. “Unfortunately, people aren’t hearing about the problems that AI can cause.”
Analysts say recognition alone won’t solve the shadow AI problem. As Bitdefender’s findings suggest, organizations also need to better understand how their employees are using AI tools across the business.
“The hallmark of companies that successfully manage such risks will be an up-to-date inventory of which generative AI services are authorized and which are not,” said Rick Turner, an analyst at Omdia, a division of Informa TechTarget.
Cunningham agreed that visibility and governance of AI is key.
“Don’t try to stop your employees from using AI,” he reiterated. “Prevent AI from being used invisibly, indiscriminately, and with more access than necessary for the task.”
Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company providing writing, editing, video hosting, podcasting, on-stage presentation, and consulting services to the technology industry.