Expert Speak

Think Banning Shadow AI Will Work? Think Again

AI raises many ethical concerns, and managing shadow AI has become one of the major challenges for organizations.

An AI assistant at Meta mistakenly recommended a technical fix that briefly exposed sensitive company and user data to employees. The incident occurred after an engineer followed the AI’s advice on an internal forum, leaving the information accessible for about two hours before the issue was resolved.

This incident involved an internal AI agent that had been approved by the organization. Imagine if an employee had instead used a public AI tool that resulted in a data leak. Not only would that employee’s job be at risk, but the organization would also have to deal with the consequences of unregulated AI usage.

Don’t just ban shadow AI
Banning shadow AI tools without providing an alternative is counterproductive. It only makes it more difficult for employees to get their work done.

Instead, organizations should provide an approved AI tool that employees can use. Whenever a particular AI tool is blocked, users should see a message recommending the approved alternative. This allows them to continue their work without using unauthorized solutions.

Role‐based access to tools
Understand which teams need which types of AI tools and provide access accordingly. Public AI tools can be made available to roles that don’t handle sensitive information. For example, designers may safely use public AI tools, whereas giving the same access to developers, who could accidently paste source code into these tools, would be far riskier. Teams who regularly work with confidential customer and business data could have alternative company-approved AI tools.

Providing access based on job roles helps employees remain productive while reducing the risk of sensitive information being exposed.

Have an AI forum
One of the best ways to understand employees’ AI needs is to create an internal AI forum where they can openly discuss AI, share the challenges they face, and recommend the tools they want.

This creates an opportunity for employees to brainstorm better ways to use AI while helping the organization understand AI requirements at the ground level. If an employee requests a design tool that the IT team hasn’t yet approved and more employees support that request, the IT team can evaluate and onboard the tool safely.

An AI forum also allows employees to share best practices, learn from one another, and discover safer and more effective ways to use AI.

A final word
Shadow AI can be effectively managed by putting the right controls in place while also providing employees with the tools and information they need to innovate and stay productive. The responsibility lies with organizations to identify the right AI tools and establish appropriate guardrails.

At ManageEngine, we believe privacy and innovation go hand in hand. That’s why we design and deploy AI capabilities in our products with privacy and security at the forefront.

ManageEngine is a division of Zoho Corporation and a leading provider of IT management and security solutions for organizations across the world. With a powerful, flexible, and AI-powered digital enterprise management platform, we help businesses get their work done from anywhere and everywhere—better, safer, and faster. To learn more, visit www.manageengine.com.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button