Governance First as Shadow AI a Reality

Professor Kerry-Lynn Thomson, Director of the School of Information Technology at Nelson Mandela UniversityThe challenge facing organisations is no longer whether employees are using unauthorised AI tools, but how businesses govern that reality. This is according to experts from the Institute of Information Technology Professionals South Africa Special Interest Group for Cybersecurity (IITPSA SIGCyber). 

Shadow AI is the unsanctioned use of artificial intelligence tools by employees without IT approval or oversight, creating potential security, compliance, and operational risks.

Definitely happening

Bryan Baxter, Head of Securelytics at BC Technologies, believes organisations should accept that employees will continue to seek AI tools unless secure alternatives are available. “If approved platforms are not provided, employees will use Shadow AI anyway, as surely as water flows downwards.”

The IITPSA SIGCyber experts argue that most employees adopt AI to work more efficiently rather than to circumvent security policies. However, without clear governance, organisations can lose visibility into how business information is being processed, increasing the risk of data leakage, regulatory breaches and reputational harm.

Not malicious

Professor Kerry-Lynn Thomson, Director of the School of Information Technology at Nelson Mandela University, says organisations should recognise that AI is primarily a governance challenge rather than simply a technology problem.

“Shadow AI risks often do not originate from malicious intent and the use of AI tools to improve productivity is primarily driven by the good intentions of employees. However, employees may upload sensitive data such as customer information, intellectual property or internal documents into public AI platforms without understanding where that data is stored, how it is processed or who may ultimately be able to access it.”

Open engagement

She says organisations should focus less on restricting AI and more on creating a culture of responsible use. “Addressing Shadow AI should not only be focused on restricting access to AI tools. Organisations should cultivate a culture of AI risk awareness, ethical use and trust, where employees are guided on how to use AI tools to reduce risk.

“The best way to deal with it is to engage openly with employees, educate them and obtain their buy-in to develop a culture to safely adopt AI in the business. Organisations need to regularly run campaigns to empower employees with information pertaining to the dangers of using AI in contravention of company policies.”

Underestimate the scale

An anonymous contributor, the CTO of a Johannesburg-based multi-site contact centre group, says many organisations may underestimate the scale of unauthorised AI use until they examine their own network traffic.

Following a routine review of AI-related firewall activity, the organisation identified dozens of different AI platforms in active use across the business. While the example reflects one organisation’s experience, the contributor says it demonstrates why visibility is the first step in effective governance. 

Prohibited

The IITPSA SIGCyber committee contributors encourage organisations to begin by understanding which AI services are being used across their environments before implementing risk-based governance that distinguishes between approved, conditionally approved and prohibited tools. 

Combined with employee awareness, data protection controls and clear governance, this approach allows organisations to realise the productivity benefits of AI while managing associated cybersecurity and compliance risks.

Notify of
guest

0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x