Shadow IT was a term created to describe the use of technology outside the purview of IT security and compliance teams (security compliance). An example of Shadow IT would be tools like flash drives or cloud storage to share documents with internal/external personnel, which can lead to the loss of sensitive/confidential information. This is why data loss prevention (DLP) measures are an important aspect of security compliance. An example DLP measure would be disabling USB drives on computers to prevent the use of flash drives.
AI is often not being introduced through structured programs with clear ownership and governance.
This brings me to an interesting article I read yesterday related to Shadow AI, which has emerged as a new term during the past few years. I find the concept interesting since, at least from the outside looking in, it appears AI is being pushed from the top down, bypassing attempts by security compliance to introduce controls into processes. This approach often leads to data loss similar to what happened to Meta last month while implementing their Model Compatibility Initiative (MCI) tool, even if the data loss was limited to internal personnel.
This is why security leadership must evolve from the “Department of No” to the “Department of How.”
The writer of the article is of the opinion the security function needs to evolve from “No” to “How”. This brought flashbacks from when companies reimagined internal and external audit teams as advisers. I’m not going to refute the writer here so much as I think this should already exist. Security should already be included in the “how” through project management and software development life cycle processes.
The issue is still that the security compliance teams are being bypassed. Organizations are asking staff to find ways to use AI outside the typical project management and SDLC processes. There’s no reimagining of security compliance if organizations aren’t willing to use a structured approach to implementing AI… and this introduces a massive risk that I don’t think executives and board members are aware of or are just willing to accept to beat the competition.
The CISO vs. Shadow AI Cold War
Just my two cents.
They did the old DLC trick on our laptops years ago. We cannot use a USB stick in any way, shape, or form. It is frustrating what with being on the IT team and all.