Mitigating the hidden risks of Shadow AI

25/06/2025 | VentureBeat

VentureBeat examines the risks associated with the unauthorised use of artificial intelligence (AI) tools and applications when organisations implement restrictive policies to block access. Such policies have proven ineffective, as they merely drive Shadow AI underground. Employees will find workarounds, whether through personal devices, private accounts, or screenshots, resulting in a critical lack of visibility for IT and security leaders. Moreover, as the article highlights, this approach stifles innovation while failing to manage cybersecurity and data protection risks.

The article outlines several key steps required to achieve effective mitigation, focusing on visibility, governance, and employee skills development. The first step involves gaining a complete understanding of AI usage within the organisation. From here, tailored policies should be developed, avoiding blanket bans in favour of context-aware controls. This could include browser isolation techniques to prevent sensitive data from being uploaded to public AI models or redirecting employees to sanctioned, enterprise-approved AI platforms. Next, robust data loss prevention (DLP) mechanisms are essential for identifying and blocking attempts to share sensitive information, serving as a safety net against accidental disclosure. Finally, comprehensive employee education is vitalproviding practical guidance on responsible AI use and clear communication about the consequences of exposing sensitive data.


Training Announcement: Freevacy offers a range of independently recognised professional AI governance qualifications and AI Literacy short courses that enable specialist teams to implement robust oversight, benchmark AI governance maturity, and establish a responsible-by-design approach across the entire AI lifecycle. Find out more.

Read Full Story
Artificial intelligence AI, dark cloud

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.