The Rise of Shadow AI - Implications for Privacy, Security, and Ethics

Fujitsu / September 11, 2024

Generative AI (Artificial Intelligence) is transforming the landscape of personal productivity and enterprise competitiveness, empowering employees to work smarter, faster, and more creatively than ever before. Organizations have been quick to recognize these advantages. Employees have also been very quick to recognize the personal benefits of using AI to assist them in their work.

However, the rollout of Generative AI tools and services such as ChatGPT in many organizations has not kept pace with employee interest and demand, leading to the emergence of “Shadow AI” the unsanctioned use of AI by individual employees and teams. Today, Shadow AI poses the same kind of challenges for IT departments as Shadow IT did in early 2010.

What is Shadow AI and what issues dose it present

Shadow AI refers to the unauthorized adoption and use of AI tools and services, like ChatGPT, by employees without IT department approval. While employees may be motivated by good intentions seeking to enhance their productivity and capabilities, Shadow AI poses significant problems for organizations.
Without proper IT oversight and safeguards, Shadow AI introduces a range of legal, regulatory, reputational, and operational risks. For instance, the EU’s General Data Protection Regulation (GDPR) requires explicit consent for data usage. Organizations that breach these regulations can face fines of up to €20 million or 4% of the company’s annual global turnover from the preceding fiscal year, whichever is higher.
Furthermore, Shadow AI can perpetuate biases and exhibit discrimination inherent in their training datasets, raising ethical concerns. AI systems might also generate false or misleading information, compromising decision-making processes, which can lead to monetary loss, reputational damage, and a loss of trust in the organization.

What drives Shadow AI adoption

Several factors drive the adoption of Shadow AI:
Accessibility:
The increasing availability of free and low-cost AI tools, such as ChatGPT, enables employees to independently adopt these technologies. Cloud-based AI platforms and open-source libraries have democratized AI, allowing non-technical staff to integrate advanced AI into their workflows. While IT departments can take steps to mitigate this, employees may still use personal devices to access AI tools and incorporate the results into their work.
Pressure:
The competitive pressure to enhance productivity, innovation, and speed can push individuals and teams to bypass lengthy approval processes and resort to Shadow AI.
Familiarity:
Many new employees, including recent graduates, are already familiar with Generative AI tools from their academic experiences and expect to use similar tools in their professional tasks. If these tools are not provided officially, they may turn to Shadow AI.
Governance:
Insufficient AI governance frameworks can lead to fragmented AI adoption, where isolated instances of AI usage occur outside official channels.

How widespread is Shadow AI

Shadow AI is a growing concern. A recent survey by the Deloitte AI Institute found that 20% of the 2,000 employees surveyed admitted to using Shadow AI to support their work. However, given its unauthorized and covert nature, the true volume is difficult to ascertain, with some estimates suggesting it could be over 60% in certain organizations.

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...