Leaders

Managing shadow AI risks in the workplace effectively

The rise of shadow AI: companies must embrace approved tools while safeguarding data, says Beth Tschida

Published

on

The rise of shadow AI: companies must embrace approved tools while safeguarding data, says Jamf CEO Beth Tschida

In Short:
– 98% of organisations encounter unapproved “shadow AI” usage by employees, risking sensitive data exposure.
– Businesses should approve AI tools, set boundaries, and focus on security over surveillance for better governance.

AI has gone from workplace experiment to everyday productivity tool, but there is a problem many businesses cannot easily see: employees are already using AI tools that IT teams may never have approved, assessed or even known about.

Beth Tschida, CEO of Jamf, says the rise of “shadow AI” is forcing businesses to rethink how they secure AI without simply trying to shut it down.

This so called shadow AI is becoming increasingly difficult to ignore, with around 98% of organisations recognising that some form of unapproved AI use is happening inside their business.

And telling employees to simply stop using it is unlikely to work. If AI can save someone hours of work, there is a good chance they will find a way to use it.

The bigger issue is not necessarily the AI tool itself. It is what the tool can access.

An employee might paste information into an AI assistant without realising that sensitive customer, financial or company data is leaving the organisation’s controlled environment.

What looks like an innocent prompt could create a very real security problem.

Stop banning AI. Start governing it.

Rather than playing whack a mole with every new AI tool that appears, organisations should establish a clear list of approved platforms, define what employees can and cannot do with them, and build security controls around that usage.

The goal is simple: move from “don’t use AI” to “here is how you can use AI safely.”

That approach also changes the conversation around employee monitoring.

Businesses need visibility over AI usage, but there is a fine line between security and surveillance.

Monitoring every prompt an employee types could quickly become intrusive and create its own workplace concerns.

A more targeted approach is to understand what data and sensitive credentials AI tools can access on an employee’s device.

In other words, businesses should be asking less about what did the employee type? and more about what could the AI tool get its hands on?

Who is responsible when AI goes wrong?

AI governance cannot sit with employees alone.

Chief Information Security Officers, Chief Technology Officers and other technology leaders need to work together to establish the policies, permissions and technical controls that determine how AI can be used across an organisation.

Employees still have a role to play, but expecting every worker to understand the security implications of every AI tool is hardly a robust risk strategy.

The bigger challenge is making the secure option the easy option.

Compliance is coming

The regulatory landscape around AI is continuing to develop, and businesses will increasingly need to demonstrate how they handle customer and company data.

That means organisations should not wait for a new rule to land before getting their AI house in order.

Businesses need clear policies, approved tools and the ability to show where data is accessed, how it is transformed and where it ultimately goes across endpoint devices.

AI is not waiting for businesses to catch up. And neither are their employees.

The companies that get ahead will not necessarily be the ones that use the least AI. They will be the ones that figure out how to use it without losing control of their data.

For more information, visit Jamf.



Trending Now

Exit mobile version