<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The existence of Shadow AI in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65324#M6599</link>
    <description>That’s a terrible definition of Shadow IT… because the better one has been purloined to define Shadow AI.&lt;BR /&gt;&lt;BR /&gt;It’s never code snippets it’s always a complete service or there is significantly less benefit in using it…&lt;BR /&gt;&lt;BR /&gt;Luckily the vast majority of this stuff is web delivered so set your proxy, CASB and DLP to parent data going to anything but those services that you vet, approve and commission. This policy should be relatively easy as these are categorised and to be usable you should be paying for the service.&lt;BR /&gt;&lt;BR /&gt;Monitor efficacy and do meet every quarter on the progress.&lt;BR /&gt;</description>
    <pubDate>Tue, 12 Dec 2023 23:40:14 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2023-12-12T23:40:14Z</dc:date>
    <item>
      <title>The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65321#M6598</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why should we care about Shadow AI, this piece explains why we should be very worried and that we need to understand and counter this issue now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.techpolicy.press/beware-the-emergence-of-shadow-ai/" target="_blank"&gt;https://www.techpolicy.press/beware-the-emergence-of-shadow-ai/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 23:01:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65321#M6598</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-12-12T23:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65324#M6599</link>
      <description>That’s a terrible definition of Shadow IT… because the better one has been purloined to define Shadow AI.&lt;BR /&gt;&lt;BR /&gt;It’s never code snippets it’s always a complete service or there is significantly less benefit in using it…&lt;BR /&gt;&lt;BR /&gt;Luckily the vast majority of this stuff is web delivered so set your proxy, CASB and DLP to parent data going to anything but those services that you vet, approve and commission. This policy should be relatively easy as these are categorised and to be usable you should be paying for the service.&lt;BR /&gt;&lt;BR /&gt;Monitor efficacy and do meet every quarter on the progress.&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Dec 2023 23:40:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65324#M6599</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-12-12T23:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65327#M6600</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&amp;nbsp; Don't forget the API gateway as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 01:18:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65327#M6600</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-12-13T01:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65328#M6601</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is a definition for Shadow AI:&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Shadow AI represents &lt;STRONG&gt;the hidden, uncontrolled frontier of AI usage within organizations&lt;/STRONG&gt;, bringing both opportunities for individual productivity and challenges for corporate governance and risk management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Forbes also did a piece on it on 31st October 2023:&amp;nbsp; &lt;A href="https://www.forbes.com/sites/delltechnologies/2023/10/31/what-is-shadow-ai-and-what-can-it-do-about-it/?sh=60b6ffe77127" target="_blank" rel="noopener"&gt;https://www.forbes.com/sites/delltechnologies/2023/10/31/what-is-shadow-ai-and-what-can-it-do-about-it/?sh=60b6ffe77127&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;CIO.com did a piece too:&amp;nbsp; &lt;A href="https://www.cio.com/article/648969/shadow-ai-will-be-much-worse-than-shadow-it.html" target="_blank" rel="noopener"&gt;https://www.cio.com/article/648969/shadow-ai-will-be-much-worse-than-shadow-it.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;2021.AI did a short piece on it too:&amp;nbsp; &lt;A href="https://2021.ai/shadow-ai-impact-deploying-ai/" target="_blank" rel="noopener"&gt;https://2021.ai/shadow-ai-impact-deploying-ai/&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Plenty of explanations available.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 01:29:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65328#M6601</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-12-13T01:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65329#M6602</link>
      <description>That’s what the CASB is for API into the service and application aware forward/reverse proxy to the service - if you want a special, sure knock yourself out but all the SASE vendors are crawling over themselves to ‘do’ GenAI traffic with ZTNA, mirrored gateways etc. data you app send out can’t be decrypted, parsed and inspected? “Sorry, computer says no.”&lt;BR /&gt;&lt;BR /&gt;Anyway when you commission a service in most regulated industries you’ll probably need to define the traffic you send down to the data element At some point and the vendor will undertake to not go beyond that - your internal audit reminding you and your internal data flows should all be mapped.&lt;BR /&gt;&lt;BR /&gt;If your applications are sending data out without full instrumentation and oversight, fix it, its probably just a matter of time before it’s over.</description>
      <pubDate>Wed, 13 Dec 2023 01:36:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65329#M6602</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-12-13T01:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65330#M6603</link>
      <description>Yes the article at the top looks like it may have used shadow AI to generate its definition of Shadow IT:&lt;BR /&gt;&lt;BR /&gt;“What is Shadow IT?&lt;BR /&gt;&lt;BR /&gt;For those unfamiliar with Shadow IT, these are often code snippets, libraries, solutions, products, services, and apps on managed devices that lurk outside the oversight of corporate, nonprofit, and government IT departments. Shadow IT can threaten an organization's cybersecurity, privacy, and data confidentiality. For example, they increase the likelihood of data breaches and ransomware infiltrating the corporate network, often costing the organization more than $1m for each incident, according to the Verizon 2023 Data Breach Incident Report.”&lt;BR /&gt;&lt;BR /&gt;Whilst it’s Shadow AI definition fits Shadow IT perfectly:&lt;BR /&gt;&lt;BR /&gt;“ What is Shadow AI?&lt;BR /&gt;&lt;BR /&gt;Shadow AI refers to the AI systems, solutions, and services used or developed within an organization without explicit organizational approval or oversight.”&lt;BR /&gt;&lt;BR /&gt;Succinct, elegant and natural.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Dec 2023 01:43:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65330#M6603</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-12-13T01:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: The existence of Shadow AI</title>
      <link>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65332#M6605</link>
      <description>&lt;P&gt;HI &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; I enjoy these debates by the way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The definition of Shadow IT can be described as:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Shadow IT is &lt;STRONG&gt;the use of IT-related hardware or software by a department or individual without the knowledge of the IT or security group within the organization&lt;/STRONG&gt;. It can encompass cloud services, software, and hardware. The main area of concern today is the rapid adoption of cloud-based services.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I think this is distinctly different from the Shadow AI definition:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Shadow AI represents &lt;STRONG&gt;the hidden, uncontrolled frontier of AI usage within organizations&lt;/STRONG&gt;, bringing both opportunities for individual productivity and challenges for corporate governance and risk management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Which would mean the uncontrolled use of AI tools without authorisation within an organisation, which could result in organisational IP being disseminated out of the organisation without managements actual knowledge.&amp;nbsp; Which would result in the loss of IP, corporate knowledge and potentially share information unintentionally with competitors or the dark side, seeking greater understanding of the internal workings of the company.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I guess the issue, is keeping it in context with a meaningful comparison, and ensuring both are fully understood.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 13 Dec 2023 02:42:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/The-existence-of-Shadow-AI/m-p/65332#M6605</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-12-13T02:42:04Z</dc:date>
    </item>
  </channel>
</rss>

