The Risks of Shadow AI
It’s likely you have seen the recent reports about the CEO’s of AI companies advising that the development and the release of new AI models should be paused, so that better governance and safety can be developed to protect humans.
You have also probably seen the concerns about AI agents replacing many white and blue collar jobs.
Most of us have limited ability to control or influence these issues.
If your organisation holds personal information and does not have an approved AI system for employees, do you think you are able to answer the following:
How often and how much information containing Personal Identifiable Information (PII) has been posted into a free, publicly available AI system, by one of your employees?
If PII information has been posted, it is very likely your organisation has breached APP 11 of the Privacy Act because your organisation has lost control of the information and made an unauthorised disclosure to a third party. The regulator recommends that organisations do not enter personal information into public AI tools ever.
Your first step is to figure out whether you have a problem. The only way to do that is to run a discovery audit to see who’s doing what!