Emergence of Shadow AI

Shadow IT was a term created to describe the use of technology outside the purview of IT security and compliance teams (security compliance). An example of Shadow IT would be tools like flash drives or cloud storage to share documents with internal/external personnel, which can lead to the loss of sensitive/confidential information. This is why data loss prevention (DLP) measures are an important aspect of security compliance. An example DLP measure would be disabling USB drives on computers to prevent the use of flash drives.

AI is often not being introduced through structured programs with clear ownership and governance.

This brings me to an interesting article I read yesterday related to Shadow AI, which has emerged as a new term during the past few years. I find the concept interesting since, at least from the outside looking in, it appears AI is being pushed from the top down, bypassing attempts by security compliance to introduce controls into processes. This approach often leads to data loss similar to what happened to Meta last month while implementing their Model Compatibility Initiative (MCI) tool, even if the data loss was limited to internal personnel.

This is why security leadership must evolve from the “Department of No” to the “Department of How.”

The writer of the article is of the opinion the security function needs to evolve from “No” to “How”. This brought flashbacks from when companies reimagined internal and external audit teams as advisers. I’m not going to refute the writer here so much as I think this should already exist. Security should already be included in the “how” through project management and software development life cycle processes.

The issue is still that the security compliance teams are being bypassed. Organizations are asking staff to find ways to use AI outside the typical project management and SDLC processes. There’s no reimagining of security compliance if organizations aren’t willing to use a structured approach to implementing AI… and this introduces a massive risk that I don’t think executives and board members are aware of or are just willing to accept to beat the competition.

The CISO vs. Shadow AI Cold War

Just my two cents.

From Trust, but Verify to Zero Trust to CYA

There’s an aspect to auditing internal controls that has always seemed straight forward to me that for some reason others have trouble grasping. I figure it’s just a personality trait. It doesn’t really matter if the control is financial, operational, or technological, it all boils down to taking the control in question and asking the control owner to “prove it”.

In essence, as an auditor, we’re asking the control owner to prove that the control occurred on a specific day, week, month, or year, depending on the frequency of the control. This thought process has also served me well in the current dis/misinformation age. However, what do we do when the evidence provided is questionable at best? This is being taken to another level now with AI, which allows control owners to create evidence that is perfect. What do we do when the evidence is too perfect?

This ISACA SmartBrief on AI article got me thinking about the topic –> The Audit Evidence Crisis: How AI Deepfakes Are Rewriting Assurance Standards. The article recommends we move on from the “Trust, but Verify” approach to auditing into a new era of “Zero-Trust”.

Why a Zero‑Trust Approach is Essential

A zero‑trust mindset ignites inquisitive and professional skepticism that strengthens the auditor’s ability to:

  • Independently obtain audit evidence from IT and OT environment without interference
  • Validate the authenticity of evidence before relying on it
  • Detect manipulation in digital documents, images, and communications
  • Assess whether controls are resilient against AI‑enabled fraud
  • Reduce audit risk in environments where deception is increasingly automated.

Taking this a step further, this got me to thinking about how audit firms go about what I like to refer as CYA. I’ll refrain from spelling that out in hopes we all know what it means. There are a few steps during an engagement that deal with fraud and non-compliance, which requires the organization being audited to verify (sign) that they are unaware of a fraud or non-compliance.

  1. Contract/Engagement Letter – Signed prior to the engagement, this documents details auditor and client responsibilities, amount other topics. Client responsibilities include notifying the service auditor of any fraud or instances of non-compliance.
  2. Fraud and Non-Compliance Inquiry – Performed during the planning phase, this step involves inquiring with control owners at various levels (e.g., management, staff) whether they are aware of and fraud or instances of non-compliance.
  3. Management Representation Letter – Signed by the client at the completion of the engagement, prior to issuing the final report, this document reiterates responsibilities by the client to notify the auditor of any instances of fraud or non-compliance.

Now, let’s be real. They’re all manual responses and don’t really prove anything, just a CYA for the audit firm. However, I wouldn’t be surprised if audit firms update their engagement letter, fraud and non-compliance inquiry, and representation letter templates to include references to if/when AI is used to create audit evidence. To an extent, it’s already somewhat tangentially included, but it might need to be specifically noted going forward.