Organisations are struggling to cope with their employee’s use of unsanctioned AI, with over a third saying they are facing challenges monitoring the popularity of ‘shadow AI.’
This is based on findings from Strategy Insights which polled 3,320 directors from companies in the UK, US, Germany, and Northern Europe, in order to gain a better understanding of AI management.
Without upgrades to legacy systems, businesses struggle to monitor the use of AI systems like chatbots across their tech stacks.
Shadow AI, which simply denotes any AI system that is not openly approved by a business to be used by employees, can increase cybersecurity and compliance risks as employees could accidentally share sensitive data, and the models used may not have the necessary or parallel security measures required.
Around half (48%) of respondents said that employee training will be required to ensure staff use AI responsibly and ethically, as well as informing them of the associated risks of using AI systems. This is especially important in industries like finance, healthcare, and social services.
Just over two-thirds (67%) said that stringent governance frameworks would be key to lessening the risks of shadow AI.
Recommended reading
- AI Use in Cyber Threats Only to Increase, Google Cloud Says
- Google: Legacy Tech and GenAI is Leaving UK Firms Vulnerable
- 92% of Enterprise Devices Unprepared for AI Security Challenges
The use of large language models and generative AI systems can leave sensitive data vulnerable to cyber incidents and non-compliance.
Around one in five UK companies have potentially exposed sensitive corporate data via the use of generative AI by employees, a RiverSafe study showed.
Major corporations have taken extreme actions to try to stop unsanctioned uses of AI due to their cybersecurity risks, including Apple, Amazon, and JP Morgan.
Employees continue to use AI technology without informing their bosses in a growing trends, according to Gartner, showing that employees may not be taking the risks seriously.
It also points to the normalisation of AI technology in people’s everyday lives, and how this has potentially infiltrated the workspace.





