Cracking down on shadow AI is making your business less secure, not more

Cracking down on shadow AI is making your business less secure, not more

Security is always a moving target. But AI has made it move faster than many organizations can manage, presenting a gargantuan challenge for SOC teams. The near constant stream of announcements of new models or providers has resulted in a massively expanded attack surface. Senior Product Manager at Nexthink. While security teams work hard to review and approve as many tools as possible, the volume is still crushingly high. Today, only 22% of workers rely exclusively on the AI tools their employer provides, while more than a third (35%) of Gen Z employees say they prefer using personal AI applications over company-approved ones. For every sanctioned tool a business governs, most of its workforce is quietly working around it.If almost 80% of employees use unapproved AI tools, then it isn’t an aberration - it’s the default. Shadow AI is normal across organizations, but the scale of the challenge is badly underestimated by the people responsible for managing it.Why the crackdown backfires Faced with unsanctioned use, the instinct is to clamp down. Blacklist as many tools as possible and pull usage back inside the lines. The problem is that, while this feels like control, in reality it just leaves security blind.Blocking doesn’t stop an employee using a tool, it just drives the risk out of sight. If their tool of choice is blocked on their laptop, they’ll access it on their phone. Or with their personal email address instead of their work one.This is true of many IT tools, but especially so with AI because people can become extremely attached to specific chatbot personalities. Consequently, AI use is driven deeper into the shadows, leaving zero visibility or record for security teams about potential data leakages or other risks.This is the trap at the center of most shadow AI strategies. The harder an organization tries to eliminate the problem, the less it can see. And the less it can see, the more dangerous the problem becomes. Governance that looks airtight on paper can bear little resemblance to what’s actually happening across the business.Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!The consequences are not abstract. When confidential information flows into unmanaged third-party platforms, the fallout can add as much as $670,000 to the cost of a data breach, and most of the employees responsible have no idea they’ve created a risk at all.Policy isn’t enforcement The reason for these problems comes back to the speed at which AI development is moving. ChatGPT is barely five years old and the difference in performance over that time is immense. One result of this is that pretty much any AI security and best practice training employees have done has not been adequate.The idea was not to overload employees with too much information. By keeping it ultra-straightforward and focusing on only one or two tools that were security-approved with examples looking at low-risk, early-adoption scenarios, companies could make compliance as easy possible.For a normal technology, it would be a sensible strategy. However, the level of self-driven AI adoption we’ve seen has been far higher than companies expected. Shadow AI use is rampant and so security cannot afford to continue blindly enforcing rules that aren’t working.Rather, to govern employee behavior, you need to be able to understand and analyze it. When it comes to AI that means gaining visibility into what tools and models employees are using, how, and where it’s actually delivering value.An experience-based approach That shift requires visibility into how AI is used across the workforce. A DEX (Digital Employee Experience) approach delivers exactly that, automatically detecting both approved and shadow AI through traffic patterns and endpoint activity, without relying on employees to self-report.Usage and experience data sit in a single view, broken down by team and workflow, so leaders can see where people are working around the rules and act on it.From there, the response stops being a blunt ban and becomes far more useful. In-app guidance can steer employees towards sanctioned tools in the flow of work, reinforcing the right behavior without killing the productivity they were chasing in the first place.Policies can be built around real usage instead of guesswork. And because 96% of leaders now say digital adoption support is critical to AI readiness, that same visibility shows exactly where training will close a gap rather than tick a box.It’s time to manage shadow AI Shadow AI isn't going anywhere, and pretending otherwise is how organizations end up exposed. The companies that handle it well will be the ones that stop trying to ban it and start paying attention to it. Everyone else is just hoping their policy is being followed, with no real way of knowing whether it is.We've featured the best endpoint protection software.This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Original Source

Read the full article at Techradar →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.