
SOC 2: Certification versus Attestation
Learn what SOC 2 tells you about your suppliers, as well as how to make the most of the experience if you’re thinking of going for SOC 2 in your own business.

CISOs have known about Shadow IT, the practice of using unsanctioned software tools that can result in potential security risks, for decades. For example, a user might install an open-source tool that requires elevated privileges, only to discover later that the tool or one of its components is malicious, and the user has now opened a backdoor into the network.
IT has typically gotten around Shadow IT by restricting user privileges, such as removing the user’s right to install apps. This method isn’t perfect, especially as more and more tools become web-based, but it’s been fairly workable.
Now, security professionals are faced with a new menace: Shadow AI, the use of unsanctioned AI tools such as Claude, ChatGPT, Grok, or even locally-managed LLMs, which can lead to a wide array of new problems.
Unlike Shadow IT, Shadow AI’s risk lies primarily in its use, not in whether something has been installed that could open a backdoor. AI tools have gained a reputation for privacy violations and aggressive data storage, making it challenging to delete data you provide to a generative AI tool.
ChatGPT is even currently under court order to store all its past chats with users, even when the user explicitly deletes the chat.
Users might inadvertently type company secrets or confidential information into these tools, resulting in data leakage. In Europe, as well as other jurisdictions with strict privacy regulations, users might type in confidential customer data, thus violating those data protection laws.
Another issue is the lack of reliability these tools have. Hallucinations are a generative AI problem that isn’t going away. For example, numerous legal professionals have been fined for using fictitious citations in reports generated by AI.
More directly, users might receive low-quality recommendations from AI on how to solve a software issue instead of calling IT.
Blocking access to generative AI tools from your network isn’t enough because 47% of people using these tools are doing so from their personal devices. Additionally, genAI is being integrated into so many existing platforms that users can access it from almost anywhere. Microsoft Office provides Copilot while Google Docs integrates with Gemini.
Websites are also increasingly integrating AI-powered chatbots into their help sections so users can query the chatbot instead of reading the docs.
Between embedded AI, SaaS integrations, and browser extensions, blocking AI access is virtually impossible.
Users turn to these tools because they believe the tools increase productivity and speed up tasks. Grok has become especially good at “replacing Google,” performing dozens of internet searches before answering a question.
A lack of approved AI tools might be exacerbating the problem. Without approved tools, users feel forced to use personal accounts instead.
IBM’s 2025 Cost of a Data Breach Report states that 20% of organizations said they suffered a breach in which Shadow AI was involved. Of those organizations, 97% didn’t have AI access controls in place. (It should be noted that 13% of organizations suffered a breach because of sanctioned AI as well.)
The additional cost of a breach for organizations with “high levels” of Shadow AI was $670,000, compared to organizations with low levels of AI use or none at all. In total, incidents involving Shadow AI resulted in more compromises of PII (Personally identifiable information) and IP (intellectual property) information.
The IBM report also says, “The swift rise of shadow AI has displaced security skills shortages as one of the top three costly breach factors tracked by this report.”
In other words: Shadow AI is a massive security problem!
Shadow AI increases a company’s exposure to cybersecurity risks in several ways, some more severe than others.
The most immediate risk is data leakage and exposure from users typing in sensitive information into insecure AI models. Unaware of an AI company’s data retention policies or that AI companies might be using prompts to further train models, employees might type in sensitive info, such as:
While LLMs aren’t anywhere near creating new strains of malware, some legitimate malware risks do exist that are specific to LLMs.
For example, through social engineering, an attacker can get an employee to unwittingly generate a malicious script and then run it on their machine. The malicious script can then download payloads to the machine.
Malicious browser extensions posing as AI can also steal AI chat histories.
Malicious models exist that don’t have the typical safeguards built into more mainstream tools. However, even mainstream tools suffer from hallucination, sometimes providing outputs that can lead to disastrous consequences.
In addition to the risks for the company itself, data leakage and exfiltration will almost always lead to some kind of compliance or regulatory risk. This is especially true for jurisdictions with strict privacy regulations, such as Europe with its GDPR (General Data Protection Regulation).
Certain sectors are likewise at higher risk than others, such as the health sector, which must comply with HIPAA (Health Insurance Portability and Accountability Act). The act delineates stringent controls that health professionals in the United States must keep in place to prevent abuse of a patient’s medical data. Such data is immensely valuable on the black market because it facilitates insurance fraud, which is why it’s so heavily regulated—and heavily fined when a company exposes it.
Data sovereignty is another key compliance issue when using unsanctioned AI models. When “chatting” with an AI tool, you’re sending data to servers that might reside outside the sanctioned zones according to your jurisdiction.
In 2003, Amazon discovered ChatGPT responses that looked “similar to internal Amazon data,” according to one of Amazon’s lawyers.
Samsung suffered a leak of top-secret source code after an employee pasted the code into ChatGPT to “optimize” it. Shortly after the leak, Apple banned ChatGPT and Microsoft Copilot for fears of similar leaks.
In the healthcare sector, 17% of employees admit to using unsanctioned AI tools, despite strict rules forbidding this. When asked why they used it, employees typically responded that their employers didn’t provide an approved version for them to use, and they were trying to speed up workflows.
Outright bans tend to force AI usage underground, which is even riskier than knowing what’s going on. A more effective strategy would involve a combination of clear company policies (governance), better visibility, and approved alternatives.
Company policies should focus on approved alternatives instead of outright bans, as well as placing AI tools into tiers, such as:
Users should also understand clearly why these tools are prohibited.
A Cloud Access Security Broker (CASB) will provide better visibility into network access for tools accessed through business devices. However, it might not be sufficient to prevent access from personal devices. That’s why governance must occur first.
Approved alternatives should be as easy to use as mainstream options. Mainstream AI providers offer paid tiers for API access that have stricter controls than the general tiers, and a company can integrate these into its own solution. While these are pricier than publicly available tiers, they’re far less risky because they typically don’t retain company data.
Other options are to develop in-house tools using open-source models and make them accessible via an easy-to-use front-end.
SolCyber is an experienced managed security service provider (MSSP) providing cybersecurity solutions with 24/7 human-led monitoring, detection, and response.
We can help you build in the necessary governance, visibility, and alternatives to protect your organization from shadow AI. To learn more, reach out to us for a chat.
Photo by Stefano Pollio on Unsplash

Learn what SOC 2 tells you about your suppliers, as well as how to make the most of the experience if you’re thinking of going for SOC 2 in your own business.

Are the shiniest new threats worse than the disruptive disorder of history?

Full disclosure carnival turns ‘Defender’ into ‘Attacker.’

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






