The progression of artificial intelligence (AI) technologies has reached a level that greatly enhances the different organizational sectors by facilitating them with the means to advance and improve systems and processes. Shadow AI implies the usage of AI tools and systems by individuals within an entity, respectively, without permission thereby implying that these tools were not directly monitored or controlled by the centralized IT or security department. It also contributes to significant cyber risks such as data and security breaches, abuse of compliance, and, in general, an increased threat landscape. This paper highlights into the emerging global security trends and Shadow AI while also covering the unique positioning within the threat landscape concerning unauthorized computation of sensitive data, safety vulnerabilities of the unmonitored AI models, and model poisoning alongside data leakage-marked out. Moreover, this paper covers how Shadow AI distracts the attack landscape while increasing the level of security problem for the organization. Shadow AI, however, can be employed to increase the ability to respond to threats, locate irregularities, and increase the range of options available for cyber solutions even with all its risks.

Shadow AI: Cyber Security Implications, Opportunities and Challenges in the Unseen Frontier

Longo, Antonella;
2025-01-01

Abstract

The progression of artificial intelligence (AI) technologies has reached a level that greatly enhances the different organizational sectors by facilitating them with the means to advance and improve systems and processes. Shadow AI implies the usage of AI tools and systems by individuals within an entity, respectively, without permission thereby implying that these tools were not directly monitored or controlled by the centralized IT or security department. It also contributes to significant cyber risks such as data and security breaches, abuse of compliance, and, in general, an increased threat landscape. This paper highlights into the emerging global security trends and Shadow AI while also covering the unique positioning within the threat landscape concerning unauthorized computation of sensitive data, safety vulnerabilities of the unmonitored AI models, and model poisoning alongside data leakage-marked out. Moreover, this paper covers how Shadow AI distracts the attack landscape while increasing the level of security problem for the organization. Shadow AI, however, can be employed to increase the ability to respond to threats, locate irregularities, and increase the range of options available for cyber solutions even with all its risks.
File in questo prodotto:
File Dimensione Formato  
s42979-025-03962-x-Shadow AI.pdf

accesso aperto

Tipologia: Versione editoriale
Licenza: Creative commons
Dimensione 1.56 MB
Formato Adobe PDF
1.56 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11587/556410
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? ND
social impact