Shadow AI creates hidden employee-led risks
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
With all the buzz around nation-state threats, it’s easy for organizations to focus on threats outside the business – and forget about risks that can spiral outwards from within.
Whilst GenAI tools have introduced undeniable efficiencies for employees, these platforms have also introduced a new class of risk: two in three UK organizations admit they can’t track whether employees are sharing data via approved tools.
Most of the time, employees aren’t sharing sensitive data because they have malicious intentions. They are uploading sensitive information – like contracts, client proposals or supplier agreements to models like ChatGPT and Claude to save time on routine tasks.
Steve Bradford is SailPoint's Senior Vice President, EMEA.
Almost all (93%) of CEOs across the globe have adopted generative AI to some extent in the past 12 months (PwC). What’s concerning is that much of this activity is happening without any oversight, in the browser – meaning organizations are failing to track the flow of company information, including when and where it’s uploaded.
This is spiraling into serious risk for businesses.
First, because employees may inadvertently share credentials or other access details with public LLMs, which could result in unauthorized access if the model is compromised.
Second, uploading personal data to LLMs can trigger compliance breaches with laws like GDPR and the Data Use and Access Act – resulting in costly fines as well as reputational damage.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
To take control of this issue, leaders will need to implement tools and technologies that provide visibility and control over usage at both the browser and the application levels.
Employees don’t need more mandatory cybersecurity training – the problem is incentive. Many company-owned gated LLMs are still in the pilot stage, falling short of the speed and precision offered by public alternatives.
While the majority of employees understand the risks, 35% of UK businesses admit data sharing through external tools takes place – indicating many would rather ‘throw caution to the wind’ than waste valuable time using slower tools.
But the risks of this behavior – particularly in highly regulated sectors like financial services, could mean unsanctioned LLMs become 'hidden icebergs’ in an organization. Concealed, but capable of causing catastrophic damage upon impact – like inadvertently exposing customer transaction histories or credit scores.


