AI and cybersecurity risks, simpified

Nowadays, AI is impossible to ignore within organisations: it is used in varying degrees to improve productivity and quality and to reduce costs. Even if an organisation has decided not to do anything with AI, it will still be used by employees. Whether one wants it or not: AI is not going away any time soon. However, the use of AI brings with it various unknown risks and challenges.

AI within organisations in practice

There are now countless AI solutions being used on a large scale. The best-known general AI platforms are OpenAI's ChatGPT, Google Gemini and Microsoft Copilot. In addition, many specialised AI/machine learning solutions are available, for example for medical applications, art authentication and other specific fields.

Organisations are also increasingly deploying AI within their own business processes. Well-known examples include chatbots for customer service, the use of AI in telephone menu systems, and process automation. As a result, AI is becoming an increasingly integral part of day-to-day operations.

Cybersecurity and data risks of AI use

Nevertheless, the use of AI by employees and organisations brings new risks in the field of cybersecurity and adds to the growing complexity faced by CISOs and IT departments. The biggest problem is that employees often forget to filter data and, as a result, (often unintentionally) leak sensitive information such as internal documents, customer data or business strategies into these AI tools. This data is then used to train the AI models when this is done through the free versions of the AI. It is often the case that paid AI models are not trained on submitted data, but the user must actively opt for this.
To manage these risks effectively, it is essential to gain insight into how employees use AI, which AI is being used, and how this can be made safer. Some of the risks include: the rise of shadow AI, data leaks due to a lack of masking of sensitive data, and the use of free AI models

Shadow AI

Shadow AI is the use of AI that has not been approved by the organisation and for which the organisation has not entered into (paid) contracts. Shadow AI is often used by employees on their own initiative within the organisation. This can have various reasons, such as familiarity with a specific AI, or employees feeling that they get better results compared to the approved AI models.

A simple example of this works as follows:

An employee is dissatisfied with the AI result from the AI approved by the organisation and runs it once more through their own free ChatGPT account to get the desired result. This can of course be prevented by blocking the unwanted AI in the firewall, but the employee then uses their phone as a hotspot via 4G or 5G, thereby bypassing the organisation’s security policy and measures; unfortunately, this is not a problem that is easy to solve.

Blocking unwanted AI is often not effective in limiting the risk of shadow AI, and it also causes the organisation to lose visibility into it. There are other solutions available to coordinate this better.

Legislation and regulation

Due to the large-scale use of AI and the associated potential risks, the European Union and various governments have decided to take action. The AI Act, introduced in August 2024, is a European law that sets rules for the use of AI systems based on risk classification (prohibited AI, high risk, transparency requirements). As a result, organisations are also required to document how AI is used and which measures are taken to limit risks.

In addition, an important point of attention is preventing sensitive information from being unintentionally leaked via AI applications. This is where the application of Data Loss Prevention (DLP) measures becomes important. As mentioned earlier, a leak can occur quickly, but the resulting damage can, in some cases, have long-lasting consequences.

Controls and alternatives

To prevent the use of AI from getting out of hand within your organisation, you can take various control measures as described in the AI policy, thereby complying with the AI Act. There are also products available focused on DLP, and we now even offer a Secure AI Gateway.

The Secure AI Gateway provides:

  • Visibility into the use of Shadow AI
  • Coordination of Shadow AI users towards approved AI
  • Filtering of sensitive information submitted to the AI
  • Data Loss Prevention (DLP)
  • Hallucination protection on AI-provided information, preventing flawed decision-making based on nonsensical answers
  • Cost reduction on paid AI subscriptions
  • The ability to offer and compare multiple AIs simultaneously, Multi LLM
  • Support for external and internal AI platforms such as ChatGPT, Gemini, Copilot, on-prem GPT box, Bedrock, Azure OpenAI, Vertex, etc.

Who are we?

Zero Trust Networks is a cybersecurity company with certified network and security engineers with more than 18 years of experience in network infrastructure and security. Our goal is to help organisations improve their cyber resilience and find a cost-effective solution tailored specifically to your requirements and wishes.

Do you know what's leaving your organisation through AI?

Chances are employees are already using AI beyond your visibility. We map this out and show you how to regain control

Schedule a free consultation:· +31 70 355 8478 or get in touch with us using the button below.

Get in touch with us